London Daily

Focus on the big picture.

New Bluetooth hack can unlock your Tesla—and all kinds of other devices

New Bluetooth hack can unlock your Tesla—and all kinds of other devices

All it takes to hijack Bluetooth-secured devices is custom code and $100 in hardware.

When you use your phone to unlock a Tesla, the device and the car use Bluetooth signals to measure their proximity to each other. Move close to the car with the phone in hand, and the door automatically unlocks. Move away, and it locks. This proximity authentication works on the assumption that the key stored on the phone can only be transmitted when the locked device is within Bluetooth range.

Now, a researcher has devised a hack that allows him to unlock millions of Teslas—and countless other devices—even when the authenticating phone or key fob is hundreds of yards or miles away. The hack, which exploits weaknesses in the Bluetooth Low Energy standard adhered to by thousands of device makers, can be used to unlock doors, open and operate vehicles, and gain unauthorized access to a host of laptops and other security-sensitive devices.


When convenience comes back to bite us


“Hacking into a car from hundreds of miles away tangibly demonstrates how our connected world opens us up to threats from the other side of the country—and sometimes even the other side of the world,” Sultan Qasim Khan, a principal security consultant and researcher at security firm NCC Group, told Ars. “This research circumvents typical countermeasures against remote adversarial vehicle unlocking and changes the way we need to think about the security of Bluetooth Low Energy communications.”

This class of hack is known as a relay attack, a close cousin of the person-in-the-middle attack. In its simplest form, a relay attack requires two attackers. In the case of the locked Tesla, the first attacker, which we’ll call Attacker 1, is in close proximity to the car while it’s out of range of the authenticating phone. Attacker 2, meanwhile, is in close proximity to the legitimate phone used to unlock the vehicle. Attacker 1 and Attacker 2 have an open Internet connection that allows them to exchange data.

Attacker 1 uses her own Bluetooth-enabled device to impersonate the authenticating phone and sends the Tesla a signal, prompting the Tesla to reply with an authentication request. Attacker 1 captures the request and sends it to Attacker 2, who in turn forwards the request to the authenticating phone. The phone responds with a credential, which Attacker 2 promptly captures and relays back to Attacker 1. Attacker 1 then sends the credential to the car.

With that, Attacker 1 has now unlocked the vehicle. Here’s a simplified attack diagram, taken from the above-linked Wikipedia article, followed by a video demonstration of Khan unlocking a Tesla and driving away with it, even though the authorized phone isn’t anywhere nearby.



NCC Group demo Bluetooth Low Energy link layer relay attack on Tesla Model Y.


Relay attacks in the real world need not have two actual attackers. The relaying device can be stashed in a garden, coat room, or other out-of-the-way place at a home, restaurant, or office. When the target arrives at the destination and moves into Bluetooth range of the stashed device, it retrieves the secret credential and relays it to the device stationed near the car (operated by Attacker 1).

The susceptibility of BLE, short for Bluetooth Low Energy, to relay attacks is well known, so device makers have long relied on countermeasures to prevent the above scenario from occurring. One defense is to measure the flow of the requests and responses and reject authentications when the latency reaches a certain threshold, since relayed communications generally take longer to complete than legitimate ones. Another protection is encrypting the credential sent by the phone.

Khan’s BLE relay attack defeats these mitigations, making such hacks viable against a large base of devices and products previously assumed to be hardened against such attacks.


On the (link) level


The key to the successful bypass is that, unlike previous BLE relay attacks, it captures data from the baseband—where radio signals are sent to and received from the devices—and does so at the link layer, the very lowest level of the Bluetooth stack, where connections are advertised, created, maintained, and terminated. Previous BLE relay attacks worked at the GATT—short for Generic Attribute Profile—layer, which is much higher up the stack.


Because the link layer is where the credential is encrypted, the new method defeats cryptographic defenses that defend against GATT-based relays. Link layer relays also have significantly less latency than GATT relays because they bypass levels higher up the stack that act as a bandwidth bottleneck. That makes link layer relays indistinguishable from legitimate communications.

Khan’s attack uses custom software and about $100 worth of equipment. He has confirmed it works against the Tesla Model 3 and Model Y and Kevo smart locks marketed under the Kwikset and Weiser brand names. But he says virtually any BLE device that authenticates solely on proximity—as opposed to also requiring user interaction, geolocation querying, or something else—is vulnerable.

“The problem is that BLE-based proximity authentication is used in places where it was never safe to do so,” he explained. “BLE is a standard for devices to share data; it was never meant to be a standard for proximity authentication. However, various companies have adopted it to implement proximity authentication.”

Because the threat isn’t caused by a traditional bug or error in either the Bluetooth specification or an implementation of the standard, there’s no CVE designation used to track vulnerabilities. Khan added:

In general, any product relying on BLE proximity authentication is vulnerable if it does not require user interaction on the phone or key fob to approve the unlock and does not implement secure ranging with time-of-flight measurement or comparison of the phone/key fob’s GPS or cellular location relative to the location of the device being unlocked. GPS or cellular location comparison may also be insufficient to prevent short distance relay attacks (such as breaking into a home’s front door or stealing a car from the driveway, when the owner’s phone or key fob is inside the house).

Making BLE authentication safer


With no patch or fix in sight, what can be done? The answer: require something more than just perceived proximity before trusting the phone or key fob as authentic. One mechanism is to check the location of the authenticating device to ensure that it is, in fact, physically close to the locked car or other device.

Another countermeasure is to require the user to provide some form of input to the authenticating device before it’s trusted. Phone-based security keys that comply with the recently introduced WebAuthn standard, for instance, require not only that the device be close to the machine or account being unlocked but also that a user present the device with a valid fingerprint, facial scan, or PIN. That prevents this attack from working on those devices.

Another countermeasure is to use a phone’s accelerometer to measure its movements. When a device has been stationary for a given amount of time, the proximity key functionality is disabled.

A Kwikset representative said that its iOS app for Kevo has a timeout feature that activates once a device has been stationary for 30 seconds. It also provides an option for requiring a PIN before the device is trusted. Those features aren’t yet available in the company’s Android app. The representative said the company expects the PIN option to be available in the Android app by late September. The attack works only on Kwikset’s Kevo line, the representative said.

Representatives of The Bluetooth Special Interest Group, the body that oversees the Bluetooth standard, issued a statement that read in part: “The Bluetooth Special Interest Group (SIG) prioritizes security, and Bluetooth specifications include a collection of features that provide developers the tools they need to secure communications between Bluetooth devices and implement the appropriate level of security for their products. All Bluetooth specifications are subject to security reviews during the development process.”

Tesla representatives didn’t respond to an email seeking comment for this article.

NCC Group issued a statement about the hack here and has published advisories here, here, and here.

In fairness to both the lock maker and electric car manufacturer, they are only two of the many device makers affected by this new attack. The point of the research isn’t to single out one or two offenders but rather to make clear that BLE authentication based on proximity alone was never something anticipated in the standard and should have been abandoned long ago.

“Over the last decade, industry has turned a blind eye to the risks of relay attacks against proximity authentication systems,” Khan said. “This research demonstrates that Bluetooth Low Energy relay attacks are practical and effective against popular products and highlights the need for the industry to rethink the risk-to-convenience tradeoff for Bluetooth passive entry.”

Newsletter

Related Articles

London Daily
0:00
0:00
Close
Unelected PM of the UK holds an emergency meeting because a candidate got voted in… which he says is a threat to democracy…
You Are So Beautiful
Rob Schneider explains California reparations legislation.
Postmodern Jukebox European Tour Version
Who knew badminton could get so intense?
An old French tune (by Georges Brassens) Pomplamoose ft. John Schroeder
Farmers break through police barriers in Brussels.
Sattahip Motor Show 20
London's Iconic British Telecom Tower Sold To Become Hotel
SONATE AU CLAIR DE LUNE - Moonlight sonata
Ukraine Arrests Father-Son Duo In Lockbit Cybercrime Bust
A kiss to build a dream on
US Offers $15 Million For Info On Leaders Of Cybercrime Group Lockbit
Wonderful Tonight - Eric Clapton (Boyce Avenue acoustic cover)
Russia Claims UK Cultural Agency Spied for Ukraine
Mean Blues
Apple warns against drying iPhones with rice
La Chansonnette
Alexei Navalny: UK sanctions Russian prison chiefs after activist's death
Pattaya Addicts
German economy is in 'troubled waters' - ministry
Franz Liszt - Liebestraum - Love Dream
In a recent High Court hearing, the U.S. argued that Julian Assange endangered lives by releasing classified information.
Dream a little dream of me
New video
Unchained Melody sung like you've NEVER heard!
Tucker Carlson says Boris Johnson wants "a million dollars, in Bitcoin or cash, from Tucker Carlson to talk about Ukraine.
Dave Brubeck - Take Five
Russia is rebuilding capacity to destabilize European countries, new UK report warns
Édith Piaf - Non, Je Ne Regrette Rien (Sofie)
EU Commission wants anti-drone defenses at Brussels HQ
Rondo Alla Turca
Von der Leyen’s 2nd-term pitch: More military might, less climate talk
Kiss of fire
Global Law Enforcement Dismantles Lockbit Ransomware Operation
Tom Jones - I´ll Never Fall In Love Again 1967, 1989, 2001
Prince William Urges End to Gaza Conflict
Israel Cachao López - Guajira Clásica
UK court to hear Assange's final appeal against extradition to the US, where he faces charges related to his journalistic work—the publication of a classified video in 2010 that exposed US war crimes against humanity.
Edward Maya - Stereo Love (feat. Vika Jigulina) (Extended Mix)
About 50-60% kids either chose to be YouTuber or influencer
Strauss - Radetzky March - Karajan
A viral video of Nationals MP Barnaby Joyce lying on a Canberra footpath is celebrated by his media mates.
La vie en rose
European Countries React to Navalny's Death by Summoning Russian Diplomats
The Temptations - My Girl (Smokey Robinson Tribute) 2006 Kennedy Cent
Israel has gone ‘beyond self-defence’ in Gaza, says Labour’s Streeting
Orlando Cachaito Lopez Redencion
English farmers to be offered ‘largest ever’ grant scheme amid food security concerns
Edith Piaf - NON, JE NE REGRETTE RIEN
Cameron government knew Post Office ditched Horizon IT investigation
RADETZKY MARCH-2008-Wien, New Year Concert
EU Calls for Immediate Ceasefire in Gaza Conflict
Only you (And you alone)
EU Vows To Hold Putin "Accountable" After Meeting Alexei Navalny's Wife
Strangers In The Night
EU Launches Probe Into TikTok Over Child Protection Under Digital Content Law
Charles Aznavour - La Boheme
The EU Initiates Naval Mission to Defend Red Sea Trade Routes
Summer time
EU and UK Announce Joint Effort on Migration
Sting and Stevie Wonder - Fragile (from Sting's 60th birthday concert)
Brazil's Lula Likens Gaza Operation to Holocaust, Israel Says "Red Line" Crossed
Aux Champs Elysees
Ministers Confirm Proposal to Prohibit Mobile Phone Usage in English Schools
Stand By Me - Ben E. King (Boyce Avenue acoustic cover)
