E-Class (W211) 2003-2009

Keyless-Go compromised...

Thread Tools
 
Search this Thread
 
Rate Thread
 
Old 02-28-2011, 03:51 AM
  #1  
MBWorld Fanatic!
Thread Starter
 
Polar Bear's Avatar
 
Join Date: Nov 2004
Posts: 1,691
Received 139 Likes on 94 Posts
W221 S600, W220 S55 AMG Kompressor, W124 300E, W140 S320, W210 E3204M W164 ML320 Bluetec
Keyless-Go compromised...

http://eprint.iacr.org/2010/332.pdf

In essence, they are using a relay attack that extends the range the car can talk to the key. i.e. If you are in a store, an attacker with antenna 1 can approach you. Another attacker with antenna 2 next to your car outside could pull the door handle and the car would actively search for the key. Antenna 2 would receive this "search" signal and relay it to the attacker in close proximity to your location in the store holding antenna 1. Your key would receive this signal transmitted from antenna 1 in the store and would respond. Then antenna 1 would relay it back to antenna 2 close to the car and the car would open (and also start if this was repeated).
Old 02-28-2011, 06:21 AM
  #2  
Member
 
Silly_me's Avatar
 
Join Date: Mar 2009
Posts: 80
Likes: 0
Received 0 Likes on 0 Posts
E320CDI
Attacker with antenna 1 better be smokin hot.


By theory they could start the car and drive off, no?
Old 02-28-2011, 07:03 AM
  #3  
MBWorld Fanatic!
Thread Starter
 
Polar Bear's Avatar
 
Join Date: Nov 2004
Posts: 1,691
Received 139 Likes on 94 Posts
W221 S600, W220 S55 AMG Kompressor, W124 300E, W140 S320, W210 E3204M W164 ML320 Bluetec
Originally Posted by Silly_me
Attacker with antenna 1 better be smokin hot.


By theory they could start the car and drive off, no?
Lol!!!

Yes, they could.
Old 02-28-2011, 07:57 AM
  #4  
Newbie
 
Salmanito's Avatar
 
Join Date: Feb 2011
Posts: 5
Likes: 0
Received 0 Likes on 0 Posts
E 300
Originally Posted by Polar Bear
http://eprint.iacr.org/2010/332.pdf

In essence, they are using a relay attack that extends the range the car can talk to the key. i.e. If you are in a store, an attacker with antenna 1 can approach you. Another attacker with antenna 2 next to your car outside could pull the door handle and the car would actively search for the key. Antenna 2 would receive this "search" signal and relay it to the attacker in close proximity to your location in the store holding antenna 1. Your key would receive this signal transmitted from antenna 1 in the store and would respond. Then antenna 1 would relay it back to antenna 2 close to the car and the car would open (and also start if this was repeated).

Well, Thanks for telling everyone how to steal my car...

Besides, if that's the case, wouldn't that apply to "any" car with the keyless feature...Damn even Mazda has it nowadays..
Old 02-28-2011, 08:12 AM
  #5  
MBWorld Fanatic!
Thread Starter
 
Polar Bear's Avatar
 
Join Date: Nov 2004
Posts: 1,691
Received 139 Likes on 94 Posts
W221 S600, W220 S55 AMG Kompressor, W124 300E, W140 S320, W210 E3204M W164 ML320 Bluetec
Originally Posted by Salmanito
Well, Thanks for telling everyone how to steal my car...

Besides, if that's the case, wouldn't that apply to "any" car with the keyless feature...Damn even Mazda has it nowadays..
You're welcome. Actually you should probably thank the Swiss researchers who discovered this.

If you read the article you would discover that it affects many different manufacturers cars and not just MB.
Old 02-28-2011, 09:24 AM
  #6  
Newbie
 
Salmanito's Avatar
 
Join Date: Feb 2011
Posts: 5
Likes: 0
Received 0 Likes on 0 Posts
E 300
Originally Posted by Polar Bear
You're welcome. Actually you should probably thank the Swiss researchers who discovered this.

If you read the article you would discover that it affects many different manufacturers cars and not just MB.
I knew the Swiss must have had something to do with it

Well, it's good we're not stuck with the keyless feature since it's optional and you might want to use it or not...

So No keyless feature while in LA...
Old 03-01-2011, 01:55 AM
  #7  
Newbie
 
wannabfast's Avatar
 
Join Date: Jan 2011
Location: Bay Area, California
Posts: 2
Likes: 0
Received 0 Likes on 0 Posts
2007 e550 P2, Sports Pkg., aFe Pro Dry S, AMG Pedals, Mud Guards
Thanks Polar Bear! I wrap my extra key in aluminum foil and will need to devise a similar shield perhaps lining the case for the key I carry.

Trending Topics

Old 03-01-2011, 03:05 AM
  #8  
MBWorld Fanatic!
 
WEBSRFR's Avatar
 
Join Date: Apr 2006
Posts: 2,136
Received 40 Likes on 34 Posts
Tesla Model S P100D
This came out quite a while ago and though it is technically possible, it requires quite a bit of groundwork to make it actually work. They basically need to have someone with a transmitter repeater literally a couple of feet from you (yes, a hot woman would probably make this part of the heist a lot easier!) and from there they may need multiple other repeater/transmitters to where your car is for for the initiation of an uninterrupted key less go "handshake." If this ever becomes prevalent there is a pretty easy work around. You can put your keyless go fob in a case/enclosure that blocks RF transmissions and you can just take the key-fob out when you are close to the car.

It is probably not a bad idea for MB to install an "off switch" in the fob for turning off the keyless go handshake transmission so you can turn the fob off when you walk away from the car.

Oh and if the hot woman gets so close to you that she can actually take the key away from you, then all bets are off

Last edited by WEBSRFR; 03-01-2011 at 03:08 AM.
Old 03-01-2011, 07:53 AM
  #9  
Junior Member
 
justinrhenry's Avatar
 
Join Date: Dec 2010
Location: Dallas, TX
Posts: 35
Likes: 0
Received 0 Likes on 0 Posts
2008 E350 4Matic
Originally Posted by wannabfast
Thanks Polar Bear! I wrap my extra key in aluminum foil and will need to devise a similar shield perhaps lining the case for the key I carry.

it also helps if you wrap your head in aluminum foil. better safe than sorry.
Old 03-02-2011, 12:17 PM
  #10  
Super Member
 
Long Islander's Avatar
 
Join Date: May 2003
Location: Long Island, New York
Posts: 877
Received 50 Likes on 35 Posts
2018 E400 4matic Wagon
Originally Posted by WEBSRFR
If this ever becomes prevalent there is a pretty easy work around. You can put your keyless go fob in a case/enclosure that blocks RF transmissions and you can just take the key-fob out when you are close to the car.

It is probably not a bad idea for MB to install an "off switch" in the fob for turning off the keyless go handshake transmission so you can turn the fob off when you walk away from the car.
Of course, any of these solutions essentially eliminate the convenience of having Keyless Go in the first place -- that is, not having to touch or fish your keys out of your pocket, briefcase, etc.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 


You have already rated this thread Rating: Thread Rating: 0 votes,  average.

Quick Reply: Keyless-Go compromised...



All times are GMT -4. The time now is 04:24 PM.