Cars Being Stolen With Keyless Entry
If car owners leave their keys on the table or near their doors, they could not realize that they are allowing thieves to hijack their signal. This relay attack is a highly-tech method used by criminals to steal keys from new vehicles.
Keyless ignition vehicles emit an extremely low-power radio signal, seeking a compatible fob that can respond. If the signal is captured and recreated, it can be used unlock the car, and also to start it.
Relay Attack
Imagine your car at your driveway, with your key fob in your home. You might think that your car is secure but sophisticated thieves are planning a heist without you being aware. These thieves use technology to hack into vehicles via digital chinks. Known as relay theft, it’s a more common method of stealing vehicles with keyless entry.
Cars with keyless entry are designed to function using signals that are sent from the remote control (RF) transmitter to the owner’s key fob. To ensure that keyless entry is not accessed by unauthorised persons the RF transmitters that are on the key fob as well as the car are programmed only to turn on when they are within a specific distance from one another. However, thieves can circumvent this limitation employing a method known as the relay-attack.
To accomplish this two people work together: one stands by the car, using a device that captures digitally the key fob’s signal. The other, in the vicinity of the house of the owner and using a second device to send the key fob’s signal down to the car keys got stolen what to do. This trick tricks the car into thinking that the key fob is close enough to allow it to unlock and begin the engine.
This type of attack was once a costly process that required expensive equipment. It is now possible to purchase an inexpensive relay transmitter online and pull off an heist in a matter of minutes. This is the reason car keys stolen from house and car stolen thieves love it.
All modern vehicles with keys are at risk. Certain cars are more vulnerable to this type than others. In fact, researchers have tested 237 popular cars and found that they can be all stolen using this method.
Tesla vehicles are supposedly less susceptible to this type of theft, however the company has not yet implemented UWB features that would effectively check distances on the car’s signal to prevent relay attacks. The company has promised to do so in the future, but until then, they remain vulnerable. Installing an anti-theft system that safeguards your keys and your car against such a threat is a proactive approach to ensure the security of your vehicle.
CAN Injection Attack
Modern vehicles can defend themselves from thieves by sending encrypted messages to the key to verify its authenticity. The system is believed to be safe, but thieves have found ways around it. They can impersonate the smart key and send messages to the vehicle letting it unlock the doors, disable its engine immobilizer, and let them leave the car. To do this they have access to the smart key’s internal communications network.
Today, most automobiles are equipped with between 20 to 200 electronic control units (or ECUs) which control different aspects of the car key stolen but not car‘s operation. They communicate with one another using the CAN bus. To ensure that power consumption is low, these ECUs enter a low-power sleep mode that’s activated when they receive a wake up’ frame. These frames are typically sent by the ECU that is in charge of the smart key or door. However the messages aren’t usually authenticated or encrypted so they can be intercepted by criminals with a cheap and basic device.
They look for a place where they can connect directly to the wires of the CAN connection. They usually are hidden in the headlights, or in other locations in the front of the vehicle. To get them, you must pull the bumper and cut holes in the headlamp assemblies. The thieves employ an instrument known as a CAN injection attack to send fake messages which fool the safety systems of the car into unlocking and disengaging the engine immobilizer.
The devices are available on the Dark Web and work with all major car makers, including BMW and Cadillac, Chrysler, Fiat and Ford, Honda, Hyundai and Jeep, Lexus and Nissan, Renault and Toyota, Volkswagen and Maserati. The researchers who discovered this CAN Injection attack are recommending that all car makers address it in their existing models, but the fact is that these thieves will continue to take anything they can get their hands on. We can stop this by implementing mechanical safety measures such as Discloks in all of our cars and parking them in well-lit, visible areas.
Jamming the Signal
In a variant different to the relay attack, thieves could use a gadget to jam the signal that is sent by a key fob when the car stolen without key is locked. The device may be inside the pocket of a burglar in a parking lot or in a hideout near the driveway being targeted. Owners aren’t able to verify whether the car is locked after pressing the lock button. The device used by the crook interferes with the signal to lock the car. Therefore, thieves can leave the vehicle.
The crooks also use devices to amplify the key fob’s signals in order to unlock vehicles. They can accomplish this if the key is inside the pocket of the driver or hanging from a hook inside the house. After the car has been unlocked, they can make use of the standard computer hacker to program a blank key fob and gain control over the vehicle.
To protect against this type of attack, car makers have come up with a range of anti-theft gadgets. However, thieves are always trying to beat these measures.
They’ve been using devices that transmit at the same frequency as remote keyfobs in order to intercept signals. The crooks can then copy the unlock code of the key fob and then start the car with this fake signal.
This method is particularly popular in the US, where many cars are equipped with wireless technology. Owners can start and unlock their car using a mobile application on their phone. This technology is likely to become more popular as more car manufacturers attempt to connect their cars to their owners phones.
It is crucial that drivers follow the right procedures when parking their vehicles. They should not leave their keys in the ignition and should always secure the car when they are not in it. If they can they should also utilize the gearstick or steering locking device. They should also consider installing a tracking device on their vehicle in the event it is stolen.
Flat Battery
This kind of attack happens more often than people realize. Thieves employ cheap devices to extend the signal from your key fob to unlock and begin the car, even if it’s switched off. They then drive the car around a corner or to a trailer and take off with it. It would be possible to shield your vehicle from this by installing an interrupter switch for the starter circuit. Simpler versions come with an ON/OFF button which interrupts the circuit. It costs about $15 and is easy enough to install by yourself.
Car thieves are constantly searching for new ways to take vehicles. The police as well as the car makers and insurance companies are always trying to catch up with their strategies and offer better anti-theft solutions for modern cars. However, that doesn’t stop thieves, who are able to be quick to adapt and find ways to circumvent the latest anti-theft measures.
For instance, a lot of criminals use a device that works on the same frequency as the fob in order to block the signal. They place the device in their pockets or in a location near their vehicle, and it prevents the fob’s lock commands from reaching the vehicle and thereby leaving the vehicle unlocked. This can be done in minutes. The device is inexpensive and can be purchased online.
Hacking the computer system of the car is another option. This is more difficult, but still feasible. All cars have an diagnostic port, and hackers have created devices that connect to them and let them access the software of the car. From there, they can program a blank key fob and start working. It is possible to do this on older cars as well but it’s more difficult without taking out the ignition.
This method is likely to be more popular if more vehicles are connected to drivers’ mobile phones. Once a burglar has gained the username and password for an app for vehicles they are able to open the car or get it started with the app on their phone. You can guard yourself by not leaving valuables inside your car, and parking in garages.