Most Viewed Content:

Google to bring PWA application backup & restore function for Chrome/android

According to thespAndroid reports, GitHub's Chromium repository recently added...

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

Security Researchers Find Vulnerability That Could Expose Honda Models to Cyberattacks for the Past Decade

Security researchers and The Drive’s Rob Stumpf recently released a video of their use of a handheld radio to unlock and remotely start several Honda vehicles, though the car company insists the cars have security protections that would prevent an attacker from doing such a thing. According to the researchers, the hack was made possible because of a vulnerability in the keyless entry system of many Honda cars built between 2012 and 2022.

They call this vulnerability Rolling-PWN.

The basic concept of Rolling-PWN is similar to the attacks we’ve seen before against Volkswagen and Tesla and other devices where someone uses a radio device to record a legitimate radio signal from a key fob and then transmits it to the car. This is called a replay attack, and if you think it should be possible to defend against this attack with some sort of cryptography then you are right. In theory, many modern cars use a rolling key system, which basically means that each signal only works once; when the button is pressed to unlock the car, the car is unlocked and that exact signal should not be unlocked again.

But as Jalopnik points out, not every recent Honda car has this level of protection. The researchers also found vulnerabilities, and surprisingly, recent Honda cars (especially 2016 through 2020 Civics) instead use an unencrypted signal that doesn’t change. Even those cars with the rolling code system – including the 2020 CR-V, Accord, and Odyssey – could be vulnerable to the recently discovered attack. stumpf even used the vulnerability to fool a 2021 Accord, whose remotely turned on the car’s engine and unlocked it.

Honda told The Drive, however, that the security systems it installs in its key fobs and cars do not allow the vulnerabilities described in the report to be implemented. In other words, the company says such an attack couldn’t happen – but apparently, it somehow exists.

According to the Rolling-PWN website, this attack worked because it was able to resynchronize the car’s code counter, meaning it would accept the old code – basically because the system was built with some tolerance so its security system could be defeated. The site also claims that it affects all existing Honda cars currently on the market, though it says they’ve actually only tested it on a handful of models.

And more worryingly, the site suggests that other brands of cars are also affected, but is vague on the details.

Latest

2024 Beijing Auto Show: All-new Toyota Crown unveiled at the booth

At the Beijing Auto Show, which opened on April...

Teclast P50 Tablet released: Pre-installed with Android 14, Unisoc T606 processor

Teclast today officially announced the launch of its P50...

Nissan’s global sales in March were 365,845 units, YOY increase of 3.3%

Nissan announced the latest production and sales data: global...

Skyworth EV6 II super-charging car 2024 model launched: Starting from 139,800 RMB

The 2024 Skyworth EV6 II car was officially launched...

Newsletter

Don't miss

2024 Beijing Auto Show: All-new Toyota Crown unveiled at the booth

At the Beijing Auto Show, which opened on April...

Teclast P50 Tablet released: Pre-installed with Android 14, Unisoc T606 processor

Teclast today officially announced the launch of its P50...

Nissan’s global sales in March were 365,845 units, YOY increase of 3.3%

Nissan announced the latest production and sales data: global...

Skyworth EV6 II super-charging car 2024 model launched: Starting from 139,800 RMB

The 2024 Skyworth EV6 II car was officially launched...

Kia Sonet SUV launched with optional L2 smart driving assistance

Kia's entry-level SUV Sonet Motors was officially launched at...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

Elon Musk urges RoboTaxi planning and production, priority shifts beyond planned $25,000 model

According to Bloomberg News, this year will be an unstable year according to Tesla’s own standards, mainly due to declining sales, confusion in product...

OPPO K12 launching April 24, boasting 100-watt flash charging and extended battery life

The OPPO K12 phone will be officially announced on April 24, with the slogan “providing 500 million mass users with 100-watt flash charging and...

New electric Mini Cooper starts pre-sale: 3 models, 210,000-270,000 RMB

MINI released the new electric MINI COOPER model. Pre-sales of the new car started at the same time, and three different models were launched:...