Let's just pretend this worked flawlessly the first time. The sponsor is Blinkist: The first 100 people to go to blinkist.com/stevemould will get unlimited access for 1 week to try it out. You'll also get 25% off if you want full membership.
@nicholas34354 жыл бұрын
What are you talking about of course it worked the first time :)
@legoman-we2zy4 жыл бұрын
Lmao
@RobertoMariani4 жыл бұрын
Someone hacked your video, too
@eaglewolf4044 жыл бұрын
No worries.
@buttonsjr4 жыл бұрын
I got the notification the second time, so you got that going for you. I know sometimes KZbin punishes people for re-uploads to fix something. You got it re-uploaded pretty quick.
@samykamkar4 жыл бұрын
I also have no idea what I'm doing most of the time.
@mikecauser4 жыл бұрын
With all your great research on the topic, how much time is spent coming up with the cool project names vs the actual coding? Rolljam, Magspoof, PoisonTap, Glitchsink...etc. 50/50, right?
@mibdev4 жыл бұрын
samy is my hero
@gonespral4 жыл бұрын
samy is my hero
@Abdega4 жыл бұрын
I’m now imagining a Mr Magoo like scenario where someone just stumbles upon vulnerabilities
@IceMetalPunk4 жыл бұрын
I'm not a fancy security expert like you, but I am a software developer working on a web-based fintech app, and... yes, can confirm, a large portion of any development/IT/tech is just trial and error. And lots of banging your head against a desk trying to figure out why the debug output doesn't match what you expect 😂
@AllDayBikes4 жыл бұрын
1:00 Nice detail on the Bmw parking hahah
@Talaxianer4 жыл бұрын
̣
@ronochow4 жыл бұрын
I died 🤣
@Leo-zt7fo4 жыл бұрын
Mini is owned by BMW.
@William-Morey-Baker4 жыл бұрын
you beat me to it by like 20 seconds... the timestamp is nice though
@Jad91144 жыл бұрын
+
@jordanericbaird27243 жыл бұрын
I love how you can tell he genuinely enjoys doing this. The smile, the laugh, the energy. Keep up the work!!
@luk15054 жыл бұрын
6:48 "I tweaked some variables, I didn't have a clue what I was doing, but I noticed that it changed things" - said almost every engineer at some point. That's how you make discoveries! I love your videos, Steve :D
@minecrafter05054 жыл бұрын
He pretty much summed up my job there... And according to my resume I know what I am doing :P
@YourMJK4 жыл бұрын
That's just called debugging
@D33r_Hunt3r_4 жыл бұрын
It's like I'm back in my matlab class... **stares of into space due to painful memories**... good times lol
@StopChangingUsernamesYouTube4 жыл бұрын
Yep. The real work is going back and figuring out what part of the five different variables you tweaked in "throw everything at the wall until something sticks" mode that made the difference.
@Lesesmo4 жыл бұрын
"Huh, my code work, and I have no idea why." said the greatest engineer I know.
@kezzyhko4 жыл бұрын
To anyone wondering and for the sake of saving history, This video was reuploaded, because on the first upload it did not have sound in the moments of talking with Samy
@quinnbattaglia51894 жыл бұрын
Thank you, I was wondering
@sanskarraikar10954 жыл бұрын
yeh
@youtube.commentator4 жыл бұрын
Same, thanks
@hollanderson4 жыл бұрын
Thank you love you
@connecticutaggie3 жыл бұрын
A big advantage of Manchester encoding is that every bit guarantees a transition. This means that your signal contains the data and the data rate clock. As you mentioned that the fob can't maintain a consistent transmit frequency, the same is true for the data clock. Manchester allows the receiver to synchronize the data rate. Also, the transmit signal likely starts with the same start byte (most commonly AA or 55) to allow that receiver to lock onto the signal (timing wise) and also adjust its gain (AGC).
@theodoric42702 жыл бұрын
This is important for magnetic strip credit cards, as an example. The card reader needs to know how quickly you're swiping the card and it uses a standard starting sequence to synchronize. It doesn't matter how fast you swipe the card (within reason) as long as you don't vary the speed and the whole strip goes through the reader.
@donaldviszneki82512 жыл бұрын
@@theodoric4270 i always thought this was dumb since maintaining a constant velocity is not always easy. I think a better system is either to use two tracks with a clock track or a second magnetic polarization axis. But magstripe is slowly dying anyway...
@charlesnathansmith Жыл бұрын
@@donaldviszneki8251 it worked well enough, and that's always going to be the standard to hit. When magstripes fail it tends to be from demagnetization or it physically chipping off rather than a rate error From a security standpoint, a lot of the RFID upgrades for credit cards and badges just became "Spooky replay vulnerabilities at a distance" rather than proper challenge/response implementations
@ilikaplayhopscotch4 жыл бұрын
I like how the poorly parked car was a BMW, that made me laugh.
@Narsuaq4 жыл бұрын
It's funny cos it's true
@carni50644 жыл бұрын
Its ironic because Mini is BMW.
@culpritdesign4 жыл бұрын
Typical
@dyscea4 жыл бұрын
Seeing this comment first then finding the BMW made me laugh.
@SuperMincraftia4 жыл бұрын
I laughed as well then I remembered I drive a bmw and also can’t park.
@enethion3 жыл бұрын
How to recognize a passionate person? If you approach him with the smallest achievement in his field, he instantly goes "That's great! How does it feel?".
@suullus26683 жыл бұрын
Samy is my hero.
@carchocolate933 жыл бұрын
Sounds like the whole Kerbal Space Program community
@canadianrocketman34752 жыл бұрын
@@carchocolate93 ya
@JBBell2 жыл бұрын
Really ought to be a word for this wonderful opposite of gatekeeping.
@enethion2 жыл бұрын
@@carchocolate93 yup
@mr88cet3 жыл бұрын
Great video! Thanks. It’s worth pointing out that looking at a chip under a microscope to reverse-engineer it is pretty challenging, although not technically impossible if you use mechanical-chemical polishing. Back in 1995 (or thereabouts) when my company at the time was working with something like 2-micron fabrication technology, I was able to diagnose a power-drain by eye-droppering a liquid-crystal solution onto a chip to find the hot spot on the chip. However, even at 2 microns, the image was pretty blurry. 2 microns is about 4 times the smallest wavelength for visible light, so it’s possible, but difficult, to image the chip. Nowadays though, when the features approaching 1/100 the shortest wavelength of visible light, you pretty much have to use electron microscopes, which only show you the surface. So, to see the internal structure, you have to extremely precisely polish off layer by layer, re-imaging each layer. That’s definitely possible, yes, but very difficult.
@PurpleCh4lk2 жыл бұрын
I understand some of these words.
@dorjanhajdari26702 жыл бұрын
Your sir are a smart cookie. But I'm sure you know that. Thanks for the information. For reasons I do not have the ability to explain. The fact that wavelengths have lengths and how they react to specific objects at different sizes escaped my knowledge. I can confidently say it will not escape it again, at least for another 15 years. So thanks
@mr88cet2 жыл бұрын
@@dorjanhajdari2670, thanks. Well, experienced anyway… I had a guitar teacher a few eons ago who said, “not sure I’m ‘experienced,’ but I have had a lot of experiences!”
@SquirrelTheorist2 жыл бұрын
@@mr88cet Clever teacher! I love how he defines what he seems to contradict only to prove it true through his definition.
@dawnfire8211 ай бұрын
X-ray it. Stitch the images. Make a circuit diagram and analyze. Voila. I did this as a project in an EE grad class.
@jonathanxdoe4 жыл бұрын
Remember: never park your car next to someone in a hoodie and with a laptop
@Alexander_l3224 жыл бұрын
Just run him over instead
@Dhruv12234 жыл бұрын
Even if he reserves the spot for you on a busy day?
@cr100014 жыл бұрын
Specially not someone who looks like the villain in a horror movie like at 1:22 :)
@SLLabsKamilion4 жыл бұрын
... But the hacker with the hoodie and laptop is in the passenger seat, trying to gather WPA PMKIDs... Do I just not park? EDIT: Instructions unclear; vehicle is now in lake and hacker is very angry about his laptop getting soaked. Something about SSH keys being irreplaceable?
@A1rPun3 жыл бұрын
Remember: don't judge a book by it's cover.
@atlas_194 жыл бұрын
"I'm in my car! Amazing."
@SM-wt8gd3 жыл бұрын
@@BodywiseMustard awhhh
@diegocrusius3 жыл бұрын
lmao
@thecrondogs3 жыл бұрын
I'm in my mum's car. Brum brum
@mohamadattiaibrahim71163 жыл бұрын
😂.
@sar3lp8103 жыл бұрын
me 2
@homomorphic2 жыл бұрын
Didn't mention a relay attack which works with modern fobs with passive unlock (where you can walk to the car and just open the door so long as you have the fob). Two thieves park near a restaurant and observes patrons entering. When they observe a car they want one of them follows the target into the restaurant and walks near them with a transceiver. His partner walks to the car (from which they observed the targets exit from) with the paired transceiver which then relays the passive code from the fob via his partners relay transceiver and the perp opens the door and drives off.
@bobafruti4 жыл бұрын
1:00 BMW is the Apple of cars, Their motto is “park different”
@joepbeusenberg3 жыл бұрын
You know Mini is actually a BMW automobile?
@moesiatestecles19753 жыл бұрын
Ahh thanks. I thought he made a jab at BMW drivers for parking recklessly which doesn't ring completely untrue in my experience
@DirtyPoul3 жыл бұрын
@@joepbeusenberg Well, yes and no. Yes, as in the company BMW, but no as in the BMW brand. Mini is not part of the BMW brand.
