A Car Hacking Village session on Sunday at DEF CON 34 in Las Vegas will take apart a real, commercially available relay attack tool and show how off-the-shelf hardware defeats passive keyless entry and start systems. Researcher Robbie Galfrin plans to document the process of sourcing and operating the device, and to play a demonstration video of the attack carried out against a vehicle.
The talk goes after the trust model that passive keyless entry is built on. Drivers never touch the fob to unlock the car; instead the vehicle and the key carry out an automated radio challenge-response exchange whenever the two come close to each other. That handshake treats proximity as proof of legitimacy.
Relay tools dismantle that assumption without breaking any cryptography. Two inexpensive radios pick up the fob’s signal and extend it over distance, so the car concludes that the genuine key is sitting right beside it. Galfrin’s research digs into how the device is constructed and how it relays the exchange to defeat the proximity check.
The demo lands as relay-based theft keeps rising, since the gear involved is easy to buy and needs no coding skill. The session wraps with a rundown of mitigations meant to close the gap the attack exploits.