High risk of theft: Cars with keyless entry in Malaysia

By THOMAS HUONG | 13 February 2018

Photo of hacking posed by model. For illustrative purpose only.

KUALA LUMPUR: Keyless entry technology for cars provides convenience for owners, but it has also become a security weakness and a boon for car thieves.

On Monday, in an article entitled Car thieves have gone high-tech, The Star reported that cars with the keyless entry system can be stolen in minutes by a frequency-­hacking device that is available locally.

The report said the device, which costs about RM150 and can be obtained online or at some electronics stores, can unlock a car and start its engine by hacking its radio frequency identification (RFID) information.

A source said the device could open almost every car with keyless entry.

The report also pointed out that car owners are also encouraged to use anti-theft devices such as steering locks, immobilisers, motion sensors and top-grade alarms.

Meanwhile, auto companies contacted by Carsifu.my declined to comment, saying they need more time to look into the issue.

Relay Attack technology for car theft 

Carsifu.my also spoke to veteran vehicle security expert Datuk Alex Lye, who said it is highly possible that car theft syndicates are already using the RFID frequency-­hacking devices here.

"This method is called Relay Attack. It's a simple device to read the signals, once you press the button on the door handle.

Car thieves don't have to lug around heavy tools anymore," said Lye, who is working together with MAI (Malaysia Automotive Institute) and international vehicle theft experts from United Kingdom, Holland, South Africa and United States.

Lye is also a member of IAATI (International Association Auto Theft Investigators) which is based in United States, and shares information among various enforcement agencies such as Metro Police UK, South African Police.

IAATI is also the the only such organisation that is recognised by Interpol.

"So far, none of the vehicles that is stolen via Relay Attack have been recovered to conduct a post-mortem audit. In Europe, especially in the United Kingdom, there has been an increase in vehicle theft by Relay Attack," he said.

Lye said these thieves are a few steps ahead of vehicle manufacturers, even though "PDRM (Royal Malaysia Police) has been successful in reducing vehicle theft by as high as 20%."

Relay attack scenario
RFID frequency-­hacking device are easily available and cheap

LYE: Yes, these devices are available on the Internet.

Regarding the RM150 device, it comes with a schematic diagram and you have to install it yourself.

I am not sure whether a Frequency Reader can read the code as it only sees the transmitted frequency (433 MHz). I have seen some 'Frequency Jammers' where they jam your remote/fob from activating the alarm.

You will think that something is wrong with the system and you lock your vehicle manually. No alarm system activated, so it is easy meat.

A simple hacking frequency-hacking device is available from the local electronics store or online shopping.
A simple hacking frequency-hacking device is available from the local electronics store or online shopping.
After-market anti car theft devices are only deterrents

LYE: Many after-market security products serve as a visible deterrent but offer no serious solutions to vehicle theft.

Steering locks are useless as car thieves simply inject an acid solution into the key hole and it dissolves the lock. Or the thieves cut the steering to pry the lock away from the steering.

Regarding pedal locks, the thieves just kick hard on the pedal and it will slide down and the thieves can operate the pedals. As for GPS/GSM systems, the thieves can use GSM jammers (which is also readily available online or in local stores).

Possible solutions for automakers

LYE: The vehicle has to be fitted with another secondary transponder immobiliser system, that works separately from the keyless system.

This transponder immobiliser must be an internationally recognised system that can withstand a 30-minute attack. The longer you engage the car thief, the more likely the thief will go for another vehicle. However, this secondary transponder immobiliser system cannot be installed as an after-market system as it will void the vehicle warranty.

To protect a vehicle from being stolen you have to protect these three important points - the ignition, the starter motor and the fuel pump. You must protect at least two of these points. Also, this security system must be able to protect itself from being overridden.

Real World Attack Scenarios
Automakers can do more

LYE: The onus is now on vehicle manufacturers to provide better anti car theft security systems.

Malaysia should upgrade the MS 1742 standard for Vehicle Security System and we should have security 'stars' rating for all vehicles, akin to the New Car Assessment Programme for Southeast Asian Countries (ASEAN NCAP).

Furthermore, with the Phased Liberalisation of Motor and Fire Tariffs, a vehicle's security system will also be a factor that determines motor insurance premiums.

More than simple vehicle theft

Last year, Lye organised Interpol's 2nd International Conference featuring speakers from various countries (Australia, Japan, Thailand, Philippines, United States, Mongolia) who spoke about vehicle theft.

According to Lye, Interpol found out that "lone wolf cells" are stealing vehicles to use as car bombs.

"Interpol have started a database to track all stolen vehicles. In fact, a United States-based company spoke at our conference on tagging all terrorist equipment from guns to forensic evidence to stolen vehicles used for car bombs or terrorist attacks. They need to follow the trail so they can nip it at the bud," said Lye.

Last November, MAI further spearheaded improving awareness of vehicle theft and hosted the KLIAS (KL International Automotive Summit) conference, where experts spoke about vehicle theft and identifying fake parts.

MAI, which serves as the focal point, coordination centre and think tank for the nation's automotive industry, will be hosting KLIAS 2018 in July.