@stuartd97413 жыл бұрын
@@DirtyPoul but you will find many components of a mini have bmw on them? Infact the same parts that fit on some of the BMW range.
@DirtyPoul3 жыл бұрын
@@stuartd9741 Yes, of course. Some of the cars share the same platform, so that's to be expected. But that doesn't mean that Mini is part of the BMW brand. It's a separate brand owned by the company BMW. That's what I meant.
@MrJakson1123 жыл бұрын
that "hacker sitting in the dark in a hoodie" cliche was so well done. love it.
@1aboPLZ2 жыл бұрын
Doesn't it have proven psychological causality?
@samuilzaychev96362 жыл бұрын
Me too 👍
@arslanahmedqureshi29642 жыл бұрын
I just discovered your channel today and already watched two hours of your videos I mean amount of the research and effort you put in each of your video is impressive... Really appreciate what you are doing..
@andrewholaway41134 жыл бұрын
I have worked for two different US companies that develop software-defined radios for commercial and government customers. Your opening explanation of rolling codes was fantastic (far outstripping the initial explanation I received when working on our rolling codes project, despite being like 2 minutes long compared to an hour-long briefing at work). Thank you for your dedication to science communication and bringing these awesome aspects of science to the fore!
@htcmlcrip3 жыл бұрын
Therea missed part in rolling key explanation. Someone cover that plz lol
@pahvalrehljkov3 жыл бұрын
dalai lama once said: if you need an hour to explain something, you know jack sh**...
@since18763 жыл бұрын
@@pahvalrehljkov in things like business related videos, they artificially inflate the information to fill a certain amount of time. Because the person creating the presentation isn't gonna get shit for a two minute presentation compared to one that looks like he put more effort into it. Even if it's better for everyone if it's short.
@caleblimb32754 жыл бұрын
"What this demonstrates really well is that I have no idea what I'm doing." XD
@freehugzfacehugger67934 жыл бұрын
Thats me every day in online school lol
@DamienAlexander4 жыл бұрын
He nailed that so well on the comedic spectrum.
@hamishmacleod86164 жыл бұрын
Hilarious!
@AM-du7si4 жыл бұрын
*fairly
@manfrom20xx134 жыл бұрын
Me during chemistry class be like
@AndyLevy13 жыл бұрын
10:19 I think it would have been good to mention here how jamming works in this case. If you are sending out a jamming signal to the car on the broad spectrum, you are not jamming the airwaves so much as you are jamming the equipment. You are causing the car to process useless signals - meaning that the car has no processing power left at that time to process the real signal. You are essentially flooding the car with bad signals, keeping its computer occupied while you listen out for the good signal.
@putoutmyfirewithgasoline18773 жыл бұрын
Sounds similar to a DDOS attack?
@fbevc2 жыл бұрын
Actually it has little to do with processing power. The signal you are jamming with is basically noise to the car, and if that noise is "louder" that the actual signal from the key, then all the car "hears" is that noise. It's like trying to have a conversation next to a jet taking off - your voice and the jet engine emit different frequencies, but since your ears listen to the whole frequency range, the jet completely overpowers, but a microphone with a frequency response tuned to the frequency of your voice could hear you.
@petermarsh45784 жыл бұрын
I love that this covered your whole thought process from the ground up, rather than just stating information. Top notch stuff!
@kylehughes1 Жыл бұрын
Samy is the man. been following his work for years. related, LTC (timecode used to sync audio/video dual system or multiple cams in production) is essentially manchester encoded as well. i have had to actually manually decode it by looking at the bits before lol. silly thing to have to do but it works in a pinch. so if you are syncing your cam using timecode, you may have been using it all this time.
@DigitalicaEG4 жыл бұрын
Thank you, stole my first car today :)
@firstletterofthealphabet73083 жыл бұрын
oh no.
@user-xy6nc9fr1q3 жыл бұрын
Oh yyyyyyy
@imhereiguess26083 жыл бұрын
Nice dude! Hope you get more cars soon!
@rapidcorp3 жыл бұрын
Lol
@wach91913 жыл бұрын
Just unlocking a car is not enough.
@JonathanBates4 жыл бұрын
:D That double spot taking BMW made me laugh!
@SangheiliSpecOp4 жыл бұрын
I clearly saw that it was a bmw and parked like that, but the joke didn't register in my head for some reason lmao
@Leo-zt7fo4 жыл бұрын
Ironically, Mini is owned by BMW and is usually driven by women.
@sambishara93004 жыл бұрын
@@SangheiliSpecOp it is like when you see something so many times your brain ignores it because it is the norm
@SentientTent4 жыл бұрын
@@Leo-zt7fo do you have any sources on those car ownership demographics?
