When the keys to the kingdom are very easy to obtain, many question the quality of the keys, but this time, what's in trouble is the kingdom. Millions of vehicles and garages use wireless systems for locking and unlocking doors, but a small device called RollJam, made of just $32 worth of hardware, can intercept the rolling code of a remote and open doors at will.

RollJam: The $32 Gadget That Opens Cars and Garages
RollJam, barely larger than a cell phone

When a device designed to act as a remote keylogger was first discussed, intercepting the keystrokes of a wireless keyboard, more than one thought it was crazy. Years and several proof-of-concept demonstrations later, manufacturers decided to implement encryption systems in their products due to the obvious security risk. Intercepting a wireless signal is not new. This technique has been applied in all sorts of situations, including vehicle theft. The first signs of vulnerability were attacked with a scheme of rolling codes, so that the code is different in each opening, immediately rejecting any repeated code.

How RollJam Works

Even so, with a little creativity, the right software, and $32 in hardware, it's possible to exploit a new vulnerability in that scheme. The person responsible is Samy Kamkar, and the device is called RollJam. Presented officially at the latest DefCon conference, RollJam works in a very particular way: The device is placed at a prudent distance from the vehicle or garage you want to enter. When the owner arrives and presses the button on their remote, the door won't respond because RollJam intercepted the code and transmitted noise to the nearby receiver. The immediate reaction of the user is to press the button again, and this time the door works, but with a critical difference: The code that opens the door is not the one sent by the remote, but the one RollJam recorded first. By using that previous code, and obtaining a reading of the second code generated by the new press, the attacker has a “clean code” with which they can enter the vehicle or garage at the first opportunity.

Which Vehicles Are Affected?

In other words, RollJam is a kind of “man in the middle” that intercepts and releases codes, but always keeps the most recent one. Kamkar used the device on vehicles from different companies, including Ford, Toyota, Nissan, Volkswagen, Cadillac, and Chrysler. The most interesting fact comes from a Cadillac spokesman, who reported that new models adopted a system that adds “expirations” to codes. If each code expires after three or four seconds, the RollJam attack is worthless, but right now there are millions of vehicles exposed, and Kamkar plans to publish the design on GitHub...

Source: