• n3m37h@lemmy.world
    link
    fedilink
    English
    arrow-up
    216
    arrow-down
    8
    ·
    10 months ago

    Let’s ban a product instead of solving the issue at hand… Seriously? I hate my country more and more as each day passes

    • sab@kbin.social
      link
      fedilink
      arrow-up
      53
      arrow-down
      30
      ·
      10 months ago

      While this is seems a bit incompetent, it is easier for them to make technology less available than to fix the underlying issues here. They might set out to do both, but solving the underlying issues will take more time.

      At least they’re trying to do the right thing, and they’re making an effort to deal with a problem that affects real people. Good on them.

      • edric@lemm.ee
        link
        fedilink
        English
        arrow-up
        101
        arrow-down
        3
        ·
        10 months ago

        This is like banning usb cables so Hyundai/Kia cars won’t be stolen, instead of forcing the car manufacturer to just install an actual immobilizer on affected vehicles. Seeing Hyundai/Kia do everything but install immobilizers is infuriating as well. They’re rolling out software updates, giving out wheel locks, installing cages on the ignition panel, etc. Literally everything but fix the problem.

        • BossDj@lemm.ee
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          57
          ·
          10 months ago

          This is like banning usb cables

          If USB cables were used almost exclusively for illegal and just generally anti social behavior.

          I’d never heard of this thing, and it does sound fun, but this was the use case list from the paragraph calling it a “humble hobbyist device” doesn’t come across as very defensible:

          People can use them to change the channels of a TV at a bar covertly, clone simple hotel key cards, read the RFID chip implanted in pets, open and close some garage doors, and, until Apple issued a patch, send iPhones into a never-ending DoS loop.

          But also agreed on fuck those car companies that just don’t care and would rather weaponize the government than try to fix anything (without a subscription fee of course). Anti social behavior forced Kia to change their shitty grift of a product so 🤷

          • edric@lemm.ee
            link
            fedilink
            English
            arrow-up
            57
            arrow-down
            3
            ·
            10 months ago

            exclusively for illegal and just generally anti social behavior.

            Except they aren’t. These devices are used for various non-illegal purposes and are actually helpful for pentesters so we can learn about potential vulnerabilities on wireless systems before they can be exploited by bad actors. The same way a usb cable is useful for transferring data and at the same time can be used for illegal stuff (like literally any hack where you connect to a device via usb). The worst part (and the article mentions it), is that it doesn’t even work on security systems on cars built since the 90’s. So they’re banning something that isn’t even a problem in the first place.

            • BossDj@lemm.ee
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              23
              ·
              10 months ago

              I totally get and agree this is a dumbfuck response to the problem they allege to be fixing, and hopefully their committee it whatever concludes the same, but the article didn’t mention any redeeming values for the device as you did

      • seang96@spgrn.com
        link
        fedilink
        English
        arrow-up
        33
        arrow-down
        3
        ·
        10 months ago

        The problem is they are banning a device that doesn’t solve the issue at all except if you have a car from before the 90s. The tools being used for this are custom made with a much larger range. Maybe they should ban smartphones too since people are using them to detect laptops in cars to break into since they are being stupid about it.

      • n3m37h@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        1
        ·
        10 months ago

        It won’t stop theives from being able to obtain them. And it’s a legit tool, should we ban all usb because they can be used to steal Hyundai and Kia cars?

        It’s obvious there are flaws to car manufacturers theft protection. Shit watch LPL, lock noob, Bosnian Bill (hope you’re doing well brother) and you will see most locks are a fucking joke.

        There are Defcon vids on YouTube that go over how cars can be hacked yet manufacturers are still using these systems

      • Cethin@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        10 months ago

        This device is probably not what a professional car thief would use. It may be used sometimes by someone messing around, but it’s a tool made for an introduction into different types of penetration (testing). It doesn’t do anything as well as a more dedicated device would, and it’s also not as customizable. If a car is vulnerable to this then it’s vulnerable to a lot more things. Also, if someone really wants to steal your car they don’t need this device specifically.

      • n3m37h@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 months ago

        More like hide the problem so no one knows about it. This is the entire locksmith ideology, security through obscurity and that has been working out great hasn’t it?