@anderpanders62104 жыл бұрын
@@SentientTent the picture on 1:00 has a tiny BMW logo on the badly parked car.
@beboba24983 жыл бұрын
To jam a car you don't need to think about range of frequencies, just use directional antenna on car receiver, this jamming won't affect the 2nd spy receiver.
@mediaaccount83903 жыл бұрын
THANK YOU for showing all the attempts that didn't work. It's sooo important to show that success requires work.
@yackfou24122 жыл бұрын
Who cares?
@SolidSiren2 жыл бұрын
@@yackfou2412 most people who are curious
@johnelwer36334 жыл бұрын
"Authorities report nationwide wave of smashed car windows. Suspects say 'Steve told me it was easier'".
@eliotmansfield3 жыл бұрын
Or just collect the keys from the fishbowl party
@JSTheAnonymousOne Жыл бұрын
Something you need to be careful of: replay attacks on cars can cause at least one remote to go out of sync. You might be able to recover it by pressing a button on the second remote, but it'll require resynchronizing it yourself or taking it to someone who can if you're unable to
@kahazaba4 жыл бұрын
Instructions unclear: I have opened my microwave with a skoda car key.
@htcmlcrip3 жыл бұрын
I managed to open my microwave e by downloading app to unlock microwaves. Just run the app and boom! Now you can open microwave doors without any key :) bluetooth may be needed tho
@N.I.R.A.T.I.A.S.3 жыл бұрын
I'd rather drive a microwave than a Skoda.
@gameit99703 жыл бұрын
@@N.I.R.A.T.I.A.S. i will microwave a drive than a skoda
3 жыл бұрын
I unlocked my car with microwave. No need to use keys!
@pratikvyas96263 жыл бұрын
😂 happy frozen fooding!! OMFG THS IS AN EPIC COMMENT THREAD!!
@kubik72034 жыл бұрын
Steve Mould : i hacked into my own car Robber : i hacked into Steve Moulds car
@FredNagel4 жыл бұрын
Mark Rober: I hacked into Elon Musk's car (to save the world)
@matthewkambic4 жыл бұрын
It would be a burglar as a robbery would only take place if you were in the car 😁
@dawsoncannon49584 жыл бұрын
@@matthewkambic Burglary is specific to thievery in buildings. And either the way, the comment states nothing concerning thievery. So it would only be a hacker. But if the hacker stole the car, he'd be a car thief and he'd be commiting grand theft auto
@marksworkshop87244 жыл бұрын
Dude, way to be a prick.
@dawsoncannon49584 жыл бұрын
@@marksworkshop8724No one's being a prick😂 I swg, people wanna make drama out of anything and everything. @Matthew Kambic, did you feel like I was tryna be a prick towards you?
@knuckle123562 жыл бұрын
I love that you blurred out your key bitting in the opening scene.
@SheepUndefined6 ай бұрын
Even funnier that he didn't blur it in all the other shots
@Derek_Garnham3 ай бұрын
cut to hacker in dark basement, reversing blurring algorithms.
@fadiyaldo71674 жыл бұрын
1:00 Love the very realistic view of the parking lot🤣🤣
@zerge834 жыл бұрын
savage
@butterflygroundhog4 жыл бұрын
Steve be like "click out of mouse, W is binding.."
@maskedredstonerproz3 жыл бұрын
I understand that reference, and am glad to see another man/woman of culture
@prakharmishra30003 жыл бұрын
Nose picking lawyer
@kudosu30373 жыл бұрын
Car-Jacking lawyer...
@kommstein56923 жыл бұрын
blood curdling lawyer
@tutacat Жыл бұрын
You could exchange with the car to get the current RTC time, and reduce cost. It would also prevent changing the time on the keyfob into the future.
@mformandar4 жыл бұрын
That is most accurate depiction of a car park I've ever seen @1:00
@DavidGossettMusic4 жыл бұрын
Steve does realize that Mini is made by BMW right? 😂
@mformandar3 жыл бұрын
Doesn't matter though, does it?
@JohnDlugosz4 жыл бұрын
Social engineering: Use your SDR to be receiving. Make an app or script or whatever, so that every time a signal is received it plays an interesting sound clip. Each one is different, and after introducing it everyone will try theirs to see what noise it makes. For example, having a party at home, say "watch this" and get out my key fob, show them when I press the button, an old-fashond "auuuuuga" horn sounds from the home theater sound system in surround sound. Much more dramatic than a laptop sound. "Now try yours!"
@ianr20024 жыл бұрын
Well shit. That's a very good idea that'd definitely get a lot of people to fall into the trap
@vintagerealityvr3 жыл бұрын
I don't know about you but if I'm inviting people to my house for a party I'm not trying to steal from them haha. What kind of friends do you keep?
