Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

how the hell do you steal a 2020 vehicle without the key? I thought thats the whole point of the sophisticated FOBs (that cost $500 for a replacement). I thought the only way you could steal a late model car was with a tow truck.


There are relay attacks where you boost the signal from 50 feet away. Think someone pulls up outside your house with a giant antenna attached to a clandestinely made device, unlocks the car and drives it straight into a shipping container.

A lot of cars are vulnerable to "all keys lost" programming through the OBD2 port. You show up with an Autel box, smash a window/jimmy the door, pair a blank fob to the car and drive it away.


Shit, I'm to hire a thief to make me a new key. Sounds cheaper and faster than the dealer. ;)


My understanding is that a tool is used to boost the the signals between the car and key fob so the thieves can simulate them being very close -- close enough to unlock and subsequently start the car.

Once the door is unlocked though there are any number of ways to get the car moving, especially if you have access to the ODB2 port.

My key fob can be put into a battery-saving mode which disables wireless communication unless a button is pressed. My vehicle also supports a song-and-dance to disable all proximity-based sensing, at which point you need to hold the key fob against the ignition panel to start the car.

This is incredibly inconvenient and I don't know anyone who does either of these, though.


I've got a great solution. How about requiring the users insert a hard to reproduce physical key-like object in a slot before the car will start?


Objections to how fobs would weaken security were made before they were introduced and fell on deaf ears - I'm not certain why car companies would start listening now.

I want my physical keys and knobs and buttons on the console back - half the electronics in cars seem to add negative value.


Yes! I hate touch screens in cars. I hate that they are so much more difficult to use and require so much more attention. I guess they're only possible because the car does half the driving for you now, picking up whilst you're distracted trying to turn on the windscreen demister or whatever.


Wafer locks used in car doors are actually inherently easy to lockpick because the tolerances can't be that high. Wafer locks are used because they allow you to insert the key upside down and still unlock it.


Ah, I've got a solution to that too! I'm going to call it two factor authentication. Basically it uses a secondary digital key as well that communicates in parallel with the physical widget.


Huh that's pretty clever, requiring both would make it pretty foolproof.


they already solved this with DNS, how about a certificate chain? so (at the very worst) you can revoke the certificate on the stolen car. But also allow lost keys to be replaced by reprogramming them from a dealer certificate (which could also be revoked, and have a TTL). No, I dont want the car to require an internet connection to start, but I think its reasonable to say "to enable anti-theft, your car must resync at least every 6 months to update certificates. If not, it will be easier to steal and you can pay into a higher insurance pool".


Facial recognition might be easier


How hard would it be to have the fob recognize it hasn't moved in x minutes and turn itself off? If it's in your pocket it would stay active, and the user experience would be exactly what it is today, while stopping night-time relay attacks.


Sounds about on par with my old Saturn that you could probably start with a screwdriver. But at least I can get new keys made for $5 each.


Guessing with a Flipper Zero (https://news.ycombinator.com/item?id=39084137)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: