Last September we took a close look at this new wave of thefts, which pits technologically savvy thieves against vulnerable cars lacking proper protections. Of course, that hasn't stopped manufacturers from continuing to offer "keyless" locking and ignition systems, very convenient for drivers but tempting to the core for hackers. The latest development comes from a Chinese team that built two devices with $22 worth of parts that easily extend the range of a keyless key…

Stealing cars with $22 in hardware
Team Unicorn

If traditional keys already face security problems (we still remember well the story of the TSA master keys), imagine what is happening with the keyless systems that many manufacturers install in their cars. What seems like a convenient tool for drivers can become a nightmare under certain circumstances. For example, how many of those drivers know how to enter their cars with a keyless lock if the battery runs out? I bet very few, but that's not all. Hackers are having a real feast, and it's only a matter of time before the technology goes from security experts to those with ill intentions. As if that weren't enough, the required hardware is getting much cheaper…

In mid-April, the so-called "Team Unicorn" (Yingtao Zeng, Qing Yang, and Jun Li) from the firm Qihoo 360 demonstrated at the Hack In The Box conference in Amsterdam the effectiveness of a pair of devices whose total cost does not exceed $22. In essence, they work as extenders for the electronic key. One of the devices is placed near the car to be stolen, while the other is placed a prudent distance from the key, and makes it believe it is close to the vehicle. The device picks up the signal and transmits it to its twin, which in turn generates a response sent from the car to the key, all in an interval of 27 milliseconds.

This type of attack is not exactly new. The first efforts began in 2011, and last year it already took just $200 to build the equipment. However, this new development by Team Unicorn has another advantage besides cost, and that is its range. According to available information, the devices cover a distance close to 300 meters. Limitations? Manufacturers could further reduce the interval and complicate the communication. And finally, storing the key in a Faraday bag would prevent the devices from picking up the signal.

Source: