• Germany's news in English

Thieves 'could hack VW, Porsche, Audi cars'

Tom Barfield · 14 Aug 2015, 16:53

Published: 14 Aug 2015 15:01 GMT+02:00
Updated: 14 Aug 2015 16:53 GMT+02:00

Facebook Twitter Google+ reddit

Researchers from the Netherlands and the UK will this week present a paper detailing the flaw in transponders used by Volkswagen (VW) in its Audi, Porsche, Bentley and Lamborghini lines, Bloomberg reported on Friday.

Cars produced by Fiat, Honda, Volvo and Maserati may also be affected.

But rather than publicize and fix the problems, VW took out a court injunction against the researchers in the UK after they showed the company their findings in 2013, preventing publication.

How it works

The loophole, found by Roel Verdult and Baris Ege of Radboud University and Flavio Garcia of the University of Birmingham, targets Megamos Crypto immobilizer transponders, one of the most common brands.

Immobilizers stop the car's engine from starting unless the correct key fob is close to the car's sensors and are used in modern cars with a "start engine" button rather than a turn-key ignition.

"We have reverse-engineered all cryptographic mechanisms of Megamos Crypto... furthermore, we have identified several weaknesses in Megamos Crypto which we exploit in three attacks," the scientists wrote.

In one of the attacks they developed, the researchers used "brute force" - simply writing a computer program to try every possible combination of cryptographic keys – to break into cars in less than half an hour.

Not yet a widespread method

"This isn't a very realistic way of stealing cars" at the moment, security expert Dr David Oswald told The Local.

"For every one of these attacks, you have to speak with both the car and the key at least once. You need to get close."

In most electronically-assisted thefts carried out today, Oswald said, thieves gain physical access to the car before connecting a computer or other device through the vehicle's On-Board Diagnostics (OBD) port, which provides access to the car's computer.

However, Oswald warned that "in the long term, it would definitely make sense to change the transponder. One should always make all components secure."

While private car owners might not be at risk from the technique immediately, Oswald pointed out, there are cases where it would be easier for thieves to access both car and key fob wirelessly – for example, if a criminal rented a car he planned to steal later.

"There are technical solutions that are relatively secure that are available immediately," Oswald said, although they would require physically changing components on every vehicle currently fitted with the Megamos transponder.

For now, while consumers could avoid buying cars fitted with the affected security system, "many other similar systems are not particularly secure either," Oswald warned.

VW says risk is low

In an emailed statement on Friday, a VW spokesman told The Local  that “the thresholds for protection against theft are always being lifted... the ignition lock on some older models of vehicle doesn't match that on our current vehicle modules. That's unavoidable.”

But he added that "even on older models from our product range like the ones the authors' work addressed, the attacker would need at least one key and notes on at least two successful ignitions.”

Similar cases across many different fields of IT security have seen researchers heavily criticize companies for gagging their colleagues rather than fixing loopholes, as happened in this case with the UK injunction.

Story continues below…

"The court proceedings with the universities and the authors before the High Court in London about publication of the article was ended with an amicable compromise," the VW statement read.

"The authors are permitted to publish a part of their scientific work."

The paper has now been published with one sentence redacted, which the researchers say contained a detailed description of calculations performed by the Megamos chip.

"Volkswagen always builds the most modern, technically up-to-date security technology into its vehicles," the statement continued.

But VW added that while it offers software updates where necessary, it is "usually not possible" to update hardware components.

This article was updated on 14/08/2015 with the emailed statement from Volkswagen.

For more news from Germany, join us on Facebook and Twitter.

Tom Barfield (tom.barfield@thelocal.com)

Facebook Twitter Google+ reddit

Your comments about this article

Today's headlines
Germans think they're fit, but they're really couch potatoes
Photo: DPA.

There's been an increase in the number of Germans who define themselves as "fit", but their lifestyle choices don't quite match this self-perception.

Intensive farming 'endangers a third of German species'
Photo: DPA

There are 32,000 species of animal, plant and mushroom life native to Germany. Due to intensive farming methods, one in every three of these is endangered, a new report shows.

German hospital uses therapy to 'treat' paedophiles
A poster from the campaigne "Don't offend", which offers therapy to paedophiles. The sign reads "Do you love kids more than you'd prefer? There's help." Photo: DB Scholz & Friends / DPA.

A unique German initiative is offering therapy to paedophiles to control their urges, with the aim of getting them help before they offend.

Minister: 'no tolerance' for clowns after chainsaw attack
Photo: DPA

Interior Minister Thomas de Maizière has called for a zero-tolerance approach to 'killer clowns' after a series of attacks culminating in two teenagers being chased by a clown wielding a chainsaw.

Baby who was auctioned on eBay taken away from father
Photo: DPA.

A German court ruled on Thursday that a man who put his one-month-old baby up for sale on the online auction platform eBay should only be allowed contact with the child under supervision.

Portugal's ruling party calls German minister 'pyromaniac'
Finance Minister Wolfgang Schäuble. Photo: DPA.

The head of Portugal's ruling Socialists called German Finance Minister Wolfgang Schäuble a "pyromaniac" on Thursday after he criticized Lisbon for reversing course on austerity.

These are Germany's top ten universities
The new library of Freiburg University. Photo: Jörgens.mi / Wikimedia Commons

These are the best universities in all of Germany - at least according to one ranking.

Introducing Swabians - 'the Scots of Germany'
Photo: DPA

These Southern Germans have quite a reputation in the rest of the country.

Woman sues dentist over job rejection for headscarf
Photo: DPA

A dentist in Stuttgart is being taken to court by a woman whom he rejected for a job as his assistant on the basis that she wears a Muslim headscarf.

Isis suspect charged with scouting Berlin attack sites
Photo: DPA

German federal prosecutors said Thursday they had brought charges against a 19-year-old Syrian man accused of having scouted targets in Berlin for a potential attack by the Isis terror group.

10 German clichés that foreigners get very wrong
Sponsored Article
Last chance to vote absentee in the US elections
10 ways German completely messes up your English
Germany's 10 most weird and wonderful landmarks
10 things you never knew about socialist East Germany
How Germans fell in love with America's favourite squash
How I ditched London for Berlin and became a published author
12 clever German idioms that'll make you sound like a pro
23 fascinating facts you never knew about Berlin
9 unmissable events to check out in Germany this October
10 things you never knew about German reunification
10 things you're sure to notice after an Oktoberfest visit
Germany's 10 most Instagram-able places
15 pics that prove Germany is absolutely enchanting in autumn
10 German films you have to watch before you die
6 things about Munich that’ll stay with you forever
10 pieces of German slang you'll never learn in class
Ouch! Naked swimmer hospitalized after angler hooks his penis
Six reasons why Berlin is now known as 'the failed city'
15 tell-tale signs you’ll never quite master German
7 American habits that make Germans very, very uncomfortable
Story of a fugitive cow who outwitted police for weeks before capture
jobs available
Toytown Germany
Germany's English-speaking crowd