        I don’t have any faith in our incompetent government to do anything right if it costs corporations money.

    • Toribor@corndog.social
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 months ago

      I figure half the purpose of these sorts of devices is to prove just how insecure certain systems are to bring about change. Governments rarely have a good grasp on this sort of thing though. It’s not like banning the device will make anyone more secure.

      • n3m37h@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 months ago

        Who gives a shit? He prob doesn’t know what it is or what it is used for either, and neither does his party apparently

    • Jaytreeman@kbin.social
      link
      fedilink
      arrow-up
      2
      arrow-down
      39
      ·
      10 months ago

      Pick an issue. Literally any issue. Canada isn’t on the morally right side (with the exception of supporting Ukraine’s war for freedom).
      People are fine. Landscape is amazing. Government at all levels needs to be gone. We’d be better off with actual criminal mobs running everything. They’d at least be competent

  • fmstrat@lemmy.nowsci.com
    link
    fedilink
    English
    arrow-up
    183
    arrow-down
    4
    ·
    10 months ago

    Read everyone, this is hype, and Canada is being dumb on this one.

    The Flipper Zero is also incapable of defeating keyless systems that rely on rolling codes, a protection that’s been in place since the 1990s that essentially transmits a different electronic key signal each time a key is pressed to lock or unlock a door.

    Most of this reaction is due to staged videos on TikTok and politicians not understanding technology. Maybe they’ll stop a few joyriding kids, but car thiefs aren’t using F0s.

    • Billiam@lemmy.world
      link
      fedilink
      English
      arrow-up
      72
      arrow-down
      1
      ·
      10 months ago

      Politicians passing laws based on things they don’t understand?

      Quelle surprise.

      But also:

      a protection that’s been in place since the 1990s

      That’s not necessarily a guarantee, c.f. Hyundai and Kia’s lack of ignition locks.

      • centof@lemm.ee
        link
        fedilink
        English
        arrow-up
        19
        arrow-down
        2
        ·
        10 months ago

        Politicians passing laws based on things they don’t understand?

        aka virtue signaling

        • BearOfaTime@lemm.ee
          link
          fedilink
          English
          arrow-up
          9
          arrow-down
          1
          ·
          10 months ago

          Another way of saying that is moral grandstanding, which I kind of like better. I like the imagery of grandstanding, especially when describing politicians.

        • Billiam@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          10 months ago

          That’s because you all up there in America Lite hate capitalism, freedom, democracy, eagles, and baby Jesus.

    • Aatube@kbin.social
      link
      fedilink
      arrow-up
      10
      arrow-down
      3
      ·
      edit-2
      10 months ago

      Isn’t it possible for someone to code a code-roller onto the flipper zero app store?

    • Player2@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      2
      ·
      10 months ago

      With a jammer it’s definitely possible to bypass rolling codes with Flipper, but it’s only temporary and has limited usefulness

      • KairuByte@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        15
        ·
        10 months ago

        That isn’t bypassing rolling codes, that’s capturing a single code while preventing it from reaching the car.

        And once the code is used once, or the fob gets a new code to the car, the previously captured code is useless.

        This isn’t the same thing as bypassing rolling codes.

        • Player2@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          10 months ago

          Hmm, I don’t know the precise terminology, I meant bypass as a way to temporarily get around the rolling code system without actually breaking the code itself. You’re probably right though

      • Takumidesh@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        10 months ago

        It’s pretty difficult, you need to get the rolling code from the fob, but you also need to jam it so it doesn’t reach the car.

        Then you have one opportunity to replay the code before the holder of the fob hits the button in range and rolls the code over.

        So even if you manage to set that up that only gets you in the car, it doesn’t get it started.

        • Player2@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 months ago

          Yes correct, just pointing out that it is technically possible to get around the system

  • cheet@infosec.pub
    link
    fedilink
    English
    arrow-up
    140
    arrow-down
    2
    ·
    10 months ago

    Im a security professional who works to harden medical devices. I use the flipper zero to easily test many different protocols that would be a pain in the ass to do “manually”.

    The flipper makes it easy for me to verify IR, sub GHz, USB, SPI, and many other protocols while being able to walk around the devices I test.