@simonseis7443 жыл бұрын
That's not really social engineering, that's just tricking your friends, also why you stealing from your friends?
@KatorNia3 жыл бұрын
@@simonseis744 _"That's not really social engineering, that's just tricking..."_ That's exactly what Social Engineering is: "The use of deception to manipulate individuals into divulging confidential or personal information."
@seraphina9853 жыл бұрын
@@simonseis744 They don't necessarily need to particularly be friends though, this is the sort of attack someone could pull off by investing a few weeks infiltrating say a company so they can produce their party trick at the office Christmas party. Especially easy to pull off given how many companies hire temporary staff during the Christmas period which would give a would-be gang of car thieves a chance to infiltrate the employee social group.
@InimicalDivinity2 жыл бұрын
1:18 I liked for this scene alone. YOU LOOK SO SINISTER. That's textbook villain material right there.
@BMWclubb4 жыл бұрын
Can we just appreciate that this man is still rocking is Pebble in 2020. I finally dont feel alone
@Hepglon3 жыл бұрын
there are dozens of us! Dozens!
@brookewestonctc3 жыл бұрын
Me too! Woop!
@MINERAL-1153 жыл бұрын
That video was absolutely fascinating. I'd never really thought about how these keyfob systems actually work; somewhat ironically, as I'm a fairly decent electronics repair tech and have fixed plenty of car keyfobs in the past!
@martagdok11 ай бұрын
Alright, I never ever bother to leave a comment but THIS video was so fun, informative, engaging and most of all so damn easy to follow for a beginner like me, hats down! I'm just starting my journey of learning how to program and code, researching fields that I'd like to focus on in the future, you've inspired me to pursue cybersecurity engineering! Big thanks!
@TheHive954 жыл бұрын
The preamble isn't nessecarily saying 'im a key', it's actually pretty standard. Since Manchester encoding guarantees transitions, this preamble is used to synchronise the receiving clock exactly to the right edges so that the important payload doesn't get corrupted. (Phase locked loop circuit)
@javigarcia-ripoll65783 жыл бұрын
I love how passionate you are explaining the process and what you discovered. Nice video!
@cmdrpausanias2332 Жыл бұрын
One subtle thing I noticed - the BMW taking up two spaces and parked squiffy, nice touch, I'm not a BMW fan either!
@thetafritz98684 жыл бұрын
1:00 I love how you made the BMW occupy 2 spaces XD
@Jesse__H4 жыл бұрын
This was super interesting once again, Steve. I really value the _variety_ on your channel. I'm like you, I find EVERYTHING (potentially) interesting.
@haydenlandry38372 жыл бұрын
Military radio systems use a similar technique to prevent jamming, called frequency hopping. It's like what Samy was saying; you have the two radios with synchronized clocks, and an encryption key determines the pattern of frequencies. The radios "hop" pseudo-randomly but remain synchronous, preventing jamming or interception.
@davebond44514 жыл бұрын
Wait. I've seen this before..
@lostkorok53754 жыл бұрын
Haha me too, missed somes sounds
@SteveMould4 жыл бұрын
But this is the first time I'm uploading it. Don't know what you're taking about!
@Lazy_Tim4 жыл бұрын
@@SteveMould Second time worked a charm. First time I couldn't hear any of your chat or leave a comment? Posted before I saw this.
@SteveMould4 жыл бұрын
@Thu Nell Ⓥ I was trying to be funny. Failed at that too!
@hazgebu4 жыл бұрын
@Thu Nell Ⓥ he was joking. Check his community tab for more information :)
@SthamerAMVs4 жыл бұрын
That face after he goes “I wasn’t expecting it to work first time”😂 I felt that😂
@MachineYearning6 ай бұрын
I know this will probably get lost on a 3 year old video but just wanted to say that this is my favorite of your videos. Hope to see more like this in the future
@theocheynel63614 жыл бұрын
Very interesting, I love the way you had to think about it as an incremental approach, not knowing what you were doing and figuring it out as you go. A few questions to think about : - When you're jamming the key with your emission, couldn't you just substract what you're currently emitting from what you're receiving, instead of broadcasting on a different frequency ? Kind of the same way active noise cancellation work, if you know exactly what you're emitting then the difference with what you're receiving is what comes from the key right ? - What happens if you press they key while the car is not in range ? Doesn't that mean that the key will skip to the next code, while the car, completely unaware of the fact that you pressed the key, stay on its current code ? Or is the car looking for the code in N possible "future" codes ? If so, what if you press the key N times while away from your car, will the key and the car be "un-synchronized" forever basically ? - Some cars can have several keys am I right ? Back in the day when you had several keys only one of them was remote (which is understandable), but now I think that you can have several remote keys for your car. Is this a more complex algorithm ? Or does the car simply have several registers, one for each key ?
