started · updated
Security vulnerabilities identified in digital accounts and keyless vehicles
Recent reports highlight significant vulnerabilities in digital and physical security systems. In the realm of digital accounts, the use of passkeys is being promoted as a defense against rising phishing attacks. Unlike traditional passwords, passkeys utilize asymmetric cryptography and biometric authentication—such as fingerprints or facial recognition—to create a link between a device and a service. This method is described by the FIDO Alliance as ‘phishing-resistant and secure by design’ because it eliminates shared secrets that attackers can intercept.
Simultaneously, a study by the German motoring organization ADAC has identified critical flaws in keyless vehicle entry systems. Testing of over 850 car models revealed that nearly half of the vehicles tested are susceptible to radio signal relay attacks, where criminals intercept and extend the signal between a key and the car. In one-third of the tested vehicles, thieves were able to start the engine within a minute. While technology such as Ultra Wideband (UWB) exists to prevent these attacks by measuring signal travel time, many manufacturers have yet to implement it.
Entities
ADAC · FIDO Alliance · Google