Monday, April 20, 2020

Vehicle cybersecurity still lacking: Ford Focus and Volkswagen Polo


Vehicles are becoming increasingly connected and complicated. The modules/equipment in the vehicle along with the connectivity makes the newer vehicles targets with many attack vectors. With these advances, the consumer would think cybersecurity would be the first thing on the engineer’s mind. Unfortunately, this is not always the case. It is likewise notable, there are many laws and statutes directed at the vehicles for emissions and other aspects of the vehicle. While these are indeed needed, there are no laws focused on the cybersecurity applied to vehicles. There is a handful of these in the works, however, at this stage, these are more voluntary and may be presented as more of a standard versus legislative action.

Successful breach
While these are noteworthy, generally, if an automobile the manufacturer does not have to or is strongly encouraged to, it is difficult to get the issue resolved and feature in the vehicle. A recent case in point involved a For Focus Titanium Automatic 1.0L and a Volkswagen Polo SEL TSI Manual 1.0L. These are both gas-powered vehicles and are very popular in Europe.
Researchers at Context Information Security were tasked with conducting a pentest of sorts on these two vehicles.

The research indicated there were rather serious cybersecurity flaws with the test vehicles. The researchers have reported these and are waiting until providing their test to the public as part of the responsible vulnerability disclosure process. This provides the manufactures time to correct or mitigate the issue, prior to sending the vulnerability, and how to attack it to anyone who has an internet connection.

Researcher’s attacks generalized
While the specifics are not available, the researchers did release general information regarding their successful attacks. As a recap, the subject vehicles, and nearly all others at this point use the Controller Area Network (CAN) to communicate between the modules in each vehicle. These communications are relevant for tire pressure, driving controls, braking, steering, etc. If this is successfully attacked, the driver and passengers assuredly are going to have a bad day. This area was one where the researchers were able to successfully access the Polo.

There was also another vulnerability with OTA (over the air) updates. The vehicles have a number of computers and programs located with the vehicle’s system. These at times need to be updated. Think of it like when you turn off your computer and the system warns you there are patches that need to be uploaded for your system. To have the owners all make appointments to drive their vehicles in every time there is an update is not a workable solution and would halt any work that would need to be done in the repair/maintenance portion of the garages at the dealerships. The researchers were able to tamper with these updates, thus adding the malicious functionality of changing the official update to whatever they would want.

The researchers also found a vulnerability with the infotainment unit in the vehicle. This, when successfully attacked, would enable or disable the vehicle’s traction control, tamper with the headlights, and holds a large amount of personal data (e.g. phone contacts, and location history). This attack was accomplished with a simple command. For this attack, the researchers or bad actors would need to have physical access. While this is a hurdle, it is not impossible, especially since this would only take approximately five minutes.

There were other tests done, with mixed results.

The researchers, curiously, were able to find the Wi-Fi credentials that apparently were for the computer systems on the Ford production line. This is a rather significant and truly bad thing to have that easily accessible.

Resources
Chllingsworth, L. (2020, April 15). Which? Identifies security risk in these road vehicles as hackers may steal your data. Retrieved from https://www.express.co.uk/life-style/cars/1269260/which-ford-volkswagen-car-security-safety-hackers-crime
Forrester, N. (2020, April 15). Latest ford and Volkswagen smart cars pose ‘serious’ privacy and security risk. Retrieved from https://securitybrief.asia/story/latest-ford-and-volkswagen-smart-cars-pose-serious-privacy-and-security-risk
Hull, R. (2020, April 8). Popular ford and vw cars found to have ‘serious security flaws’ with their connected systems putting personal data and safety at risk. Retrieved from https://www.thisismoney.co.uk/money/cars/article-8201733/Popular-Fords-VWs-security-flaws-connected-tech.html
Laughlin, A. (2020, April 9). We hacked ford focus and a volkswagen polo. Retrieved from https://www.which.co.uk/news/2020/04/we-hacked-a-ford-focus-and-a-volkswagen-polo/
Thomas, P. (2020, April 10). Popular ford and vw cars found to have ‘serious security flaws’ with their connected systems putting personal data and safety at risk. Retrieved from https://www.iaati.org/news/entry/popular-ford-and-vw-cars-found-to-have-serious-security-flaws-with-their-co


Thursday, April 16, 2020

4CAN as another vehicle cybersecurity testing tool

Vehicle cybersecurity continues to grow in pertinence. This is especially the case with the CAV (connected and autonomous vehicle) as these advancements in technology application and improves in performance. The connected vehicles are already in place and used on the road. The autonomous vehicles are still being developed and tested. There will be a time when the scenes in movies, e.g. iRobot with the fleets of self-driving cars, are in place with the vehicles communicating with each other and the infrastructure (V2V, and V2I). 