    Without the flipper I could totally do these checks with homebrew tools, a pi and an rtlsdr (unless thats gonna be illegal too?) But it would take me writing new tools and procedures rather than the ease of the flipper.

    Anybody in the know can tell you that the hardware isn’t anything special, and like many others have said, its like making a swiss army knife illegal cause the toothpick can be used to pick a lock.

    This isn’t gonna stop anybody, if pentest tools are showing flaws in your product, maybe we should send flippers to the car manufacturers and tell them to fix their shit. You shouldn’t be allowed to sell a car that can be wirelessly hacked like this, just like how the FDA doesn’t let you sell medical devices that can be hacked like that.

    You don’t just put the cat back in the bag…

    • kameecoding@lemmy.world
      link
      fedilink
      English
      arrow-up
      29
      arrow-down
      4
      ·
      10 months ago

      Based on your description it sounds like banning the flipper would be encouraging security throigh obscurity

      • go_go_gadget@lemmy.world
        link
        fedilink
        English
        arrow-up
        48
        arrow-down
        2
        ·
        10 months ago

        I remember when they had the same conversations about packet sniffers.

        Turned out the answer was to use encryption and switches.

    • sebinspace@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      10 months ago

      My girlfriend has a medical implant for her gastroparresis. How concerned should we be? If that device shuts off, she can’t eat, and there’s only a handful of doctors in the country that can work on it, and the one that sees her is often booked two weeks out

      • cheet@infosec.pub
        link
        fedilink
        English
        arrow-up
        10
        ·
        10 months ago

        The thing is, if there’s a wireless exploit/hack that can cause “patient harm” the FDA+Health Canada would force a recall the sec its publicly known.

        The flipper wouldn’t be the only thing able to exploit it, anybody with a radio and some software would be able to. It just so happens the flipper can also do it cause its a swiss army knife and has a general purpose radio.

        Generally by the time an attack exists on the flipper, its already been mastered on laptops and raspberry pis and stuff, putting it on the flipper is more to make it available to test easily without having to lug out the laptop. Nobody is inventing new exploits for such underpowered hardware as the flipper. People are porting known exploits to it.

        I can’t say how concerned you should be, but this won’t make her any safer than before, equal risk. Just as likely someone with a laptop in a backpack doing that. We don’t make laptops illegal tho.

        What I would be concerned about is the idea that the company that makes the implant would not be able to easily test for issues in the implant with such an “illegal” device. Yes they could use a laptop, but you don’t use an xray machine to find a stud, you use a handheld studfinder cause its cheap and easy.

        Hope that helps explain a bit

        • sebinspace@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          10 months ago

          the flipper wouldn’t be the only thing able to exploit it

          No, and I never once thought these capabilities were unique to the Flipper. My concern is how much it lowers the barrier of entry to potentially dangerous behavior. When people say they got one “just to be evil”, it’s deeply concerning. If someone said the same thing about a gun, something else that can be dangerous and needs to be handled responsibly, I’d be notifying someone. It’s not the capabilities themselves, it’s how accessible it makes those capabilities to the otherwise-inept

  • Obinice@lemmy.world
    link
    fedilink
    English
    arrow-up
    105
    ·
    10 months ago

    The device only gives easy access to already extremely weak/non existent security systems. That’s literally it.

    It’s just something that’s existed forever, but put into a convenient package and marketed well enough that suddenly normal people are realising how insecure their electronic systems actually are.

    Kinda like how they used to make pacemakers hackable because they never thought to add any security at all. I bet many of them still don’t.

    Anyway, the issue lies not with this device, which can’t “hack” anything with any actual security, the issue is with manufacturers making devices that literally leave the door wide open to anybody with an extremely basic electronic sniffer/cloner device.

    • mesamune@lemmy.world
      link
      fedilink
      English
      arrow-up
      39
      ·
      10 months ago

      Yep you can do the same operations with a RTLSDR (20-40$) and a signal repeater (20ish) and raspberry pi/netbook. It’s somewhat harder to do if you don’t know the software but it really just exposes very insecure hardware. Companies should put a semblance of security and it would take care of things. These kind of devices are everywhere not just the flipper. Flipper just made it a tiny bit more friendly.

