Method to VAG-keys to hack yet published
Posted on 11-08-2015 at 23:01 by Dizono – 50 Comments”
Two years ago, a team of researchers, including two Dutch citizens, how easy it was to car keys of the VAG group to hack. Volkswagen put out via the right stick for publication, but two years later it still tacking.
Two years and two weeks ago revealed that researchers managed the encryption of a lot of VAG-keys (from Seat, to Lamborghini, to crack. The encryption method was according to the researchers, under the measure and a paper in which it was declared was in the making. To publication, however, would be not to come, Volkswagen stepped to the right, because the information the thieves and other unsavory types in the map would play. The British supreme court went for it and put a permanent line through the revelation of the investigation report.
So, it seemed at least, for two years, an apparition may be the report of Volkswagen AG still to be published. What passages, the researchers have to delete to make a compromise is not known, but we can’t imagine that Volkswagen two years later, suddenly to repent has come and no problem has publication of the full report.
More so, it turns out to be a faulty implementation of the Megamos Crypto chip, which is the brand for fifteen years in almost all models of Volkswagen, Seat, Audi, Skoda, Porsche, Bentley and Lamborghini have applied. The chip has of itself a long security code, writes the NOS, but Volkswagen used but a small part of that code for encryption of the electronic immobilizer. Researcher Roel Verdult from the Radboud University in Nijmegen compared to the NOS:
“Since only a small part of the security code is used, the code is actually much simpler to figure out than it should. […] If all information is monitored between the key and the car takes about ten minutes to with a large rekencomputer the security code to figure it out. If the long key would have been used then it would take you years to count behind the code.”
According to Volkswagen, however, there is not a whole lot going on, so leave them in a comment at the NOS know. Therein, they say, among other things:
“Even with the older models of our range of products, of which the immobilizer by the authors is investigated, the car thief at least an authorized key, and the recording of at least two times to successfully start need. For these reasons, these older cars are, in principle, also protected against theft.”
A meager attempt to run for your life to save, of course, the security is just poor, and instead of the researchers to search for a structural solution, they have a lot of money in a lawsuit stabbed to publication to prevent. That with the knowledge that their models on the MQB platform, which, since 2012, built to be better protected. That you are now with engines of less than 30 dollars, keys of other brands can easily ‘hack’, might have helped the decision as to publication now. Incidentally, it is modifying the hardware of the car according to Volkswagen is practically not possible. Recalls we are seeing today, indeed rarely, fortunately, the VAG models, not so popular with the base, you would almost be bad to go to sleep!
Thanks to Dennis for the tip!