/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers find cryptographic keys shared by millions of Volkswagen vehicles can allow them clone key fobs using cheap radio hardware

In 2013, when University of Birmingham computer scientist Flavio Garcia and a team of researchers were preparing to reveal a vulnerability that allowed …

Wired Andy Greenberg

Context & Ripple Effects

Flavio Garcia's University of Birmingham team had been sitting on this result since 2013, when they were first preparing to reveal the vulnerability — the multi-year gap before publication suggests coordinated disclosure with Volkswagen took that long to settle. The finding lands five months after researchers showed 24 cars from 19 manufacturers were open to a radio amplification attack, making this the second keyless-entry failure of 2016 to hit the same supplier ecosystem.

The distinction matters: amplification extends an owner's own fob's range, while this attack clones fobs outright because cryptographic material is shared across millions of vehicles rather than unique per car. The same research lineage resurfaced in 2020, when immobilizer encryption flaws were found in some Toyota, Hyundai, and Kia keys — evidence the weakness was architectural, not one automaker's mistake.

First-order effects

  • Millions of Volkswagen owners are left holding fobs whose secrets cannot be individually rotated, since the cloned key material is baked into the fleet — remediation falls on dealers and lock re-keying rather than a software patch.
  • Volkswagen faces the disclosure directly: Garcia's team withheld publication for years negotiating fixes, so the company has had lead time, but the shared-key design limits how much of the fleet any fix can reach.

Second-order effects

  • Other manufacturers using similar immobilizer architectures face pressure to audit their own key hierarchies — a check that four years later surfaced equivalent flaws at Toyota, Hyundai, and Kia, confirming the problem crossed suppliers and brands.
  • The economics of the attack invert the usual threat model: when cloning needs only cheap radio hardware rather than bespoke equipment, insurers and fleet operators price physical theft risk differently than they do for per-vehicle-unique systems.

Third-order effects

  • Shared-secret designs across vehicle fleets prove structurally fragile, pushing the industry toward per-vehicle cryptography and, eventually, distance-bounding defenses like the ultra-wideband keyless system that GoGoByte's 2024 relay demonstration against a Tesla Model 3 still managed to defeat.
  • A decade-long disclosure pattern — Birmingham's years-long embargo here, then successive findings through 2020 and beyond — hardens into the template for how automotive key vulnerabilities reach the public, feeding regulatory attention on vehicle cybersecurity standards.

The trend: Automotive keyless entry is locked in a decade-long cycle where each cryptographic fix shifts attacks to the next weakest layer — from range amplification to shared-key cloning to relay attacks on newer protocols.