As the prominence continues to grow, so does the potential for attack. This may be from the bad actors looking for their 15 minutes of fame, malicious attackers, or cybersecurity researchers. In each of these vehicles are also vastly more attack points than in prior years. The modern vehicles have hundreds of sensors feeding data to the vehicle regarding the vehicle and also the environment in which it is driving. These may be LiDAR, radar, cameras, microphones, and other sensors. These sensors provide real-time data to the vehicle and end-users on the vehicle’s operations, which is processed immediately dependent on the criticality. 

The attackers may have access to the vehicle’s computers through the vehicle’s WiFi, Bluetooth, or cellular means. While this is notable, the controller area network (CAN) is what carries the messages through the vehicle. 

4CAN
To better protect the vehicle, better tools have to be created, which is what was done in 3Q2019 by Cisco. 4CAN was originated by George Tarnovsky, who is a member of Cisco Customer Experience Assessment and Penetration Team (CX APT). This is a hardware tool and was released as open-source. This is a PiHat, meaning the 4CAN is attached on top of the Raspberry Pi. This was engineered to be used by all automobile security researchers. The focus is to test the sensors and computers within the vehicle to check for vulnerabilities. As noted, the bench setup is much cleaner, simpler, and easier to use. This changes a 4 piece set up, including two Beaglebone boards, to two pieces of equipment.  This also lessens the setup time for the lab staff. 

The 4CAN tool works to validate the communication policy for intra-CAN bus communication, fuzzing the sensors and modules to detect vulnerabilities, and use various CAN commands to interact with the vehicle. The interaction hopefully would also detect any sensor or module vulnerabilities with the messages being sent. The tool is designed to test four CAN channels at once. 

While the tools do have advanced capabilities and would suit many use cases, the 4CAN is able to complete these tests with a simplified bench set up. This assists the lab engineer to keep it simple and organized.

Resources
Arghire, I. (2019, August 23). New tool from cisco hunts flaws in automotive computers. Retrieved from https://www.securityweek.com/new-tool-cisco-hunts-flaws-automotive-computers 

CISOMAG. (2019, August 26). Cisco releases new security tool to identify vulnerabilities in connected cars. Retrieved from https://www.cisomag.com/cisco-releases-new-security-tool-to-identify-vulnerabilities-in-connected-cars/

DeTrano, A., Royes, J., & Valites, M. (2019, August 22). New 4CAN tool helps identify vulnerabilities in on-board car computers. Retrieved from https://blog.talosintelligence.com/2019/08/new-4can-tool-helps-identify.html

DeTrano, A. (2019, August 5).4CAN. Retrieved from https://github.com/alexdetrano/4CAN/tree/master/tools 

Haking. (n.d.). 4CAN-Open source security tool to find security vulnerabilities in modern cars. Retrieved from https://hakin9.org/4can-open-source-security-tool-to-find-security-vulnerabilities-in-modern-cars/ 

Meterpreter. (2020, April 16). Cisco releases 4CAN tool to find vulnerabilities in on-board car computers. Retrieved from https://meterpreter.org/cisco-releases-4can-tool-to-find-vulnerabilities-in-on-board-car-computers/ 

N, B. (2019, August 25). 4CAN-Cisco released new open source security tool to find security vulnerabilities in modern cars. Retrieved from https://gbhackers.com/4can/ 

Paganini, P. (2019, August 24). Cisco has released a hardware tool, called 4CAN, developed to help researchers to discover vulnerabilities in automotive systems. Retrieved from https://securityaffairs.co/wordpress/90317/hacking/4can-automotive-testing-tool.html

Friday, April 10, 2020

Ba-Zynga: Being hacked is no game



Mobile gaming is an exciting field to work in and play in. With the processing of phones currently, there is not the lag present years ago. There are many companies that create these games. One of these is Zynga. Zynga is a social online game developer. The company became popular approximately a decade ago with the mobile game Farmville. They also own Words with Friends, Zynga Poker, Mafia Wars, and Café World.
Data Exfiltrated
The Zynga website was successfully attacked. This affects the gamers on the iPhone and Android platforms who installed and signed up for ‘Words with Friends’ game on or before September 2, 2019. This specifically affects the logins for game Words With Friends, and by some reports also Draw Something. The breach was reported on September 12, 2019. There were more than 170M user names and passwords exfiltrated with this attack.

