I Hacked Into My Own Car

preview_player
Показать описание

Gaining unauthorised entry to someone else's car is illegal. Jamming is illegal in the UK. It might be illegal where you live too.

Car key fobs transmit a binary code to the car over radio. If the car recognises the code it unlocks. There are various systems in place to make that process secure. This video is about the way vulnerabilities in those systems can be exploited. Including replay and rolljam attacks.

"but most of all, Samy is my hero"

You can buy my books here:

You can support me on Patreon here:

just like these amazing people:

Nathan Williams
Matthew Cocke
Glenn Watson
Mark Brouwer
Joseph Rocca
Joël van der Loo
Doug Peterson
Yuh Saito
Rashid Al M
Paul Warelis
Will Ackerly
Marcel K

Рекомендации по теме
Комментарии
Автор

Let's just pretend this worked flawlessly the first time.

SteveMould
Автор

I also have no idea what I'm doing most of the time.

samykamkar
Автор

6:48
"I tweaked some variables, I didn't have a clue what I was doing, but I noticed that it changed things"
- said almost every engineer at some point. That's how you make discoveries! I love your videos, Steve :D

luk
Автор

I love how you can tell he genuinely enjoys doing this. The smile, the laugh, the energy. Keep up the work!!

jordanericbaird
Автор

1:00 Nice detail on the Bmw parking hahah

AllDayBikes
Автор

I like how the poorly parked car was a BMW, that made me laugh.

ilikaplayhopscotch
Автор

Great video! Thanks.

It’s worth pointing out that looking at a chip under a microscope to reverse-engineer it is pretty challenging, although not technically impossible if you use mechanical-chemical polishing.

Back in 1995 (or thereabouts) when my company at the time was working with something like 2-micron fabrication technology, I was able to diagnose a power-drain by eye-droppering a liquid-crystal solution onto a chip to find the hot spot on the chip. However, even at 2 microns, the image was pretty blurry. 2 microns is about 4 times the smallest wavelength for visible light, so it’s possible, but difficult, to image the chip.

Nowadays though, when the features approaching 1/100 the shortest wavelength of visible light, you pretty much have to use electron microscopes, which only show you the surface. So, to see the internal structure, you have to extremely precisely polish off layer by layer, re-imaging each layer. That’s definitely possible, yes, but very difficult.

mrcet
Автор

Remember: never park your car next to someone in a hoodie and with a laptop

jonathanxdoe
Автор

How to recognize a passionate person? If you approach him with the smallest achievement in his field, he instantly goes "That's great! How does it feel?".

enethion
Автор

A big advantage of Manchester encoding is that every bit guarantees a transition. This means that your signal contains the data and the data rate clock. As you mentioned that the fob can't maintain a consistent transmit frequency, the same is true for the data clock. Manchester allows the receiver to synchronize the data rate. Also, the transmit signal likely starts with the same start byte (most commonly AA or 55) to allow that receiver to lock onto the signal (timing wise) and also adjust its gain (AGC).

connecticutaggie
Автор

that "hacker sitting in the dark in a hoodie" cliche was so well done. love it.

MrJakson
Автор

"I'm in my car! Amazing."

atlas_
Автор

Didn't mention a relay attack which works with modern fobs with passive unlock (where you can walk to the car and just open the door so long as you have the fob).

Two thieves park near a restaurant and observes patrons entering. When they observe a car they want one of them follows the target into the restaurant and walks near them with a transceiver. His partner walks to the car (from which they observed the targets exit from) with the paired transceiver which then relays the passive code from the fob via his partners relay transceiver and the perp opens the door and drives off.

homomorphic
Автор

"What this demonstrates really well is that I have no idea what I'm doing." XD

caleblimb
Автор

To anyone wondering and for the sake of saving history,
This video was reuploaded, because on the first upload it did not have sound in the moments of talking with Samy

kezzyhko
Автор

I just discovered your channel today and already watched two hours of your videos I mean amount of the research and effort you put in each of your video is impressive... Really appreciate what you are doing..

arslanahmedqureshi
Автор

Instructions unclear: I have opened my microwave with a skoda car key.

kahazaba
Автор

"Authorities report nationwide wave of smashed car windows. Suspects say 'Steve told me it was easier'".

johnelwer
Автор

One thing that wasn't mentioned surprisingly is: trying to guess the algorithm based on the samples. Like if you attach device to the car that records the codes send to a car, with enough data you should be able to find some patterns to understand how the codes are generated.

SuperBlackReality
Автор

1:00 BMW is the Apple of cars,
Their motto is “park different”

bobafruti