
The Department of Computer Science at ETH Zurich presents a paper documenting hacking techniques on Passive Keyless Entry and Start Systems (PKES).
The hardware setup seems simple enough. The group states:
The cable relay was performed with off-the-shelf coaxial
cables. We built two 30 m cables that we combined for the
60 m relay tests. We used a set of antennas, two small simple
home made antennas, and a large antenna for an improved
antenna-key range. We performed the attacks with
these antennas both with and without amplification. If the
LF signal near the car was weak we used a 10 mW low noise
amplifier to increase the signal level.
To summarize this hack, the small circular white antenna serves to channel the LF transmission from the car down the coax to a second antenna near the location of the owner’s key. The key then replies with authentication to the car over its usual UHF radio link which operates over longer ranges and involves no extra hardware. Obviously this will only work under limited unique circumstances where the key is left unattended but secured, such as in a parking attendant’s booth. Nevertheless, this illustrates a non-obvious, low-tech hacking vector.

Thats pretty cool, on older cars that we would repair here if the locks had been damaged by someone up to something, but not wanting to change the immobiliser system with it or program the new keys(quite expensive), we would change the lock and then tape the old key to the ring that would read it, so you had a new unprogrammed key, new lock and old key stuck in the shaft. Of course not the best thing where security was concerned thinking about it… :P