This affects those users who had signed up for Draw Something or Words With Friends prior to September 2, 2019. This database held the credentials for 172,869,660 accounts. These were stored with salted SHA-1 hashes. The database held names, email addresses, login IDs, hashed passwords with SHA1 with salt, password reset token if one was ever requested, phone numbers if provided, Facebook ID (if connected), and Zynga account ID. There was no financial information accessed.

Not the first time
The hacker, from Pakistan, was contacted to comment on this. The hacker handle for the person is Gnosticplayers. This is not the first time Gnosticplayers have been able to breach the defenses and exfiltrate data. They also had the pleasure of exfiltrating much smaller databases previously with approximately 7M passwords, which were not secured. These databases were for the discontinued game OMGPop.

Concerns
This was not the first or second time this has occurred with Zynga. This would indicate a distinct lack of care for the data entrusted to the company by the users and for cybersecurity in general. Zynga, every time a user registers and puts their data in the online form, entrusts Zynga to do the right thing with the data. This did not occur, clearly, since the same issue has been shown again and again.
On another point, the passwords were salted and hashed. Generally, when industry-standard hash protocols are used, this is a good security measure. The issue is, however, industry standards were not followed.

Zynga has also not elected to note how this attack occurred. While this is not something a company would want to be known for, this could have assisted others to learn from their oversight.
Mitigation
Once detected, Zynga did contract with a third-party forensics firm to assist with the investigation, as well as law enforcement. Naturally, they also contacted the affected users to change their passwords.

Resources
Dunham, J. (2019, December 19). 173 million accounts exposed in hack of ‘Words with Friends’ developer. Retrieved from https://www.ctvnews.ca/sci-tech/13-million-accounts-exposed-in-hack-of-words-with-friends-developer-1.4736646
Gonzalez, O. (2019, October 1). Zynga data breach exposed 200 million Words with Friends players. Retrieved from https://www.cnet.com/news/words-2ith-friends-hack-reportedly-exposes-data-of-more-than-200m-players/
Hern, A. (2019, December 19). 170M passwords stolen n zynga hack, monitor says. Retrieved from https://www.theguardian.com/games/2019/dec/19/170m-passwords-stoeln-in-zynga-words-2ith-friends-hack-monitor-says
Ivanova, I. (2019, October 2). Zynga data breach exposed 200 million Words with Friends players. Retrieved from https://www.cbsnews.com/news/words-with-friends-hack-zynga-data-breach-exposes-200-million-users/
Khandelwal, S. (2019, September 29). Exclusive-Hacker steals over 218 million zynga ‘Words with Friends’ gamers data. Retrieved from https://thehackernews.com/2019/09/zynga-game-hacking.html
Knight, S. (2019, October 1). Zynga hacked, more than 200 million accounts compromised. Retrieved from https://www.techspot.com/news/82150-zynga-hacked-more-than-200-million-accounts-compromised.html
Lakshmanan, R. (2019, October 1). 219M ‘Words with Friends’ players’ data reportedly stolen zynga hack (updated). Retrieved from https://thenextweb.com/security/2019/10/02/218m-words-with-friends-players-data-reportedly-stolen-in-zynga-hack/
Lyons, K. (2019, December 19). Zynga hack affected 170 million accounts. Retrieved from https://www.theverge.com/2019/12/19/21029682/zynga-hack-words-with-friends-draw-something-password-data-breach
Page, C. (2019, September 30). Zynga hack exposes data of 218 million Words with Friends players. Retrieved from https://www.theinquirer.net/inquirer/news/3082078/zynga-ack-words-with-frie
Zynga. (2019, September 12). Player security announcement.
Zynga. (2019). Protecting your account. Retrieved from https://www.zynga.com/security/protecting-your-account

Wednesday, April 1, 2020

Here we go again: Intel processors with problems



We all know the importance of chips in IT and embedded systems. Without the processing power, we would have many boat anchors sitting around collecting dust. One manufacturer, Intel, is in the news once again.

