Model Y broken into

Model Y broken into

Author
Discussion

Broken Hero

Original Poster:

1,195 posts

198 months

Saturday 21st October 2023
quotequote all
Morning all. I went out to the car today to find it open.

The console in front of the arm rest was open and some sunglasses were missing as well as a buggy from the boot.

Nothing showing on the ring doorbell. Sentry mode was not on - I do not typically leave it on at home (that will change) but it is pin to start.

I've seen on my phone that I had a notification around 4am to say the car is unlocked (I was asleep at the time so would've missed it)

Question is, any idea how they could've got in the car? Keycards are kept well away from the front of the house.


CheesecakeRunner

3,827 posts

92 months

Saturday 21st October 2023
quotequote all
Put your phone in the same place it was last night. Then leave it there and go out to the locked car. Can you open it? If so, your phone’s Bluetooth range is sufficient that the phone key still works.

However, this is unlikely because the car measures signal strength and only allows unlock when you’re close. I’m currently sat less than 2m from my car with my phone, and it won’t unlock.

So the most likely explanation is the car wasn’t locked in the first place. Was a door not shut properly which prevented walk away locking from working? Or if you used the key cards, did you tap in just the right place and see it actually lock? Scummers do just walk down streets trying the handles of every car in case one isn’t locked. I’ve got them on my security cameras several times. It’s unlikely to have been targeted.

The key cards don’t do any sort of broadcast so relay attacks don’t work, and Bluetooth relay attacks aren’t a thing outside of security labs.

Broken Hero

Original Poster:

1,195 posts

198 months

Saturday 21st October 2023
quotequote all
Hi I'll try the first idea (leave the phone where it was last night)

The car was last used on Sunday, I walk past it every day and the wing mirrors are always 'tucked in'- 4am this morning is the first notification I had for it being unlocked.

I noticed instantly this morning that the wing mirrors were out before seeing the notification and checked boot etc


LivLL

10,886 posts

198 months

Saturday 21st October 2023
quotequote all
Can you get Tesla involved to look at the car logs? I seem to remember there was a relay attack going around last year which thieves just loitered and scanned the key card transmission from a safe distance before replicating it to later enter and steal the car.

It's one of the reasons pin to drive was introduced from what I remember.

https://labs.ioactive.com/2022/09/nfc-relay-attack...

Seems unlikely but you never know, more likely the app was used or someone has another key card. You can check on the screen which keys are assigned to the car.

Edited by LivLL on Saturday 21st October 11:20

Broken Hero

Original Poster:

1,195 posts

198 months

Saturday 21st October 2023
quotequote all
Thanks 👍 yes I'll call Tesla. I've looked at the keys and it's just mine and OHs phones. This really is a mystery.

I believe someone somehow unlocked the car stole the items and then left it unlocked - hence the notification.

I also have walk away locking so not sure why it would've just stayed unlocked if the car 'recognised' a key.

Broken Hero

Original Poster:

1,195 posts

198 months

Saturday 21st October 2023
quotequote all
Looking at my ring doorbell footage -;the wing mirrors were in at 3.36 - but out at 4.36 - which would be around when the 'car unlocked' notification was received. So the car was locked and they found some way in without setting off the alarm. Any help with this would be appreciated 👍

BBYeah

331 posts

184 months

Sunday 22nd October 2023
quotequote all
Is your ring device on wifi? Could they have used something to disrupt the wifi connection, if so, seems worryingly organised. Or could the car be reached without the motion detection being triggered?

skwdenyer

16,536 posts

241 months

Monday 23rd October 2023
quotequote all
Broken Hero said:
Looking at my ring doorbell footage -;the wing mirrors were in at 3.36 - but out at 4.36 - which would be around when the 'car unlocked' notification was received. So the car was locked and they found some way in without setting off the alarm. Any help with this would be appreciated ??
Is the area around the car not sufficient to trigger motion alerts on the Ring?

AlexIT

1,497 posts

139 months

Tuesday 24th October 2023
quotequote all
I am not sure how these work, but could a bluetooth range extender be used to trick the car?
I mean something like this: https://www.newegg.com/p/1B4-09RP-00M27

They might have picked up your bluetooth signal and amplified it so that the car recognized the device proximity?

Or maybe my idea could be good for some movie screenplay?