@svetievboris2 жыл бұрын
From Wikipedia: "A typical implementation compares within the next 256 codes in case receiver missed some transmitted keypresses." So I guess that probably means that if you click your key more than 256 times while out of range would that essentially brick your key and door i.e. receiver.
@jellyfishjelly19414 жыл бұрын
"but most of all, Samy is my hero"
@robspiess4 жыл бұрын
Lol! I didn't realize it was *that* Samy! I still have that on my Facebook profile as an homage to that infamous Myspace hack. For those who don't know, check out the Wikipedia page on Samy Kamkar or "Samy (computer worm)".
@inigocasanovadiaz59274 жыл бұрын
Samy is my hero
@David_237_9 Жыл бұрын
The bad parking of the BMW detail at 1:00 hahahaha
@egoworks56114 жыл бұрын
level of expertise: "actually that's manchester encoding" Love your content bruh!
@ms-fk6eb4 жыл бұрын
well hey, now we know too!
@egoworks56113 жыл бұрын
@@ms-fk6eb you're right!
@RalphDratman3 жыл бұрын
Watching this is like actually doing a project that involves manipulating remote-control keys or key fobs. You have to get deeper and deeper into the specifics of the device you are trying to emulate. It can be sometimes thrilling and sometimes tedious.
@ehvway10 ай бұрын
The title of this video was NOT CLICKBAIT: it really is EPIC!
@ATGG3 жыл бұрын
5:57 That’s soooo Mr. Bean moment!!!! 😂😆🤣
@miikl8113 жыл бұрын
it made my day actually xD
@stuartmc87793 жыл бұрын
You’re right
@danriddick9144 жыл бұрын
The BMW parked over 2 spots, lol. Great stuff.
@stoojinator3 жыл бұрын
0:54 absolutely lost it at that graphic! Well played!
@dylanwulf59444 жыл бұрын
Veritasium did a similar video! His was about opening garage doors instead of cars, and also featured Samy
@quinnbattaglia51894 жыл бұрын
I can't believe KZbin actually sent me a notification as soon as the video went up.
@RoraighPrice4 жыл бұрын
the youtube algorithm sent it to you so quickly because it knew youd instantly click on it.
@aettic6 ай бұрын
Didn't expect to see Steve dipping into the world of cybersec. Good stuff, would love to see more of this kind of thing. Your inquisitive and science-minded worldview is a really great way to look at understanding the cat and mouse game we play. I'd love to see you dig into the physics of other elements of physical or cyber security.
@AVCadar4 жыл бұрын
That BMW parking reference. Spot on!
@Alba_Longa4 жыл бұрын
0:59 That a-hole BMW is a nice touch lol
@anthonyfeng61804 жыл бұрын
That's BMW in its natural habitat
@Napert2 жыл бұрын
i like how you tried to hide the key in the close-up but completly ignored it in the next clip where it's clear enough to be visible
@DampActionRC4 жыл бұрын
My old palm pilot would do something similar about 20 years ago. You could point a remote control at the IR transmitter/receiver, it would record the remote’s power code. Then you could use the palm pilot as a universal remote. Even arrange the button placement/size. Great technology
@sokol72153 жыл бұрын
Ir is something complete different than radio. So no, it's not comparable. Completely different things.
@rolfviehmann62402 жыл бұрын
@sokol Actually, I would say it's not that different. In both cases, you have a unidirectional, wireless transmission of a binary code whenever a key is pressed, and in both cases, a device can be built to sniff this transmission and repeat it. So, if a car key would send a simple, static signal whenever the "open" button is pressed, it could be sniffed once and repeated any number of times, which may be possible in rare cases, but since this is quite easy to do, the key manufacturers understand that it's very insecure, therefore better, more complex solutions have been developed. But a simple IR remote control does not need this advanced level of security, therefore, the manufacturers still (to this day) simply send a simple, static signal every time a key is pressed, so once you recorded the signals for all keys that exist, you can simulate all the keys perfectly, any number of times. The manufacturers of the remote controls know that this is possible, but since nobody ever complained about it, they don't care at all. A simple solution (static code) is always cheaper and more robust than a complex one after all. The highest level of security that could be built would be a bidirectional connection between the car key and the car, on other words, a handshake, like when a TLS connection is established, could be made, and then, the actual command could be sent over this encrypted channel. The key would of course only transmit anything interesting after the handshake would have been completed, so no sniffing would be possible at all. As far as I understand it, this is the way wireless keyboards work, to make sure that it's not easy for an aggressor to sniff any passwords you type on the wireless keyboard.
@markharrisllb3 жыл бұрын
When I was young and you locked your keys in the car, which I can't do in my modern car, all you needed was a wire coat hanger. A policeman taught me how to do it and it was frighteningly easy. The advancements in car security have been phenomenal. This is the first video I’ve seen of yours, I really enjoyed it as it was interesting and humorous.