New Warning Issued
Research is being done on different platforms across the world. There are labs actively seeking viable exploits on the equipment, from the chip to the system level. In this case, Positive Technologies researched this issue and detected the exploit with the Intel processors. The processors released in the last five years have a security flaw in the silicon. As this is in the silicon, it can’t be fixed or patched with a firmware update, which is a problem.

Target
The issue is with the Converged Security and Management Engine (CSME). This is a subsystem in the CPU, which takes care of the security tasks, securing the entirety of the firmware. This process is during the processor operations, beginning when the power button is pressed.

Exploit
The vulnerability is would, when successful, would allow the unauthenticated user to potentially enable escalation of privilege. This would lead to the attacker being able to extract the chipset key stored on the PCH microchip and gain access to the data encrypted with this key. This is clearly not the optimal situation. What makes this worse is, if there were to be an attack, it is not possible to detect this.

On a brighter note, all is not lost. The exploit is rather difficult to process. First, the attacker would need physical access to the processor and time to complete the attack. Second, the attack itself is by far not easy. If one of the steps was not easy, having to complete them both only makes this exponentially more difficult to complete in the unauthorized environment. In certain limited instances, the attack could be performed with malware engineered to bypass the target’s OS-level protections. While this is a significant detriment, the potential attack removes the chain of trust for the platform.

Granted, this is still a possible attack, which is why there is attention being paid to this and mitigation put in place, correcting most of the issues. This sounds like a perfectly workable plan, however, there are so many known and unknown vectors, this is still a tough job.

Mitigations
While this is relatively serious, Intel has put in place mitigations. These mitigations were supposed to have done beginning in May 2019. Before the present mitigations are in place, the firmware and processor are still vulnerable when the system boots on. These, while the intent is in the right place, may not be sufficient to fully mitigate the issue. 

As noted, the issue with CSME cannot be fixed since the firmware errors are hard-coded in the Mask ROM. Instead of researching and trying options repeatedly which don’t work to fix the direct issue, Intel took this in a different direction and addressed the attack vectors, indirectly working to fix the problem. There are a number of attack vectors with this

References
Allan, D. (2020, March). Latest intel CPUs have ‘impossible to fix’ security flaw. Retrieved from https://www.techradar.com/news/latest-intel-cpus-have-impossible-to-fix-security-flaw
Dent, S. (2020, March 6). Researchers discover that intel chips have an unfixable flaw. Retrieved from https://www.engadget.com/2020-03-06-intel-chips-unpatchable-security-flaw.html
HalGameGuru. (2020, March 6). “Unfixable” security flaw found in intel CPUs. Retrieved from https://linustechtips.com/main/topic/1162393-unfixable-security-flaw-found-in-intel-cpus/
Help Net Security. (2020, March 12). Scientists expose another security flaw in intel processors. Retrieved from https://www.helpnetsecurity.com/2020/03/12/load-value-injection/
KW, T. (2020, March 22). Security experts have found another flaw in intel processors. Retrieved from https://klse.i3investor.com/blogs/future_tech/2020-03-22-story-h1485581927-Security_experts_have_found_another_flaw_in_Intel_processors.jsp
Lemos, R. (2020, March 6). Physical flaws: Intel’s root-of-trust issue mostly mitigated. Retrieved from https://www.darkreading.com/vulnerabilities---threats/physical-flaws-intels-root-of-trust-issue-mostly-mitigated/d/d-id/1337254
Positive Technologies. (2020, March 5). Positive technologies: Unfixable vulnerability in intel chipsets threatens users and content rightsholders. Retrieved from https://www.ptsecurity.com/ww-en/about/news/unfixable-vulnerability-in-intel-chipsets-threatens-users-and-content-rightsholders/
The Star. (2020, March 22). Security experts have found another flaw in intel processors. Retrieved from https://www.thestar.com.my/tech/tech-news/2020/03/22/security-experts-have-found-another-flaw-in-intel-processors
Warrant, T. (2020, March 6). A major new intel processor flaw could defeat encryption and DRM protections. Retrieved from https://www.theverge.com/2020/3/6/21167782/intel-processor-flaw-root-of-trust-csme-security-vulnerability

Sunday, March 22, 2020

U of U Compromises-Uh Oh



The University system tends to focus on research in specific disciplines. These may be business, psychology, sociology, criminal justice, medical, or any of the other areas within the University system. While the staff is fulfilling their tasks, the IT area of operations is continuously working to detect attacks and put in place mitigations to reduce the opportunity for a breach. This is a daunting task for many reasons. One such target was the University of Utah Health system. The organization was unfortunately breached at least twice recently.
Attack
The system is deluged with attacks and the beginning stages of attacks, just like any other medical facility. Unfortunately, two of these recently were successful.

