• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
TechChanging Face of Security

Security Experts Warn Millions of Car Owners Should Stop Using Remote Keys

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
August 11, 2016, 10:55 AM ET
The UK Are To Re-run Emissions Tests On Volkswagen Cars After German Scandal
Photograph by Rob Stothard — Getty Images
Add Fortune on Google for similar content.

Security researchers from the U.K. and Germany have revealed how easy it is to clone the wireless keys for millions of cars made by the Volkswagen Group (VLKPY) over the past two decades.

In a paper that will be presented Friday at the Usenix Security Symposium in Austin, Texas, the researchers also described a second attack that would allow hackers to clone the remote controls for some cars from Peugeot (PUGOY) , Lancia, Opel, Renault, Alfa Romeo, Ford (F), Chevrolet, Dacia, Fiat (FCAU), Nissan (NSANY), and Mitsubishi (MMTOF).

They recommended owners of affected cars should not only check that the lights blink and the car beeps when they press the lock button on their remotes—they should stop using the remotes altogether and “resort to the mechanical lock of the vehicle.” This way, other people can’t eavesdrop on a remote’s wireless signal, clone the remote, and break into the car.

Get Data Sheet, Fortune’s technology newsletter.

“Our findings affect millions of vehicles worldwide and could explain unsolved insurance cases of theft from allegedly locked vehicles,” wrote researchers Flavio Garcia, David Oswald, and Pierre Pavlidès from the University of Birmingham, and Timo Kasper from the security firm Kasper & Oswald.

These attacks, first reported by Wired, do not overcome cars’ immobilizers. However, they could be used in combination with other well-documented attacks that do, resulting in thefts of cars, not just from them.

With the VW Group’s cars—Volkswagens, Seats, Skodas, ,and Audis—the problem is that they use cryptographic security schemes based on a few master keys, rather than using a different cryptographic key for each remote. The researchers found this out by reverse-engineering, the firmware used in some of the group’s remote keyless entry devices.

The researchers noted that the group sold almost 100 million cars between 2002 and 2015, and said the “vast majority” were vulnerable. They pointed out that they had not closely analyzed the remotes for the VW Group’s luxury brands, including Porsche, Bentley, Lamborghini, and Bugatti.

The researchers said in their paper that the VW Group told them that its latest generation of vehicles uses individual cryptographic keys. However, the researchers also noted that a 2016 Audi Q3 had the vulnerability.

It is unlikely that the VW Group can update or give replacements for all the remotes affected in the short term, the researchers noted, which is why they recommended car owners go back to using physical keys to lock and unlock their cars, and avoid leaving valuables in them.

A Volkswagen spokesman told Fortune that current Golf, Tiguan, Touran and Passat models were “not affected by the problem described.”

“The bar for theft prevention is constantly being raised, but ultimately there is no 100% guarantee for security,” he said, adding that the researchers’ findings would “serve to further improve the security technology.”

As for the second attack, affecting all those non-VW car brands, the researchers were able to reverse-engineer the security protocol that their remotes all use, which is based on an algorithm called Hitag2. They managed to “recover” the cryptographic keys for the remotes in around ten minutes, using a standard laptop.

For more on security, watch:

The remotes using the Hitag2 cipher are all built around chips from the Dutch embedded security company NXP (NXPI).

“We would like to mention that the fact that Hitag2 is cryptographically broken has been publicly known for several years and NXP has already informed their customers back in 2012,” the researchers wrote. “We would further like to highlight that for several years, NXP offers newer [chips] that are not affected by the vulnerabilities described in this paper.”

So with the VW Group remotes, the use of master keys makes them vulnerable. With the other cars’ remotes, the cryptographic system itself was too weak. The equipment needed to intercept and copy the wireless signal from a car’s remote is cheap (approximately $40) and easily accessible.

“The attacks are hence highly scalable and could be potentially carried out by an unskilled adversary,” the researchers wrote. “Since they are executed solely via the wireless interface, with at least the range of the original remote control (i.e., a few tens of meters), and leave no physical traces, they pose a severe threat in practice.”

This article was updated to include Volkswagen’s response.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Lux Capital cofounder Josh Wolfe’s limited-odds, high-stakes 2027 predictions
NewslettersTerm Sheet
Lux Capital cofounder Josh Wolfe’s limited-odds, high-stakes 2027 predictions
By Allie GarfinkleJune 25, 2026
2 hours ago
Micron drives global rally tech stock rally as traders abandon their fear of an AI bubble
InvestingMarkets
Micron drives global rally tech stock rally as traders abandon their fear of an AI bubble
By Jim EdwardsJune 25, 2026
2 hours ago
OpenAI CEO Sam Altman (left) and Broadcom CEO Hock Tan holding their new AI chip, “Jalapeño.” (Photo courtesy OpenAI)
NewslettersFortune Tech
OpenAI and Broadcom’s AI chip has a name: Jalapeño
By Andrew NuscaJune 25, 2026
2 hours ago
What bubble? JPMorgan says the $5.5 trillion AI capex explosion is profitable–for now
AIFinance
What bubble? JPMorgan says the $5.5 trillion AI capex explosion is profitable–for now
By Sheryl EstradaJune 25, 2026
2 hours ago
Jen Wong, chief operating officer at Reddit, speaks during the OMR digital and marketing trade fair
Big TechReddit
Reddit COO targets 1 billion users as internet’s ‘odd duck’ aims for new heights
By Sam BirchallJune 25, 2026
3 hours ago
Man in a suit and tie
InvestingAmazon
Bill Ackman, David Tepper, and other billionaire fund managers are quietly piling into Amazon
By Amanda GerutJune 25, 2026
5 hours ago

Most Popular

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
1 day ago
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
Economy
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
By Jacqueline MunisJune 24, 2026
1 day ago
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Retail
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
By Nick LichtenbergJune 24, 2026
21 hours ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
2 days ago
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
Asia
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
By Nick LichtenbergJune 24, 2026
22 hours ago
Trump’s international student crackdown kicked off a domino effect that could shave nearly $500 billion off the economy
Economy
Trump’s international student crackdown kicked off a domino effect that could shave nearly $500 billion off the economy
By Tristan BoveJune 24, 2026
17 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.