A group of German researchers from ADAC have published their work on extending last year's amplification attack that let thieves steal Priuses with a $17 gadget that detected your key's unlock signal and amplified it so it would reach the car.
The researchers have shown that at least 24 different car models from 19 manufacturers are vulnerable to this attack, and can be unlocked and driven away with cheap, easy-to-make radio amps.
The researchers say that thieves are already using this method to steal cars, and point to the surveillance video above as an example of a real-world theft.
Audis have had a similar, unpatched vulnerability for at least five years -- though its details have never been revealed because Volkswagen threatened to sue the researchers who discovered it.
Here’s the full list of vulnerable vehicles from their findings, which focused on European models: the Audi A3, A4 and A6, BMW’s 730d, Citroen’s DS4 CrossBack, Ford’s Galaxy and Eco-Sport, Honda’s HR-V, Hyundai’s Santa Fe CRDi, KIA’s Optima, Lexus’s RX 450h, Mazda’s CX-5, MINI’s Clubman, Mitsubishi’s Outlander, Nissan’s Qashqai and Leaf, Opel’s Ampera, Range Rover’s Evoque, Renault’s Traffic, Ssangyong’s Tivoli XDi, Subaru’s Levorg, Toyota’s RAV4, and Volkswagen’s Golf GTD and Touran 5T. Only the BMW i3 resisted the researchers’ attack, though they were still able to start its ignition. And the researchers posit—but admit they didn’t prove—that the same technique likely would work on other vehicles, including those more common in the United States, with some simple changes to the frequency of the equipment’s radio communications.
Keyless: Easy prey for car thieves
Radio Attack Lets Hackers Steal 24 Different Car Models [Andy Greenberg]
An investigation by Propublica and Bayerischer Rundfunk found 187 servers hosting more than 5,000,000 patients' confidential medical records and scans (including a mix of Social Security numbers, home addresses and phone numbers, scans and images, and medical files) that were accessible by the public, "available to anyone with basic computer expertise."
Of course they announced it at the end of the day on Friday, that’s what you do with bad news.
Iowa state court officials contracted with Coalfire to conduct "penetration tests" on its security; as part of those tests, two Coalfire employees broke-and-entered the Adel, Iowa courthouse, and were caught by law-enforcement, whose bosses in Dallas County were not notified of the test.
If you’ve worked in any high-performing engineering lab, you already know about MATLAB. This computing environment and the language that powers it is perfectly suited to science and math, with an interface that makes it easy to express and visualize complex algorithms – not to mention an infrastructure that lets it easily work with other […]
Studies have shown cannabidiol (more popularly known as CBD) to be effective in two main areas: Pain relief and stress relief. Both of those make the non-psychoactive, cannabis-derived compound a natural for topical creams. There’s no shortage of CBD products out there, but here’s eight of our favorites, all specifically designed for dermatological use – […]
If you’re part of the maker community, you know Make:. Though Make: magazine is off the shelves as of this year, the eBooks and resources put out by Maker Media are still a fantastic resource for the new generation of tinkerers, hackers, and robotics geeks. If you’re in that tribe, listen up: they’ve released a […]