The first was from January 22 through February 27, 2020. This successful attack was focused on email accounts. During this period there was an unauthorized access to a portion of the University of Utah Health staff email accounts. This was accomplished through the infamous phishing attack. This attack vector is so successful with such little capital or effort, this is bound to not slow down.

The second known successful attack was in the form of malware on a system. This was detected on February 3, 2020. Once this was found, the University of Utah Health contacted a third-party cybersecurity organization to assist them with the investigation. This investigation noted the malware may have been able to access a portion of the patient’s data, which was located in the respective employee’s email.
Data
With both of these noted successful attacks, the commonality was an unauthorized access to patient data. With these breach instances, the patient data may have included the patient name, date of birth, medical record numbers, and a limited amount of treatment information.
Post-Attack Actions
The investigation into the attack was not a simple review of logs. The compromises were alleged of a complex nature and of a highly technical nature. This is not an unusual statement by the University of Utah Health. If they were to state the attack was exceptionally simple, the management would be having additional issues from many other parties, including potentially the federal government, attorneys, and others.

The organization is also mailing letters to the affected patients. This is the standard protocol. To lower the potential for this to occur again, the organization is updating InfoSec procedures with the employees. This may or may not be successful, based on the implementation. If after a few months, the management does not reinforce the idea of cybersecurity, any lessons learned will fall by the wayside.
Looking Forward
This is yet another case of where training needs to be done through the year, insightful, and have some level of entertainment. Without this in place, the organizations will continue to be reactive post-breach, instead of pro-active to minimize the potential for a breach. Having known the method for the phishing attack would have been a great step forward. The industry could have learned from this and tailored other’s training to avoid this issue.

Resources
Bennett, L. (2020, March 21). University of Utah health says some patients’ data compromised in ‘phishing’ security breach. Retrieved from https://www.ksl.com/article/46732931/university-of-utah-health-says-some-patients-data-compromised-in-phishing-security-breach

DeWitt, K. (2020, March 20). U of U health announces phishing schemes caused unauthorized access to some employee accounts. Retrieved from https://www.abc4.com/news/top-stories/u-of-u-health-announces-phishing-schemes-caused-unauthorized-access-to-some-employee-email-accounts/

Roberts, A. (2020, March 21). Hacked: Some patient information compromised in U of U Health breach. Retrieved from https://kutv.com/news/local/some-u-of-u-health-patient-information-may-be-compromised-in-data-breach

Hospital pwned!


Hospitals are located throughout the country, and now more than ever are especially operationally stressed. As part of the intake process, the hospitals have to take in patient data. This accumulates rapidly. The hospitals hold a mass amount of patient data. The data grows daily. This data, while it does take space on the servers, also holds value for the bad actors looking to act maliciously with this. There are various tools the attackers can use in order to compromise a system. Munson Healthcare found this out the hard way.
Munson Healthcare
 Munson Healthcare is based in Traverse City, MI. Munson Healthcare operates Munson Healthcare Charlevoix Hospital. This is northern Michigan’s largest health care system. In addition to the Munson Healthcare Charlevoix Hospital, the firm also operations hospitals in Cadillac, Grayling, Kalkaska, St. Ignace, Manistee, Gaylord, and Frankfort.