@since18763 жыл бұрын
It's still very easy, now you GENTLY pry the door open, then you insert an air bag (to inflate and widen the gap more safely), then you use a wire to press the unlock button. But there is a very real risk of paint damage, so it's not recommended on a really high end car. If you have a Ferrari, you should just be careful to not lock your shit in the car. 😂
@rizzle32722 жыл бұрын
Even today if you are able to access the inner skin of the Door where the mechanical cable is housed (provided it is still mechanical. Some newer cars such as Range Rovers have fly by wire door handles) you can simply get a wire coat hanger and tug on the cable inside.
@pieterpauwels5482 жыл бұрын
a syncronised clock was actually one of the first solitions I thought of! was very satisfying when it was also presented in the video.
@nl_morrison4 жыл бұрын
This is great Steve! You should try to get into parliament next and fix the country. Much love
@SteveMould4 жыл бұрын
Ah yes, the "run for office" hack.
@nl_morrison4 жыл бұрын
@@SteveMould Senator Mould has a nice ring to it!
@EcceJack4 жыл бұрын
@@nl_morrison Senator? Wrong country, surely! :D would just be MP (often referred to as "The Right Honourable" gentleman/colleague/representative of [constituency] in the actual parliamentary debates)
@nl_morrison4 жыл бұрын
@@EcceJack Right! Well while he is at it he can fix the USA too, I'm sure it's just a bit shifting issue.
@simonjohnston31004 жыл бұрын
None of them have any idea what they're doing either
@matthewmontgomery36934 жыл бұрын
Halfway through I'm waiting for one of the other cars in the background to go *chirp chirp*.
@riendessus57932 жыл бұрын
It's ok to be completely lost, i think this is the real hacker's journey! Not knowing anything at first and slowly building up knowledge! Keep up the good work!! :)
@ReallifeBambiDeerattheFarm14 жыл бұрын
0:54 Busted out laughing! So true!
@keco1854 жыл бұрын
I think the biggest issue is with passive entry. Using repeaters to make a car parked in the driveway think the key is next to it instead of in the house.
@kilgarragh2 жыл бұрын
Can we just be thankful this dude blurred his key?
@nickchow92914 жыл бұрын
"I ain't never seen three zeros in a row. It’s always one of them gotta be a one." ~Manchester encoding
@mekelius3 жыл бұрын
8:20 Imagine going to a key party and Steve being there clicking away with his laptop :D
@dfess3 жыл бұрын
Steve out here telling swingers how to steal cars
@niklas5336 Жыл бұрын
Regarding other ways to secure keyfobs, you can have the key merely be an unencrypted request for the car to initiate a challenge-reponse. The car sends the key a challenge, the key encrypts/hashes/signs this challenge with the secret key, and the car checks the response. With an only slightly higher level of sophistication, you can measure the timing of the response and compare it against time-of-flight of radio signals. If it's too far (e.g. further than 50m, or about one cycle on a 5 MHz processor), reject the response as invalid. That way you also protect against a signal extension attack.
@jeremiasrobinson4 жыл бұрын
I'm never going to a swingers' party again!
@ronwesilen45364 жыл бұрын
Do you leave your keys in a bowl in swinger parties?
@jeremiasrobinson4 жыл бұрын
What kind of parties do you leave your keys in a bowl at?
@davidgustavsson40004 жыл бұрын
@@ronwesilen4536 yes. That's how you decide who swaps with whom, you pick a key from the bowl, and hope it's not your spouse's. I hear.
@uplink-on-yt4 жыл бұрын
Uber. You're welcome.
@ronwesilen45364 жыл бұрын
@@davidgustavsson4000 honestly interested in this. I hope it is true. Also hope woman are the ones grabbing the keys so they can fill their keyhole
@SergeMatveenko4 жыл бұрын
That BMW parked like a jerk is hilarious!:)
@kubajz22574 жыл бұрын
0:58 I love the BMW joke.
@vishal_pho3nix3 жыл бұрын
Awesome demonstration of working and security features of car keys and great way to point out the loopholes in simple terms. Great work. First time watching this channel. Loved ur work. 👍
@25Killer3 жыл бұрын
I just wanna hack my car to play the "stairway to heaven" tune every time my door is open
@taserlaser5593 жыл бұрын
Steve: *Locks keys in car* Also steve: Hold up, let me get my laptop.
@AndreasHontzia4 жыл бұрын
7:00 I feel you! But that's what hackers do. Play around until they understand it.
@BaoNguyen-pl6dx2 жыл бұрын
This got me thinking about how car and key resynchronize after the key misses a code (another key is used or someone uses a laptop with a transmitter). Look up rolling code synchronization if you're interested!
@Shakis874 жыл бұрын
The BMW taking up 2 spaces absolutely ended me hahaha
@sdspivey4 жыл бұрын
"The car door is locked, there's no way to get in." It is a convertible, so very easy to get in, no expensive tech needed, just a knife.