    • pezhore
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      2
      ·
      10 months ago

      I have one and I highly recommend the wifi card. I also have a slightly working Carbon Dioxide sensor - I say slightly because it’s readings are consistently off when compared to my Aranet. Supposedly there’s a way to calibrate, but I haven’t had time to dig into it further.

      My only issue with the device is that I wish there were more tamagochi elements to the dolphin buddy.

  • Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    91
    ·
    10 months ago

    If the flipper can help you stealing a car, the flipper is not the problem, but the neglect and incompetence of the car company is.

    • NeonKnight52@lemmy.ca
      link
      fedilink
      English
      arrow-up
      26
      ·
      10 months ago

      I work for a company of under 100 employees in a small city. Our head IT guy bought a Flipper Zero with his own money so he could make sure our building key fobs couldn’t be easily copied.

      If this guy can do it, I think the bajillion dollar auto industry can figure out a solution!

      • AnAngryAlpaca@feddit.de
        link
        fedilink
        English
        arrow-up
        15
        ·
        10 months ago

        A single guy does not have 3 layers of managers and bosses above him, who have “better ideas”, costscutting policies and “i have no idea what you just explained to me, so lets just not do it!”.

        • NeonKnight52@lemmy.ca
          link
          fedilink
          English
          arrow-up
          8
          ·
          10 months ago

          Absolutely. I bet it’s just easier and cheaper for them to not bother securing their fob radio.

          To be clear, I’m saying they should get their shit together as a company, because it’s clearly not a hard thing to fix.

  • xthexder@l.sw0.com
    link
    fedilink
    English
    arrow-up
    88
    arrow-down
    2
    ·
    10 months ago

    "It is unacceptable that it is possible to buy tools that help car theft on major online shopping platforms.”

    I can buy a hammer and screwdriver online, and those could be used for car theft. Does that make those also unacceptable?

    • el_abuelo
      link
      fedilink
      English
      arrow-up
      6
      ·
      10 months ago

      They’re also really good at murder, a much more serious crime.

      While we’re at it let’s just ban all metal cutlery, just to be on the safe side.

  • Rentlar@lemmy.ca
    link
    fedilink
    English
    arrow-up
    74
    arrow-down
    2
    ·
    edit-2
    10 months ago

    It’s called pretending to do something about the problem.

    The way they get access is by amplifying a signal of a car key near the entrance to trick the car into thinking the key is nearby. Others do just pick the driver’s side lock. Then once inside, they connect to the vehicle and pair new keys so they can drive away in less than 10 minutes.

    I’ve never understood the way modern cars just unlock without any button press, that seems really insecure. Some organized thieves probably aren’t even bothering with lock-picking and ignition hot-wiring these days as older cars would be low value to them. Oh and if a random crackhead really wanted something in the car they would probably just smash the window or pry the door anyway.

    A solution would be a 24 hour lockout timer to program new keys. That would prevent mall jackings and be a small incovenience for repair shops to need to keep cars in the garage overnight.

    • centof@lemm.ee
      link
      fedilink
      English
      arrow-up
      28
      arrow-down
      6
      ·
      10 months ago

      I call it virtue signaling. It’s the same idea, just a clearer term for it.

      Do those mythical organized thieves really exist? I think 80+% of crimes are crimes of opportunity done by vulnerable people like crackheads, mentally ill, or other low income people.

      • Rentlar@lemmy.ca
        link
        fedilink
        English
        arrow-up
        21
        ·
        edit-2
        10 months ago

        Well you can address drug addiction and vulnerability to an extent but this is about autotheft? What do drug addicts or vulnerable low income people need 6497 stolen cars for? Those will probably be caught relatively easily anyway if they just drive in the area.

        The thing is that they ship these cars overseas as quick as possible and for big money and nearly impossible to recover. You can’t do that as some lone Joe looking for your next blow, it’s a profitable criminal enterprise with multiple people taking part, to steal the cars, schmooze through the paperwork, get the cars in containers to ship, then receive payment at the other end.

