Many dealers offer optional alarms as an add-on when you buy a vehicle from them. One company called Karr sells such systems and is a leader in this space, with its tech installed in approximately 2 million vehicles across the U.S. However, not every owner may be aware that their vehicle has a Karr alarm to begin with, and that’s because some dealers actually install and leave them there, whether buyers choose to pay for their capabilities or not.
That’s a problem, since UC San Diego researchers have just discovered a vulnerability in Karr’s system that could allow nefarious actors to send commands over Bluetooth to unlock car doors, disable ignition, and enable all sorts of other chaos.
Fortunately, this is one of those cases where security experts have already notified Karr, and Karr has pushed out an update to patch the oversight, per Wired. This can be installed via a companion smartphone app that anyone can download, whether they’re a paying subscriber already or not. If you fall into the latter camp, as I’m sure most of us do, you may wonder how to determine whether your car even has Karr equipment in it. Turns out that such vehicles have stickers that read “Karr” or “SWDS” on their driver-side windows.
If you believe Karr, this vulnerability is nothing to worry about, and the company intends to work with dealers to notify owners with affected vehicles. “The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions,” a spokesperson from the firm said to Wired. “Nevertheless, we responded promptly and developed a firmware update to address the issue.” (“Promptly,” in this case, is doing some heavy lifting, as it apparently took 18 months for the company to issue this patch.)
The only problem with that calm tone is that researchers, frankly, don’t agree with it. One UCSD professor called this “probably the worst” car hacking threat to date. These experts also demonstrated to Wired how easy it is to mess with a Karr-equipped vehicle that doesn’t have the new update installed yet, so long as the hacker has the right software.
Karr-alarmed vehicles aren’t just liable to these threats while they’re running; the system’s Bluetooth radio stays on for 10 minutes after a car’s been turned off, which widens the window for potential trouble.
The reason Karr’s hardware is present in so many more cars than they’re actually used in is that some of the 3,000-plus dealers nationwide that the company works with incorporate the tech as a loss prevention measure. Before sale, when cars are still on the lot, dealers can track their inventory using Karr’s systems. And then at the point of sale, dealers will offer customers the choice to pay a regular fee to benefit from that security themselves. But if they refuse, the alarm isn’t necessarily removed; customers may have to request it, and even then, not every dealer is going to go along with that request without making life difficult.
Part of this is yet another symptom of modern connected car ownership. But unlike the SignalTrace or Flock phenomenon we’ve been covering extensively (and, unfortunately, first-hand) as of late, this problem seems to have a common-sense solution: legally mandate that dealers must remove alarms like these from their cars when sold, unless that customer has consented and wants to pay for that monitoring going forward. The potential for bad actors to exploit extraneous hardware that never needed to be in the car in the first place is too great to just leave it there, and the dealers in question need to understand that they’re putting everybody at risk unless they take this sort of thing seriously.
Got a tip? Reach out to [email protected]
Read the full article here
