Underground developers are selling Flipper Zero “car unlock” packages for hundreds of dollars, complete with a PDF listing targeted makes and models and whether the hack enables only door unlocks or full start/drive.
Underground developers are selling Flipper Zero “car unlock” packages for hundreds of dollars, complete with a PDF listing targeted makes and models and whether the hack enables only door unlocks or full start/drive.
None of this needs to happen. Frankly insurance companies need to be holding the car manufacturer’s feet to the fire by not insuring cars that can be trivially stolen like this. If a Flipper Zero can steal a car that is 100% on the car manufacturer.
If a tiny yubikey can generate cryptographically unique keys so can a car key fob.
It would not be that difficult to design a key fob which pairs with the car wirelessly (just like Apple uses for AppleTV and Apple Watch).
Literally all you need is:
If anyone complains about battery life just make the fob rechargable instead of the annoying shitty battery change process. You can even make a charging port in the car (where they keyhole used to be, or in the wireless charging tray).
Plus this can be extended to phones with zero trust and no need for external infrastructure or violating user privacy.
I agree with the sentiment, but unfortunately that screws over the owners far more and for far longer before it even impacts the car manufacturers.
Maybe a better attack (aside from government regulations) would be banks to not provide financing for loans to buy those cars. In the end, if the car is stolen they are at a loss so that makes sense.
People can’t get loans, so don’t buy the risky vehicle. It hurts a little in the now to direct them towards cars that will not be a problem in the future. And the car companies feel the sting of lost sales right away.
The governments should be, too.
Instead, some countries are taking the approach of banning Flipper Zeros or restricting their sale instead. That’s like outlawing flathead screwdrivers because you can use them to pop improperly-installed doors off of their hinges.
It’s on the car manufacturers to fix their poor security, not on tool suppliers to not make tools.
“oh no, your car got stolen…here’s another car for you to buy”
We need a global system of digital ID that simply bricks any car reported stolen.
Yeah, because there’s no way remotely brickable cars could ever be abused by the manufacturers.
Yeah, you can ban flipper, but then someone is going to use a raspberry pi zero with a SDR hat, or an arduino, or an old android phone, or a wifi router and battery pack.
Ban electrons!