Volkswagen Sued Researchers To Hide Key Hacking Flaw

Bozi Tatarevic
by Bozi Tatarevic

Volkswagen has spent over two years trying to block the publication of a research paper which reveals a key hacking vulnerability in many of their models as well as thousands from other manufacturers. According to Bloomberg, a team of researchers discovered the vulnerability in 2012 and notified Volkswagen in May 2013. Instead of working with the researchers to resolve the issue, Volkswagen argued that the paper would increase the risk of theft and sued them to stop the publication.

The research paper was blocked by an injunction from the United Kingdom High Court for two years and was finally released after originally being blocked from presentation at the 2013 USENIX Security Symposium. The researchers were able to negotiate an agreement with Volkswagen to allow the paper to be published once they removed one sentence that described a component of the calculations on the chip.

The hack describes a vulnerability in transponders that use the Megamos Crypto algorithm that allows brute force attacks to defeat the security mechanism. A similar attack was described by Silvio Cesare last year which allows a radio transmission device to generate potential unlock codes that can be sent to a car until it is opened. This attack goes one step further by using a similar mechanism to generate a response that defeats the immobilizer systems in the affected vehicles and allows them to be started.

The research team of Roel Verdult and Baris Ege from the Netherlands along with Flavio Garcia from the United Kingdom were able to reverse-engineer the Megamos Crypto security mechanisms and were able to recover the 96-bit secret key and transmit it using an RFID device. Their first type of attack is able to exploit a weakness in cipher design which allows recovery of a portion of the secret key by listening in to two legitimate communications between the vehicle and key. The second type of attack uses brute force to send updates to the immobilizer in the vehicle.

This procedure allowed the researchers to generate a secret key in about 30 minutes that was able to start the car. Their last type of attack uses a similar brute force method, but exploits systems that use a weak cryptographic key. These systems can be hacked using a standard laptop in a few minutes due to the fact that they may use a shorter secret key or lack safety mechanisms such as pseudo-random number generators in their algorithm.

Models Affected By The Vulnerability (Models In Bold Tested By Researchers)

This type of security flaw is not something that can be corrected with a software update but would require new keys as well as new immobilizer hardware inside the cars which could be costly for Volkswagen and other manufacturers. Since the flaw did not constitute a safety issue it would not require a recall in most countries.

Volkswagen not only put its own vehicles at a higher risk of theft by suppressing the research, but also caused the risk to go unknown for many other manufacturers who use the same algorithm. Volkswagen states that the current models such as the Golf and Passat use a new algorithm that is immune to this type of attack, but have not offered any assistance to owners of older vehicles with vulnerable systems.

The main issue with the response from Volkswagen is that they look to protect their design by relying on the “security through obscurity” safety mechanism. While lawsuits and injunctions will keep legitimate researchers from publishing information about these flaws, thieves will eventually find a way to break through themselves. This was demonstrated with the Keeloq algorithm in 2007 when proprietary design information was discovered by Russian hackers and leaked online.

The better way to approach these issues is to invite these researchers and white hat hackers to work with the manufacturer once a security system is developed in order to reveal vulnerabilities and fix them before they reach thousands of cars.

[Main Photo Credit: Yahya S/ Flickr/ CC BY 2.0]

[Affected Vehicles Chart Credit: Verdult, Garcia, and Ege]

Bozi Tatarevic
Bozi Tatarevic

More by Bozi Tatarevic

Comments
Join the conversation
3 of 23 comments
  • MBella MBella on Aug 18, 2015

    Electronic keys aren't 100% impenetrable? There needs to be a large class action lawsuit for this. Preferably were the lawyers get 100 million each, and the customer gets a warning sticker.

    • Luke42 Luke42 on Aug 18, 2015

      That's a carguy answer. The computer guy answer is "uhh, this was in the crypto textbook and we knew better all along. Why didn't your engineers read the damn textbook like we did?!?" It's easier said than done, but better crypto is widely available and is something the average engineer can understand if he/she bothers to try.

  • Stuki Stuki on Aug 18, 2015

    Nah, could you imagine the powerful and connected using the legal system to benefit themselves (in the short run, until bonus season), at the expense of those less equal.... How surprising!! But, but the lawyers say they are, like, good, and, like, fight the baaad evil corporations, says the public school indoctrinated progressives with the customary confused looks on their collective faces.....

  • Theflyersfan OK, I'm going to stretch the words "positive change" to the breaking point here, but there might be some positive change going on with the beaver grille here. This picture was at Car and Driver. You'll notice that the grille now dives into a larger lower air intake instead of really standing out in a sea of plastic. In darker colors like this blue, it somewhat conceals the absolute obscene amount of real estate this unneeded monstrosity of a failed styling attempt takes up. The Euro front plate might be hiding some sins as well. You be the judge.
  • Theflyersfan I know given the body style they'll sell dozens, but for those of us who grew up wanting a nice Prelude Si with 4WS but our student budgets said no way, it'd be interesting to see if Honda can persuade GenX-ers to open their wallets for one. Civic Type-R powertrain in a coupe body style? Mild hybrid if they have to? The holy grail will still be if Honda gives the ultimate middle finger towards all things EV and hybrid, hides a few engineers in the basement away from spy cameras and leaks, comes up with a limited run of 9,000 rpm engines and gives us the last gasp of the S2000 once again. A send off to remind us of when once they screamed before everything sounds like a whirring appliance.
  • Jeff Nice concept car. One can only dream.
  • Funky D The problem is not exclusively the cost of the vehicle. The problem is that there are too few use cases for BEVs that couldn't be done by a plug-in hybrid, with the latter having the ability to do long-range trips without requiring lengthy recharging and being better able to function in really cold climates.In our particular case, a plug-in hybrid would run in all electric mode for the vast majority of the miles we would drive on a regular basis. It would also charge faster and the battery replacement should be less expensive than its BEV counterpart.So the answer for me is a polite, but firm NO.
  • 3SpeedAutomatic 2012 Ford Escape V6 FWD at 147k miles:Just went thru a heavy maintenance cycle: full brake job with rotors and drums, replace top & bottom radiator hoses, radiator flush, transmission flush, replace valve cover gaskets (still leaks oil, but not as bad as before), & fan belt. Also, #4 fuel injector locked up. About $4.5k spread over 19 months. Sole means of transportation, so don't mind spending the money for reliability. Was going to replace prior to the above maintenance cycle, but COVID screwed up the market ( $4k markup over sticker including $400 for nitrogen in the tires), so bit the bullet. Now serious about replacing, but waiting for used and/or new car prices to fall a bit more. Have my eye on a particular SUV. Last I checked, had a $2.5k discount with great interest rate (better than my CU) for financing. Will keep on driving Escape as long as A/C works. đźš—đźš—đźš—
Next