Anyone within Bluetooth range can unlock vehicles and disable engines using alarms that owners may never have purchased.
VM/Getty Stock
The latest car news and reviews, with no nonsense.
Subscribe to our free daily newsletter for the most important stories delivered to you every weekday.
Many car dealerships provide optional alarm systems as an added feature when purchasing a vehicle. One company, Karr, is a prominent player in this market, boasting its technology in around 2 million cars across the United States. However, not all vehicle owners may realize their car is equipped with a Karr alarm. This is partly because some dealers install these systems regardless of whether buyers opt to pay for their services.
This is concerning, as researchers from UC San Diego have identified a vulnerability in Karr’s system that could enable malicious individuals to unlock car doors, disable ignition, and cause various disruptions via Bluetooth commands.
Fortunately, security experts have already alerted Karr, which has released an update to fix the problem, according to Wired. This update can be downloaded through a companion smartphone app available to anyone, regardless of whether they are paying subscribers. If you’re not a subscriber, like most of us, you might wonder how to check if your vehicle has Karr equipment. Vehicles with this system typically have stickers labeled “Karr” or “SWDS” on their driver-side windows, but if you're unsure, it may be worthwhile to ask your dealer.
According to Karr, there is no cause for alarm regarding this vulnerability, and the company plans to collaborate with dealers to inform owners of affected vehicles. A company spokesperson told Wired, “The vulnerability described in [UCSD’s] research is highly complex and poses a low risk to customers in real-world scenarios.” However, they acknowledged the need for a swift response, stating they have developed a firmware update to resolve the issue. That being said, it took the company 18 months to roll out this patch.
A screenshot from Karr’s website highlighting the features of its alarm systems.
The reassuring stance from Karr contrasts with the opinions of researchers, who view the situation more critically. One UCSD professor labeled this issue as “probably the worst” car hacking threat to date. These experts also demonstrated to Wired how a Karr-equipped vehicle without the latest update could be easily compromised if the hacker has the appropriate software.
Vehicles with Karr alarms are vulnerable not only when in operation; the Bluetooth radio remains active for 10 minutes after the vehicle is turned off, increasing the likelihood of an attack.
The reason Karr's hardware is found in so many more cars than it is actively used stems from the practice of some of the over 3,000 dealers partnered with the company incorporating the technology as a theft prevention measure. When vehicles are still on the lot, dealers can utilize Karr’s systems to track their inventory. Upon sale, dealers may offer customers the option to pay a fee for the security service. However, if customers decline, the alarm is often not removed; they may need to request its removal, and even then, not all dealers are willing to comply without making it difficult for the customer.
This situation reflects another challenge of modern connected car ownership. Yet, unlike the SignalTrace or Flock issues we've reported on recently, this problem appears to have a straightforward solution: legally require dealers to remove such alarms from vehicles at the point of sale unless the customer has agreed to keep and pay for the monitoring service. The risk posed by leaving unnecessary hardware in vehicles is too significant to ignore, and dealers must recognize that they are compromising everyone’s safety unless they take this matter seriously.
Have a tip? Contact us at tips@thedrive.com.
Otros artículos
Anyone within Bluetooth range can unlock vehicles and disable engines using alarms that owners may never have purchased.
A dealer-installed alarm in two million vehicles is susceptible to hacking. What's more concerning is that owners might not even be aware that their car is equipped with one.