Attack
After some time, the IT department began to notice certain issues with the email system in January 2020. There was a bit of suspicious activity within the system, which led to further investigation. The IT department detected the root of the issue. The email system had been compromised.
The attackers used the tried and true phishing technique. The attack has such low overhead and ease of use, there is no surprise this was used and was successful. In this case, the victims were actually more than what may normally be encountered. Here, 29 employees took the hook and clicked on a link or opened an attachment they should not have.
As indicated, the phishing attack was successful. The attackers had their unauthorized access from July 31 to October 22, 2019, or over 2.5 months. During this time, the attackers had unfettered access and had the ability to access to patient data. It is surprising it took nearly three months for the IT department to detect the issue. Upon the detection, the healthcare organization contracted with third-party cybersecurity professionals to investigate the breach.
Data
The healthcare facility was not sure how many patients were affected by the breach. The actual number, per the estimate from Munson, is the number is in the hundreds for the affected patients. The patient data may have included the patient names, date of birth, health insurance information, and treatment. The patient data was in the affected employee’s email accounts.
In a limited number of the affected patients, there may also have leaked the financial account numbers, driver’s license numbers, and social security numbers. The limited sample from the overall breached records is much more serious as the data included is more useful when used with the other data.
Post-Attack Actions
Obviously, this is not the optimal circumstance for the healthcare organization. As this included patient data, they had the opportunity to learn from this and report the breach to the U.S. Department of Health and Human Services per HIPAA. In addition to reporting this, the organization also is providing a credit monitoring service for the patients whose social security numbers were included with the compromise.
Internally, Munson Healthcare also had their employees undergo additional cybersecurity training. While this is a step in the right direction, this is a false hope for the future if not implemented correctly. A one-off training this year, and returning to the same routine of the single, annual training where a portion of the employee’s eyes glaze over, while the remainder eyes are trained on their cell phone paying attention to everything except for the presentation.
As for the infrastructure, the IT department has implemented additional cybersecurity measures. Given what occurred, this is a natural extension.
Looking Forward
This is yet another case of where training needs to be done through the year, insightful, and have some level of entertainment. Without this in place, the organizations will continue to be reactive post-breach, instead of pro-active to minimize the potential for a breach.

Resources
Foley, S. (2020, February 29). Munson healthcare notifies patients of data security incident. Retrieved from https://www.cheboygannews.com/news/20200229/munson-healthcare-notifies-patients-of-data-security-incident

Garrity, M. (2020, February 27). 20 michigan Health system employees fall victim to phishing attack, exposing patient data. Retrieved from https://www.beckershospitalreview.com/cybersecurity/29-michigan-health-system-employees-fall-victim-to-phishing-attack-exposing-patient-data.html

Newsbreak. (2020). 20 michigan health system employees fall victim to phishing attack, exposing patient data. Retrieved from https://www.newsbreak.com/news/0OGRRIqF/29-michigan-health-system-employees-fall-victim-to-phishing-attack-exposing-patient-data

Usher, K.H. (2020, February 27). Data breach at munson leaks patient records. Retrieved from https://www.cadillacnews.com/news/data-breach-at-munson-leaks-patient-records/article_661d3882-0b76-51d2-a309-26b7f11eea4e.html

Winant, D. (2020, February 28). 29 michigan health system employees fall victim to phishing attack, exposing patient data. Retrieved from https://seclists.org/dataloss/2020/q1/176

Thursday, March 12, 2020

Key fobs at risk



Key fobs at risk

Charles Parker, II
#
A decade ago, breaking into a vehicle was a relatively easy manual process. As technology improved, there was an increase in the technology implemented in the vehicle. We are to the point where the vehicle is a computer on wheels. This will even be more the case once automotive ethernet is implemented through the vehicle manufacturers.

To remove the opportunity for the theft a new technology was placed in the vehicle-the immobilizers. This reduced the number of key fob attacks by removing relay attacks from the attack surface. These required the attacker to be within the range of the original key.

Cryptography Applied to the Key Fob
The key fobs added a cryptographic function to the unlocking device. The attacker could not simply sniff the key fob communicating with the vehicle and replay the signal to break into the vehicle. The cryptographic function instead worked to scramble the key fob communication.
New Attack
The attack-defense cycle was at work here. The defense (the manufacturer) created a cybersecurity feature to stop the attacks. The attackers viewed this, reverse engineered the process, and created a new attack circumventing the cybersecurity feature. This instance was no different. The attackers grasped the idea of breaking through the feature with the key fobs, researched the idea, and reverse-engineered the process.

