|
|
|
|
|
by nine_k
1269 days ago
|
|
Responsible disclosure exists for serious exploits, and it sort of works. Auto makers had ample time to learn that their current radio-operated locks are insecure by design. They had years while everybody even slightly interested knew e.g. how a replay attack can be done. Did they need any more responsible disclosure time in order to act? BTW there's no need to radically invent anything in that space; say, SSH offers a working example of a tamper-proof, eavesdropping-proof establishment of a secure connection (after a secure initial pairing, expected between a key and the car anyway). |
|
Keyless is not going anywhere and you need more than an SSH-like protocol to protect it.