Microsoft-backed OpenAI valued at $80bn after company completes deal
La Mer (Beyond the Sea) – Avalon Jazz Band
‘Alexei would want to tell Russia not to give up fighting’
She
Rwandan Footballer's Dismissal Sparks Concerns Over UK Asylum Plan
Nathalie Song by Enzo Petrachi Stjepan Hauser Cello
Whisky Challenges China's Baijiu Market During New Year Celebrations
Shape of My Heart - Sting (Boyce Avenue acoustic cover)
Avdiivka - Symbol Of Ukrainian Resistance Now In Control Of Russian Troops
Radiohead - Creep
Putin Critic Alexei Navalny's "Killers" Refusing To Hand Over Body, Say Allies
Quizás,Quizás,Quizás - Andrea Bocelli - Jennifer Lopez
"Historic Step": Zelensky Signs Security Pact With Germany
Perhaps, Perhaps, Perhaps - Multi-Couples
"Historic Step": Zelensky Signs Security Pact With Germany
Pentatonix Havana
20 Tech Giants Sign Effort To Fight AI Election Interference Across Globe
Paula Cole - Autumn Leaves
Joe Biden Accuses Putin of Causing Navalny's Death
Oscar Benton Bensonhurst Blues
Russian opposition leader Alexey Navalny has died at the Arctic prison colony
OH NANANA vs ABUSADAMENTE
Tucker Carlson grocery shopping in Russia. This is so interesting.
Nina Simone - ”I Put A Spell On You”. Vezi aici cum cântă Jeremy Ragsd
Julian Assange's Wife Warns of His Death if Extradited to US
NIGHTWISH - The Phantom Of The Opera
‘A lot higher than we expected’: Russian arms production worries Europe’s war planners
Motorshow 2016 Tanjay Negros Oriental
Greece Legalizes Same-Sex Marriage and Adoption Rights
Monica Bellucci - Ti Amo
Hungarian Foreign Minister: Europeans will lose Europe, the Union's policy must change drastically
Michael Jackson - Billie Jean Milena The Voice France 2018
In Britain Homeowners are receiving CPO’s (Compulsory Purchase Orders) so their homes can be redistributed to migrants
Michael Buble (Help Me Make It Through The Night) feat Loren Allred
Memories Canon In D - Maroon 5 (Boyce Avenue piano acoustic cover)
Matteo Simoni - Marina
Maroon 5 - One More Night
Maroon 5 - Memories
Mark Knopfler - Brothers In Arms (Berlin 2007 Live)
Mark Knopfler & Emmylou Harris - Romeo And Juliet (Real Live Roadrunni
Marina, Marina - The LUCKY DUCKIES intimist live concert at Guimarães
Major Lazer & DJ Snake – Lean On Mauranne The Voice France 2016
Love Theme from Romeo and Juliet - Joslin - Henri Mancini, Nino Rota
LoLa & Hauser - Love Story
Linkin Park Jay-Z - Numb Encore (Live 8 2005)
Hallelujah Mennel Ibtissem, The Voice France Leonard Cohen
Leonard Cohen - Dance Me to the End of Love
Leonard Cohen & Natasha Rostova - Dance me to the end of love
La casa de papel - Bella Ciao
La Camisa Negra
L'italiano (Toto Cutugno) - The Gypsy Queens
Juanes - La Camisa Negra
Jonathan and Charlotte - Britain's Got Talent 2012 Live Semi Final - U
John Powell - Assassin's Tango
Joe Cocker - You Can Leave Your Hat On (LIVE in Dortmund)
Joe Cocker - Unchain My Heart 2002 Live
Joe Cocker - A Whiter Shade Of Pale
Jay Z & Alicia Keys - Empire State of Mind LIVE
Jason Mraz - Im Yours (live)
Jarrod Radnich - Bohemian Rhapsody - Virtuosic Piano Solo
James Blunt - You're Beautiful
James Blunt - You're Beautiful & Bonfire Heart (Live at The Nobel Peac)
If You Go Away - Helen Merrill & Stan Getz (Tribute to Virna Lisi)
I'LL BE MISSING YOU
I Say a Little Prayer
Hotel California ( Eagles ) 1994 Live
Historia de un amor - Luz Casal. Vezi interpretarea Biancăi Sumanariu
Here Comes The Sun - The Beatles (Boyce Avenue acoustic cover) on Spot
Heart - Stairway to Heaven Led Zeppelin - Kennedy Center Honors
HAVANA by Camila Cabello Zumba Pre Cooldown TML Crew Kramer Pastra
HAUSER and Señorita - I Will Always Love You
HAUSER - Waka Waka
HAUSER - Sway
HAUSER - Lambada
HAUSER - Historia de un Amor
HAUSER - Despacito
Great Pretender
Georgia May Foote & Giovanni Pernice Samba to 'Volare' - Strictly Come
Gary Moore - Still Got The Blues
GIPSY KINGS VOLARE Penelope Cruz
Fugees - Killing Me Softly With His Song
French Latino - Historia de un Amor
For A Few Dollars More The Danish National Symphony Orchestra (Live)
Flashdance • What a Feeling • Irene Cara
Filip Rudan - “Someone You Loved” Audicija 4 The Voice Hrvatska Sez
Eric Clapton - Wonderful Tonight
Enya - Only Time
Enrique Iglesias - Bailando (English Version) ft. Sean Paul
Enrique Iglesias - Bailamos
Elena Yerevan Historia de un amor
Ed Sheeran - Shape of You (Official Music Video)
Ed Sheeran - Perfect Symphony [with Andrea Bocelli]
Ed Sheeran - Perfect (Official Music Video)
Easy On Me - Adele (Boyce Avenue 90’s style piano acoustic cover) on S
ERA - Ameno
ELENA YEREVAN- Cancion Del Mariachi-IN STUDIO-2017 DPR
Dust In The Wind - Kansas (Boyce Avenue acoustic cover)
Don't Let Me Be Misunderstood
Despacito x Shape Of You - Pentatonix
Deep Purple - Child In Time - Live (1970)
David Foster When A Man Loves A WomanIt's A Mans World (SealMichael Bo
Dance me to the end of Love ( Pi-Air Design )
Coolio - Gangsta's Paradise (feat. L.V.) [Official Music Video]
Conquest Of Paradise (Vangelis), played on Böhm Emporio organ
Cielito Lindo
Chico & The Gypsies - Bamboleo
Canción Del Mariachi - Antonio Banderas, Los Lobos • Desperado
Camila Cabello - Havana (Audio) ft. Young Thug
Camila Cabello - Havana ( cover by J.Fla )
California Dreamin' - The Mamas & The Papas José Feliciano (Boyce Ave
Buster Benton - Money Is The Name of The Game
Hallelujah Pentatonix
Bobby McFerrin - Don't Worry Be Happy (Official Music Video)
Bob Dylan - Knockin' On Heaven's Door Emilia The Voice Kids France
Besame Mucho - Cesaria Evora
Ben E. King - Stand by Me Sax Cover Alexandra Ilieva Thomann
Bella Ciao
Bella Ciao - INSTRUMENTAL
Beautiful in White x Canon in D (Piano Cover by Riyandi Kusuma)
Bad Romance - Vintage 1920's Gatsby Style Lady Gaga Cover ft. Ariana Savalas & Sarah Reich(1)
BELLA CIAO 2020 - KARAOKE ITALIANO
BAMBOLEO - Gipsy Kings • Antonio Banderas, Katya Virshilas
BAILANDO (original)
Awesome Ukrainian yodeler - SOFIA SHKIDCHENKO (with English subtitles)
Avicii - The Nights
Atom - The Great Gig in the Sky
Aretha Franklin - (You Make Me Feel Like) A Natural Woman (Official Ly
Antonio Banderas - Cancion del Mariachi (Desperado)
André Rieu - Zorba's Dance (Sirtaki)
André Rieu - Can't Help Falling In Love
André Rieu & Mirusia - Ave Maria
Andrew Reyes Elton John - Don't Let The Sun Go Down The Voice 2020 (
Andreas Kümmert Whiter Shade Of Pale The Voice of Germany 2013 Showd
And I Love You So
All About That Bass - Postmodern Jukebox European Tour Version
Alan Walker - Faded (Piano Cover)
Ain't No Sunshine -- Bill Withers (cover by Canen 12 y.o.)
African music
Adriana Vidović - “Creep” Audicija 4 The Voice Hrvatska Sezona 3
Adriana Vidović - “Believer” Nokaut 3 The Voice Hrvatska Sezona 3
A Fistful of Dollars - The Danish National Symphony Orchestra and Tuva
4 Beautiful Soundtracks Relaxing Piano [10min]
2CELLOS - Whole Lotta Love vs. Beethoven 5th Symphony [OFFICIAL VIDEO]
2CELLOS - Smooth Criminal (Live at Suntory Hall, Tokyo)
2CELLOS - Smells Like Teen Spirit [Live at Sydney Opera House]
2CELLOS - Despacito [OFFICIAL VIDEO]
13 Year Old Girl Playing Il Silenzio (The Silence) - André Rieu
094.All About That Bass
00 - SADNESS PART 1
(Ghost) Riders In the Sky (American Outlaws Live at Nassau Coliseum, 1
(Everything I Do) I Do It For You - Bryan Adams (Boyce Avenue ft. Conn
What a wonderful world
Moon river
×