        • centof@lemm.ee
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          10 months ago

          Crimes of opportunity are not need based, they are want based. People take something because they want it and are unconcerned with the potential consequences of taking it. Even the cop quoted in your linked article admitted that 'Cars stolen for the purpose of committing another crime are not what’s behind the majority of thefts.

      • nyan@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        11
        ·
        10 months ago

        Some of the initial carjackings may be opportunistic, but the people shipping the stolen cars out of the country are definitely organized.

      • dexa_scantron@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        edit-2
        10 months ago

        Nah, flip that around. What’s a random crackhead going to do with a stolen car? Vs an already-organized and knowledgeable business like a towing company who wants to add a lucrative side gig. That’s who’s doing catalytic converter theft, too.

        • centof@lemm.ee
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          1
          ·
          10 months ago

          I would say my OC at least applies to the people who get caught. Maybe not always to those who actually do the crime.

    • Death_Equity@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      10 months ago

      Cars that unlock without pressing anything or by pressing a button on the door look for the key that is bound to them. It is secure in that only a key programmed to the car can tell the car it is ok to unlock. They keys are authenticated with a rolling code that is synced between a car and key when the key is programmed to the car. Thieves clone the key’s signal and then the car has no idea that the fake key is not the real key.

      You can’t hotwire a modern car. On a modern pushbutton ignition car the starting function is allowed through a security module that makes sure the key is there before starting. Pushing the button only asks permission to start the car and then the module is the one that tells the car to start.

      Lock-picking a modern car can be done, but it is far easier to use a wedge and inflatable air bag to pry the door open enough to use a hooked tool to open the door from the inside. Nobody picks automotive locks anymore, a lot of the door locks can be ripped out and bypassed anyways. You can of course just break the glass, but it may sound an alarm. The F150 has a massive theft issue Ford won’t bother to address, the alarm can be disabled from outside the car using no tools whatsoever.

      Once a thief has access to the inside of the car, they can program a new fake key using specialized software which is usually dealer level software but it can be done using 3rd party software. You can’t just ban all non-dealers from having the capability to reprogram keys, that is user-repair hostile and would mean you have to pay whatever the dealer wants to replace a lost or damaged key. Not to mention that thieves will still find a way to access dealer tools and keep on stealing anyways.

      A lockout period wouldn’t accomplish anything, the original key still gets cloned and can be used to drive the car away. Once the stolen car is taken, the thieves have all the time they want to reprogram a key.

      Enhancing security measures by using a more secure key authentication method will only go so far as to preventing theft and will add considerable costs to cars and key replacement. Thieves will catch up to any means of securing cars. A better solution is to improve economic prospects and enforce the current laws effectively to remove incentive to steal cars.

      • Rentlar@lemmy.ca
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        10 months ago

        Your points are all valid and I agree with your suggestions. I still think every hour of delay is important to try to track down the car before it gets out of the country…

        So compare an easy to steal car with a keyed ignition, with a modern push to start car. I don’t drive now but I used to drive the former. It wouldn’t sell for much in a used market or criminal market. Being stolen for use in a crime it may be more useful on the other hand. I don’t know if thieves looking for easy marks would go for that car over one with more modern tech…

        • Death_Equity@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          10 months ago

          Auto theft for sale in a foreign market or domestic is uncommon and mostly dealing with valuable or rare cars and typically happens within a gas tank of a international boarder. More common is for breaking down and selling parts, but that is still not that typical. Most auto theft is for personal use and to commit crime. The breakdown of types of thefts changes with area, so in America personal use or crime is more common than Europe where chopping or foreign sale is more common.

          Most turn-key ignition cars can’t be hotwired either, they have immobilizers that require a security chip authentication within the key. Most of the cars that can be hotwired are from before 2005, after that they get rarer. If it has an all metal key, those definitely can be hotwired.

          When it comes to tracking, by the time the car is located it is done being used. Most cars do not have any form of tracking that is accessible to law enforcement with cooperation from manufacturers. Modern cars with tracking can have their GPS or cell network disabled by pulling the right fuse with no impact on the drivability of the car. Aftermarket trackers are harder to disable if they are installed correctly and can lead to a faster recovery if the police move fast enough. Once the car is taken and the GPS fuse is pulled, they can keep the car indefinitely without fear of getting caught via tracking. If an aftermarket tracker is used, they just need to have the car in a place that will block the signal for long enough to disable it and then move the car again fast enough. Cops move slow, you can tell the cops where it is right now and they may not attempt recovery for hours.

