Cars

Aftermarket Anti-Theft Device Owners Don’t Know How Vulnerable They Are to Hacking

Aftermarket Anti-Theft Device Owners Don't Know How Vulnerable They Are to Hacking





When you install an anti-theft system in your car, you reasonably expect that it will make it more difficult to steal your car. We can debate how useful or not various anti-theft systems are, but they certainly shouldn’t make your car any easier to steal. According to reports, a team of researchers at the University of California, San Diego has discovered exactly that about one system in particular. wired. And to make matters worse, many drivers may not even realize that this system is installed in their car, adding no protection and all the vulnerabilities.

The device in question is KARR Security System. unrelated to Knight Automated Roving RobotIt offers many of the standard features of KARR modern security systems, such as remote lock/unlock, engine immobilization, and GPS tracking in case your car is stolen. It is used primarily by dealers to protect their own lots before selling a car and to offer it as an additional cost add-on to customers. When customers refuse, dealers deactivate the vehicle’s KARR instead of removing it.

KARR is present in more than two million vehicles. UC San Diego Today Explains in detail:

The majority of vulnerable vehicles from 2017 to today were purchased at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California. But because these vehicles are resold on the second-hand market, many millions of unsafe vehicles can be found throughout the United States, Canada, and even Japan. Many unsafe cars display a sticker with the words “KARR” or “SWDS” on the driver’s side window.

“SWDS” means Southwest Dealer Services, a subsidiary of Accusure Protection Group, the parent organization that sells KARR.

It was said that you will stop thieves, not help them.



By reverse-engineering the KARR mobile app, UCSD researchers were able to write their own code, allowing them to control every function provided by KARR in any vehicle equipped with the system, including inactive devices left by dealers. The team showed many such feats In this videoAnd for wired:

…researchers showed that they could use their own Android app to send Bluetooth commands to vulnerable vehicles that had KARR installed to carry out a wide range of potentially disruptive or dangerous hacking. Demo exploits can, with the tap of a button, unlock a car at a stop light to enable theft or carjacking, instantly disarm a parked car to prevent it from starting, or even hack a group of cars with a “pandemic” button built into the app to turn on their horns and lights simultaneously and repeatedly, as researchers demonstrated for WIRED in a UCSD parking lot.

The good news is that, unlike Hyundai and Kia thefts, KARR does not allow a would-be thief to start and drive the car. KARR does not have access to the ignition control except when immobilizing it, so one cannot steal a car with the hacked KARR app alone. The bad news is that as an aftermarket system, KARR is not limited to any one make or model, so any vehicle equipped with KARR, regardless of make or model, may have this vulnerability. Unlocking the doors via the app provides easy direct access to the car’s diagnostic port, making it easy to program the key fob and drive.

problem and solution

The crux of the problem is that KARR uses the same authentication key across all of its devices. The KARR app includes this key to operate the system legitimately, but hackers can extract it from the app to use it for their own nefarious purposes. It also doesn’t help that KARR devices have open Bluetooth connections. Even inactive units have this, making it possible to reactivate and exploit them.

Acrisure Protection Group doesn’t seem particularly concerned about this exploit:

When WIRED contacted Accusure Protection Group about the KARR security flaw, a spokesperson responded in a statement: “The vulnerability described in (UCSD’s) research is highly complex and presents little risk to customers under real-world circumstances. Nevertheless, we responded quickly and developed a firmware update to address the issue.”

Instructions to download and install this update through the KARR app are available here KARR websiteFor both active and non-active systems. However, it actually took 18 months to respond “immediately” when UCSD researchers first reported their findings to KARR in January 2025. His presentations about it at the USENIX security conference and the DefCon hacker conference in August may have inspired the timing of this release. Although the vulnerability may be “highly complex”, there are today’s car thieves who are adept at cloning key fobs and capturing their signals over the air. I hope a company that sells anti-theft devices might take security a little more seriously.



Leave a Reply

Your email address will not be published. Required fields are marked *