@muhammadaryawicaksono42324 жыл бұрын
He's in UK. He would need a license for the knife
@htcmlcrip3 жыл бұрын
@@muhammadaryawicaksono4232 true that. You cant just carry knife or scissors like that in the street
@joshstamps67183 жыл бұрын
Thats some stupid thinking
@chalee34843 жыл бұрын
you dont even need a knife... break into the window.
@icanpooptwiceadayyay87713 жыл бұрын
@@chalee3484 yep
@gabrielpetcu55022 жыл бұрын
0:55...nice touch, Sir!! Nice touch, indeed!!!
@NithinJune4 жыл бұрын
Whenever you showed your key on camera I got anxious lmao
@AdamTheJensen4 жыл бұрын
HAHAHA I love the BMW parked across the line!
@eekee60343 жыл бұрын
Hehehe! I love the hacker face in the dark. :D The green lighting for the call was pretty cool too. Interesting how far back you have to go for all this. Keys were already code-hopping before the end of the 90s, I think, and your Mini had rolljam projection in 07. I put an aftermarket remote on my Peugot 309 around 03, but I didn't care if it was a good one because it was an 80s 5-door hatch & not even the latest model. Bit of a street sleeper, that one; remarkably fun to drive.
@Mikeztarp4 жыл бұрын
11:48 "Instuctions" are how you get out of a situation where you're stuck.
@Tuulos4 жыл бұрын
I wonder if the Mini uses two separate code lists, one for locking and one for unlocking. If yes, then it would be vulnerable to a rollblock attack.
@f7p17642 жыл бұрын
Mini stores last state if it's locked or not, key sends allways one state there is no lock unlock command in key, simple and secure :)
@Logxnxx2 жыл бұрын
@@f7p1764 if I understand you correctly the car saves its last state. (e.g. unlocked) and the key only sends one code from one code list (same list for lock&unlock) and thus reverses its state from (unlocked -> locked and vice versa). However. If the key has two buttons and you press the lock button twice, this would be very stupid wouldn't it? because then the lock button would also unlock the car if its already in a locked state. my guess is that two code lists are being used or some sort of encryption is in place that actually hides the state that the key sends.
@AaronLyNxAI Жыл бұрын
Pretty smart to hide the key pinout, people can actually use that to copy keys. Not the most accurate but definitely gets you close enough you can work from there (usually the height between 2 pins is off, or either depth of cut for the pin, new chip keys help by needing a signal as well as the key pinout, but still requires pins in the lock cylinder)
@tgmtf59634 жыл бұрын
1:21 i am steve mould and i am evil
@sauravsharma93574 жыл бұрын
11:57 Security expert using wired earphones.... makes sense
@davidbergmann89484 жыл бұрын
Wired headsets also have better latency haha 🍄
@spongeboimebobbb4 жыл бұрын
@@davidbergmann8948 true dat man, still waiting for bt tech to improve lmao
@sauravsharma93574 жыл бұрын
@@davidbergmann8948 ya wired r better ,but it depends on the use case.
@ashisha86494 жыл бұрын
@@spongeboimebobbbsome high end gaming wireless mouse almost similar latency if not better compared to wired. Watch Linux tech tips comparing the mouses So its definitely possible. But data rate lower for mouse compared to headphones. So don't know if it'll reach the latency of wired
@matthieu43378 ай бұрын
When i saw that car park situation i had to pause for a few minutes for the giggles to go away. 😆 Thank you very much, i needed that.
@RandornCanis4 жыл бұрын
0:49 Serious warning. It's unimaginably simple to decode a keys' physical bitting from picture. The entire internet can now unlock your car.
@revenevan114 жыл бұрын
Yep, might not have the digital code but showing your key to the camera is basically the same as letting them take a copy of it to reproduce.
@SuperFruitbat994 жыл бұрын
he even hid the key in the first time he showed it
@jetison3334 жыл бұрын
I mean isn't he already showing the whole internet how to unlock his car? Lol
@niccy2664 жыл бұрын
Whoopsie
@ahuman44334 жыл бұрын
Lockpicking lawer comes in
@emy58454 жыл бұрын
11:43 INSTUCTIONS :)
@hounvs2 жыл бұрын
You could have an accelerometer on the attached capture device to basically intelligently detect when the car is in park and likely to have been locked. Especially if you combine it with a clock as another data point. You can figure out when they are driving and then stopping+locking to know when to throw away the lock code.
@shaukahodan23734 жыл бұрын
Tom Holland sees a guy stealing a car... "It's my own car Tom..."
@manjunathjadhav30623 жыл бұрын
Contact @mj1mj123 on Instagram for fun
@jjensen40963 жыл бұрын
0:56 love what you did with the BMW parked there 😜