          Since the majority of auto theft is just looking for a car to ditch, in America, the easier to steal the better and it doesn’t matter what the car is. F150s and Kia/Hyundai are the most popular now because they are easy to steal and common as dirt but grabbing a 2022 Honda that is left running or grabbing the keys from a driver are popular options.

      • Rentlar@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 months ago

        Then what’s the manufacturer’s excuse for not having them on current models? It would prevent the “one and done” type of attacks, there’s at least a chance that any setup gets caught on camera before the car is stolen later?

        • Madison420@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 months ago

          Ford still does have program timeout, like I said some cars have had it some haven’t and I can’t and moreover won’t try to explain anyone else’s feelings.

          • Rentlar@lemmy.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            10 months ago

            I understand. I’m upset at this but not trying to take it out on the messenger.

  • ulterno@lemmy.kde.social
    link
    fedilink
    English
    arrow-up
    62
    arrow-down
    1
    ·
    edit-2
    10 months ago

    Sure, go ahead and blame the tool.
    Then blame the science.
    Then blame the scientists who developed it.

    Blame everything but the thief.

    \s


    Then blame free will for all crime in the world and all wars waged.

    • hyperhopper@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      10 months ago

      First blame the thief. But then in the same breath blame the manufacturers that refuse to sell cars with meaningfully working locks. If you understand the tech many car companies keep selling cars that have locks that are about as secure as a zip tie.

      • ulterno@lemmy.kde.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 months ago

        The companies will just go around blaming some random engineer for it and then go on throwing money for PR stuff.

  • MTK@lemmy.world
    link
    fedilink
    English
    arrow-up
    51
    ·
    10 months ago

    Car security is horrible

    I bought a copying remote from aliexpress thinking “no way my car has a static code and not a rolling one… right?”

    Nope, fuck you Kia, any stupid cheap remote from aliexpress can be used to copy keys from a surprising amount of cars.

    Car security should improve and I hope this becomes a big enough issue that it get’s better regulated

    • MrFunnyMoustache
      link
      fedilink
      English
      arrow-up
      9
      ·
      10 months ago

      I would have expected an OTP type code to unlock a car… Considering how expensive cars are, this is really cheap to implement. Heck, I could buy a yubikey for €25, and I’m sure if a big company wants to buy a million of them, they can do it for a fraction of that cost… A brand new car costs tens of thousands…, it should’ve been a no brainer to include better security.

      • The Menemen!@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        edit-2
        10 months ago

        Yeah, but saving 1.50 per car improves some stupid business performance indicator, which respectively will get some manager a nice bonus.

        • MrFunnyMoustache
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 months ago

          I believe you, this world is so weird… For companies that make tens of billions in profit, saving a million dollars on chips is almost a rounding error compared to the benefit to their reputation when their cars are more secure.

          • The Menemen!@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            10 months ago

            Ever since I first met the insanity that are business indicator numbers, I lost my believe in humanity. People knowingly hurt their companies effectiveness and prosperity just to improve those numbers. And they get rewarded for it.

  • Rediphile@lemmy.ca
    link
    fedilink
    English
    arrow-up
    46
    arrow-down
    1
    ·
    10 months ago

    Just ordered one. I had no real interest, but once you tell me I can’t have one…I must have one.

  • banneryear1868@lemmy.world
    link
    fedilink
    English
    arrow-up
    37
    ·
    10 months ago

    RollJam and RollBack are the exploits for bypassing rolling codes. These exploits are possible because you can replay captured codes at a later time.

