Information Security News mailing list archives

Gone in 3 Minutes: Keyless BMWs a Boon to Hacker Thieves


From: InfoSec News <alerts () infosecnews org>
Date: Wed, 11 Jul 2012 02:27:01 -0500 (CDT)

http://www.wired.com/threatlevel/2012/07/keyless-bmw-gone/

By Kim Zetter
Threat Level
Wired.com
July 10, 2012

You've recently spent $64,000 on your flash new BMW with keyless entry. But when you wake up one morning, you discover, in a different kind of flash, that it's gone, stolen by hacker thieves who used the car’s keyless feature to pinch your luxury ride.

This is the reality for a growing number of BMW owners in the United Kingdom who have recently become victim to a spate of thefts, thanks to a couple of security vulnerabilities in the car’s systems. One BMW owner posted a surveillance video of the thieves taking off in the night with his car (see the video above).

The owner, who posted the video at 1addicts.com, suspects the thieves broke the glass to access the BMW’s on-board diagnostics port (OBD) in the footwell of the car, then used a special device to obtain the car’s unique key fob digital ID and reprogram a blank key fob to start the car. It took less than 3 minutes to accomplish the feat. (That said, despite their sophistication, the thieves were, comically, unable to thwart the surveillance cameras, though they tried.)

Below is a video showing how a key fob can be programmed to start a BMW.

[...]

--
Learn how to be a Pen Tester, CISSP, ISSMP, or ISSAP with Expanding Security online.
Come to a free class and see how good and fun the program really is.
http://www.expandingsecurity.com/PainPill

Current thread: