Don't miss the latest stories
Advertise Newsletter
Network
  • The Creative Finder
  • The Bazaar
  • Deals
  • Status Is Down
Community
  • Sign up / Log in
  • Discussion Forums
  • Calendar of Events
NEW

Follow

Share this

Cars
Automotive
Cybersecurity
Technology
  • Technology
MENU
  • Advertise with us
  • Submit tip/feedback
  • Work with us
  • Subscribe to newsletter
  • Subscribe to RSS
Advertise here
Advertisement

Honda’s Key Fobs Hold Critical Flaw That Allows Hackers To Control Its Cars

By Nicole Rodrigues, 14 Jul 2022

Subscribe to newsletter
Like us on Facebook
Photo 115938951 © Lequint | Dreamstime.com


Honda’s keyless system has revealed a critical design flaw, allowing hackers to remotely open, close, and even start the engines of all Honda models.  

 

The hacker attack, dubbed ‘Rolling-Pwn’, was discovered by Star-V Lab researchers Kevin2600 and Wesley Li, who learned that hackers could steal codes linked to key fobs and control the cars.

 

The researchers first made the report public in a blog post, identifying all models manufactured between 2012 and 2022 as being affected by the vulnerability. The flaw was spotted in a rolling codes program installed in all Honda vehicles. Authentication codes are exchanged between keyless entry systems and the key fobs, and in that window was where they had found the weakness.   

 

Honda’s rolling codes mechanism should have prevented this from happening as it was implemented to send new codes each time someone unlocked their car. However, the cars have been noted to resynchronize every time they receive a lock or unlock command, allowing them to accept codes from previous sessions and hence giving hackers an in. 

Advertisement
Advertisement

 

The researchers tested the hack out on 10 different models including the Honda Civic, Honda C-RV, and the Honda Accord. They filmed themselves in a series of videos which they put in their blog post to prove their findings. A representative from The Drive also tested it out himself and posted his findings on Twitter. 

 

I was able to replicate the Rolling Pwn exploit using two different key captures from two different times.

So, yes, it definitely works. https://t.co/ZenCB3vX5z pic.twitter.com/RBAO7ZtlXZ

— Rob Stumpf (@RobDrivesCars) July 10, 2022

 

Honda released a statement to Gizmodo via a spokesperson, saying that an attack like this requires complex knowledge and for the hacker to be in close range of the car. They assured drivers that the cars cannot be driven away and that this issue will be removed from future models.   

 

 

 

[via TechCrunch and New York Post, Photo 115938951 © Lequint | Dreamstime.com]

Receive interesting stories like this one in your inbox
Advertise here

More related news

Advertise here
Also check out these recent news
Web Design
Link to news page

When Your Website Goes Down, This Is the Page Customers Meet Instead

2027
Link to news page

2027 Already Has A Color Of The Year And It’s Beginning On ‘Grounded’ Territory

IKEA
Link to news page

IKEA & Xbox Press Play On Furniture & Storage Inspired By The Iconic Controller

Fashion
Link to news page

Vogue Presents ‘United Flags of Fashion’ With Top Designers For All 50 States

Coca-Cola
Link to news page

Coca-Cola Pours Fresh Life Into Its Iconic Branding With Worldwide Redesign