The researchers purchased a few immobilizer electronic control units from eBay. With these secured, the researchers were able to reverse engineer the firmware located within the key fobs. The purpose of this was to analyze the method of communication between the key fob and vehicle.
The analysis indicated the key used was very easy to crack. This used Texas Instruments DST80 encryption to secure communication. This normally would not be a significant detriment; however, the manufacturer’s implementation was the issue. For instance, the Toyota implementation was based on the serial number. What made this worse was if someone were to scan this with an RFID reader, it showed the serial number. This portion of the research was not difficult to complete. The RFID readers are for sale on Amazon for under $30. Working with these is not complicated.
Another example involved Kia and Hyundai. These manufacturers used 24 bits of random character rather than the 80 bits the DST80 offers. To put this in perspective the 24 bits used could be cracked with a laptop in a few milliseconds. Unfortunately, the rationale for not using the greater number of bits is unknown. Perhaps this was for a cost or processing time savings.
With either attack, once you have the cryptographic key, unlocking the vehicle and doing as you wish is not a far stretch of the imagination. The only other addition to the attack is the person needs to be able to turn the ignition. This may be bypassed using old-school technology (e.g. screwdriver or hot-wiring).
This was a rather significant decrease in cybersecurity applied to the key fob-vehicle communication process. This is much like cybersecurity retreating to the 1980s.
Application
This serious vulnerability is not applicable to all the models for the three automakers. This issue is applicable to older models. While this is positive, this still has the other vehicles at risk of theft and other malicious actions.
This does, however, affect many models. To show the extent, following is the listing:
Toyota                 Auris                     2009-2013
                              Camry                  2010-2013
                              Corolla                 2010-2014
                              FJ Cruiser             2011-2016
                              Fortuner              2009-2015
                              Hiace                    2010+
                              Highlander          2008-2013
                              Land Cruiser       2009-2015
                              RAV4                    2011-2012         
                              Urban Cruiser     2010-2014
                              Yaris                     2011-2013
Kia                         Ceed                     2012+
                              Carens                  2014
                              Rio                        2011-2017
                              Soul                      2013+
                              Optima                 2013-2015
                              Picanto                2011+
Hyundai               I10                        2008+
                              I20                        2009+
                              Veloster               2010+
                              IX20                      2016
                              I40                        2013
What did we learn?
Over time, security should improve. The attackers are not limiting their attacks or type of technology used for the attacks. They certainly are not moving backward in their attack plans. For the cryptography to be used in the format as it was is not appropriate. The cybersecurity needs to be at least matched, however, it should be optimized against the known and future attacks. This is done through testing and forward-looking cybersecurity architecture.
Cybersecurity needs to be built into the product from the beginning of the project. With this in place, the project’s timeline and costs are kept inline. Having to re-engineer, approve, and retrain staff is a costly venture.
Resources
Ansari, U. (2020, March 6). Poor car keys encryption: Hackers can clone millions of toyota, kia and Hyundai keys. Retrieved from https://www.carspiritpk.com/2020/03/poor-car-keys-encryption-hackers-can-clone-millions-of-toyota-kia-and-hyundai-keys/
E&T. (2020, March 6). Millions of cars’ anti-theft systems vulnerable to hacking. Retrieved from https://eandt.theiet.org/content/articles/2020/03/millions-of-cars-anti-theft-systems-vulnerable-to-hacking/
Greenberg, A. (2020, March 5). Hackers can clone millions of toyota, Hyundai, and kia keys. Retrieved from https://www.wired.com/story/hackers-can-clone-millions-of-toyota-hyundai-kia-keys/
Greenberg, A. (2020, March 7). Hackers can clone millions of toyota, Hyundai, and kia keys. Retrieved from https://arstechnica.com/cars/2020/03/hackers-can-clone-millions-of-toyota-hyundai-and-kia-keys/?comments=1
McClain, S. (2020, March 7). Hackers can clone millions of toyota, Hyundai, and kia keys. Retrieved from https://mashviral.com/hackers-can-clone-millions-of-toyota-hyundai-and-kia-keys/
McKay, T. (2020, March 5). Encryption flaws leave millions of toyota, kia, and Hyundai cars vulnerable to key cloning. Retrieved from https://gizmodo.com/encryption-flaws-leave-millions-of-toyota-kia-and-hyu-1842132716
Whazup. (2020, March 7). Hackers can clone millions of toyota, Hyundai, and kia keys. Retrieved from https://www.wazupnaija.com/hackers-can-clone-millions-of-toyota-hyundai-and-kia-keys/
Wouters, L, Van den Herrewegen, J., Garcia, F.D., Oswald, D., Gierlichs, B., & Prencel, B. (2020). Dismantling DST80-based immobilizer systems. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(2), 99-127. Doi:10.13154/tches.v2020.12.99-127