    What’s happening in most cases is the proximity-based fobs are simply amplified with a device to reach the person’s car in the driveway, since most people keep their keys by the door, and in some cases even within reach of the car without a device. It’s this low hanging fruit where the theft happens, or just a tow truck…

    The Flipper is more of an enthusiast and pranking device. The devices used in actual thefts are like disposable $50 alibaba pieces of shit. Canada is effectively creating a clandestine market for simple radio amplifiers made from the most basic electronic components. As someone in Canada who used to build the classic cmoy Altoid-tin headphone amps to sell on etsy, this is tempting…

  • Xavier@lemmy.ca
    link
    fedilink
    English
    arrow-up
    35
    ·
    10 months ago

    Honestly, I am embarrassed with the whole “look like were doing something” shtick by my government. An expensive gathering of decision makers from various sectors, a National Summit, just to say: we are now gonna be soooo tough on crime and let’s ban the toy we just saw on TikTok.

    Car theft was a major problem before 2010 until engine immobilizers became mandatory since 2007 on all vehicles made in Canada

    Then everyone got too comfortable. The regulatory bodies and car manufacturers were too focused pretending doing some work and publishing all the buzzword-of-the-day “accomplishments” they were doing while patting each others backs without explicitely requiring manufacturers to comply/implement immediately anything. Meanwhile, manufacturers were happy to integrate almost off-the-shelf “children’s RC” car starter pack obfuscated through invisible/non-existent security and protected under dubious industrial secrets.

    Obviously, criminals smelled the easy money. Starting around 2013 — mystery car unlocking device | 2015 — signal repeater car burglary, car thefts by relay attacks were known by automakers but ignored as one-offs, too technical, already dealt with by law enforcement to lets pretent it’s not that big of a problem or leave it to the police. Meanwhile, insurance claim replacement vehicles are selling like hotcakes and it is “convenient” to ignore the problem.

    The following years various reprogramming theft become known and finally CAN bus injection — new form of keyless car theft that works in under 2 minutes or in depth investigation by Dr. Ken Tindell, becomes so easy, so cheap and widely available that even kids uses them to gain Youtube/TikTok followers.

    Car hacking was a becoming serious concern during the pandemic, but now it’s simply ridiculous and as if current automaker included/provided anti-theft/GPS tracking were (un)knowingly made “defective”.

    Hence, everyone is playing catch up and blaming left and right on who is responsible for this in-slow-motion public safety disaster.

    Brian Kingston, president and CEO of the Canadian Vehicle Manufacturers’ Association, which includes Ford Motor Company of Canada, General Motors of Canada and Stellantis, said increasing the risk of prosecution is the most effective way to deter vehicle theft.

    “And at the same time, providing more outbound inspection controls at the ports to prevent the flow of stolen vehicles to foreign markets by organized criminal organizations,” he added.

    New vehicle safety standards have been published (rushed?) recently. We will see if all the panic settles down like after 2007.

    Moreover, the exponential prevalence of car theft also laid bare the incredibly poor and ineffective security at the various ports of Canada. Unsurprisingly, it has been a known constant devolution:

    The devolution of port authorities in Canada has not been without debate over the past 70 years. This paper provides a brief introduction to the role of ports in Canada and then examines the history of port policy and devolution, concluding that past policies were considered to have failed due to their inability to respond to changing circumstances.

    • ArbiterXero@lemmy.world
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      2
      ·
      10 months ago

      Clearly criminals who steal cars will DEFINITELY listen to this new law banning their tools.

      • Mr_Blott@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        7
        ·
        10 months ago

        That said, this is the argument that gun-owning cowards use, so does it fall under the “How do we stop this happening, says only country in the world where this happens regularly” category?

        Probably a wise move to nip it in the bud

        • WorseDoughnut 🍩@lemdro.id
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 months ago

          Insane take.

          You’re talking about outlawing the equivalent of a lock picking set. This tool is used by legitimate security researchers and professional penetration testers all the time. Making this type of hardware less accessible only hurts.

        • ArbiterXero@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 months ago

          Maybe, but guns are a very different problem.

          A toddler won’t kill their sibling with this by accident.

      • papabobolious@feddit.nu
        link
        fedilink
        English
        arrow-up
        5
        ·
        10 months ago

        I guess it could steal maybe some 90s cars with remote fobs, but I don’t think it can do modern keyless entry cars in any useful way.

      • Herr Woland@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 months ago

        Not only that, you can easily buy more advanced car stealing tools that are made for this purpose from Chinese websites.