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
BBYeah said:
Is your ring device on wifi? Could they have used something to disrupt the wifi connection, if so, seems worryingly organised. Or could the car be reached without the motion detection being triggered?
Sorry for the delay in responding - yes ring is on WiFi so can be jammed. It's possible to walk to the back and drivers side without disrupting it

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
I believe either they have somehow been able to boost my/OH's Bluetooth signal or something is still in or on the car that is boosting the signal. Tonight I tested it with sentry mode on and my phone in the house on the dining table with Bluetooth on. My car is parked on the street the phone around 30 lft away. I walked up to the car and opened the door. Worked every time. I could walk up to the car and open the door without my phone or key card - in calling Tesla to inspect the vehicle.

If you are reading this and use the phone key - I strongly recommend turning Bluetooth on your phone off.

Register1

2,143 posts

95 months

Tuesday 24th October 2023
quotequote all
Broken Hero said:
Hi I'll try the first idea (leave the phone where it was last night)

The car was last used on Sunday, I walk past it every day and the wing mirrors are always 'tucked in'- 4am this morning is the first notification I had for it being unlocked.

I noticed instantly this morning that the wing mirrors were out before seeing the notification and checked boot etc
If you havent got windows to close on lock, if a window is left just 5mm open, doors will not lock

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
Windows are set to close on lock

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
Broken Hero said:
I believe either they have somehow been able to boost my/OH's Bluetooth signal or something is still in or on the car that is boosting the signal. Tonight I tested it with sentry mode on and my phone in the house on the dining table with Bluetooth on. My car is parked on the street the phone around 30 lft away. I walked up to the car and opened the door. Worked every time. I could walk up to the car and open the door without my phone or key card - in calling Tesla to inspect the vehicle.

If you are reading this and use the phone key - I strongly recommend turning Bluetooth on your phone off.
Tried it again - turned Bluetooth on - put phone on dining table - walked up to car - and I was able to enter as if I had the phone on me. I tried it multiple times - and it worked every time


Tried again with bluetooth off, and (as expected) the door wouldnt unlock. Oddly though rather than showing the sentry mode screen, it just asks me to present the key card. Sentry mode is activated

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
I've contacted Tesla via the app will see what they say. This is a serious security flaw imo which we have found out about the hard way

jeremyc

23,527 posts

285 months

Tuesday 24th October 2023
quotequote all
Bluetooth range can be 10m up to 100m or more (depending upon the devices each end and radio propogation conditions).

If the car is relying on a Bluetooth signal to the app on a mobile phone, then it almost certainly can be unlocked if the phone is 30ft away (with Bluetooth enabled).

TTmonkey

20,911 posts

248 months

Tuesday 24th October 2023
quotequote all
This is total madness.

Broken Hero

Original Poster:

1,195 posts

198 months

Tuesday 24th October 2023
quotequote all
jeremyc said:
Bluetooth range can be 10m up to 100m or more (depending upon the devices each end and radio propogation conditions).

If the car is relying on a Bluetooth signal to the app on a mobile phone, then it almost certainly can be unlocked if the phone is 30ft away (with Bluetooth enabled).
Thanks Jeremy - One would expect the 'receiver' on the vehicle to only work when close to the phone for security purposes? Typically when out and about with my 7 year old, she will run up to the passenger side and press the handle to open the door - the car will not open until I've caught up and I'm a couple of feet away (with my phone in my pocket)

I believe this is the standard operation of the car and how it works for most people.

I don't think what is happening here is right - I now believe an opportunist was probably trying handles and got lucky as at the moment, you only have to walk up to the car, try the handle and it will open (when bluetooth on my phone is enabled)





AlexIT

1,497 posts

139 months

Wednesday 25th October 2023
quotequote all
Register1 said:
If you havent got windows to close on lock, if a window is left just 5mm open, doors will not lock
Mine are always partly open in the garage and the car locks.

It's worrying however that with the phone in the house the car can be opened. I will see both at home and at the office how it goes.

NDA

21,621 posts

226 months

Wednesday 25th October 2023
quotequote all
Interesting - I will experiment with mine when I get home.

At the moment it always seems to want the phone close to the car - I quite often have to show the car my back pocket (where the phone is) by twisting around to get the boot or door to open.