KEELOQ Maker Says Remote Car Entry Devices Not Hacked, Rebutting Researchers
Last week, researchers announced they had devised a way to steal cars by breaking the encryption used to encode the signals sent by keyless remote car entry devices using KEELOQ technology.
On Friday, the company declared in press release that despite this, the system is secure, saying, "Microchip recognizes that the highly talented researchers have been successful at a theoretical attack of a block cipher. However, the KEELOQ security system implementation involves much more than just the cryptographic algorithm."
The company did not deign to specify the inaccuracies, as it, "does not believe a public debate on how to steal vehicles benefits consumer security."
Obviously, the researchers now have been double-dog dared to steal a KEELOQed car.
Microchip Technology's KEELOQ
Security System is Resistant to Recent Theoretical Code Cracking [BusinessWire]
PREVIOUSLY: Researchers Hack Remote Keyless Car Entry Devices
(Photo: jessicafm)
Post a comment
Comments:
simple challenge:
get out of your lab and go steal a KEELOQ car, or stfu.
personally, I'd love to see the video on youtube.
unfortunately, I'm a skeptic with respect to most of these "proof of concept" press releases. Sort of reminds me of the nerd who says I COULD TAKE ANYONE OUT WITH THIS KARATE MOVE... and then shows us a "proof of concept".
@bnet41: As a member of one of those security research groups, let me tell you something. If security research groups did NOT release their findings, the companies would NEVER patch their software. The holes would still be found, but it would be by the people you do NOT want to know about your security holes.




I tend to agree this is something that should not be debated in public through PR releases. I hate it when security companies do that in the IT world. Both sides need to sit down and discuss the issue. Public discussion of security issues is fine, but in an area like this, it might not be a good idea. It's not like all the car systems can be patched like a operating system can.