With the press of a button on this homemade Android app,
I’m about to hack all of these cars.
[car horns beep]
In fact, this device inside all of these vehicles
makes it disturbingly easy for anyone to carjack them,
paralyze them, trigger chaotic effects like I just did,
or even silently steal a car and drive it away.
And the wildest part is that this hidden hackable device
is installed in millions of cars across America.
In about half of those vehicles,
the owners have never asked for it
and might have no idea it’s even in there.
[Yibo] There’s another one.
[Aaron] And there’s another one right there.
My goodness, they’re everywhere.
It may well be inside your car right now.
I’m Andy Greenberg.
I investigate the strange, dark,
and subversive sides of technology for Wired.
This is HackLab, the hidden hackable device
that lets me steal your car.
To learn about this new car hacking technique,
I traveled to the University of California at San Diego
to meet with the security researchers who discovered it,
computer science professor Aaron Schulman and his team.
Aaron, so this is the device.
This is a car alarm that is installed by dealers
into cars that they sell
while they’re sitting on the parking lot waiting to be sold.
In Southern California for years,
there was a big problem with theft from dealer lots.
They install it behind the dashboard.
They’ve really mounted this thing
quite deep inside of your car.
They actually cut the ignition wire at the dealer,
and they spliced this in the middle,
and that allows them to prevent the car from starting
when it’s sitting on that dealer’s lot.
I mean, I can see this is a module
with a million wires coming off of it.
What does it connect into in a car?
All the high security systems inside the car
that are used for access, so door locks,
lights, trunk, et cetera.
So this is actually a security device,
but what is the security issue that you found with it?
All of these systems actually have
the same universal key built into them.
Now the issue with that
is the system can be used by an attacker
to also immobilize your car.
And that key is unfortunately on millions of alarms
that have been deployed by these dealers,
mostly originating in Southern California,
but also now have been resold throughout the country.
How did it end up in cars on the road
and in people’s driveways and parking lots
around the country?
When you’re with a dealer
and they’re trying to negotiate the price,
they’ll actually say to you,
There’s also this alarm system.
We already put it in your car.
Do you want to perhaps pay for this as an upgrade,
and then you can have access from your smartphone
and you can control your car to unlock, lock,
activate the horn [horn honks]
[horn honks] from that smartphone app?
And then what happens if I say no?
You can, as the purchaser say,
I do not want this system in my car.
They will say, Okay, fine.
We’ll deactivate the system.
And once it’s deactivated,
we already put it in your car with all these wires,
it’s quite deep in there, but it won’t work anymore.
Now, unfortunately, what we found in our research
is even if the system has been deactivated,
it is still operating.
And whenever the car is turned on,
this actually wakes up and the Bluetooth radio turns on,
and now you can connect to it as an attacker
and remotely control it.
Wow, that is so insidious.
This thing people didn’t ask for,
in fact, they actively asked not to have it in their car,
is still in the guts of their vehicle
making it much less secure.
That’s right.
So how can people find out
if they have this device hidden in their car?
It’s really obvious, actually.
Let me show you.
Here’s the sticker right here.
If you have this sticker that says KARR,
you likely are vulnerable to this attack.
Yeah, that’s pretty clear.
And if you look down in the bottom here
under the dashboard, this little blinking light
indicates that you have this system running
and you have to get it patched.
Last year, the UCSD team warned Acrisure Protection Group,
the company that sells the car alarm device,
about the hacking technique they had discovered.
The company responded just this week
by rolling out a security update.
So if you have KARR installed on your vehicle,
you can now download or update your KARR app on your phone
to patch the device and protect your car.
But there’s no automatic software update mechanism.
Car owners will need to manually install the fix
or their vehicle stays vulnerable.
So this is actually Sumanth’s car, one of our students.
He was the first to volunteer to have their car hacked.
Did you actually pay for this?
Like do you have it active in your car?
No, I did not pay for this.
But as it turns out, with just a button click,
I can activate it as long as it’s parked
just a few minutes ago.
Or if the car is on and driving, right?
[Sumantha] Yes. So can you show us?
[Sumantha] Sure, so right now, I’m going to convert it
from this deactivated state into an active state.
So that little honk was the only sign you’re going to get
that your car just became vulnerable?
Yes, just the honk.
Now, I can lock the car.
Go ahead, try to see if you can unlock it.
And as it turns out, we can also unlock the car.
[Andy] Yep.
So now you can honk the horn,
for instance, [horn honks]
and you can also turn on and off the lights.
So as it turns out, we can also immobilize the car.
So you can sit in, try to switch on the ignition,
and it’s not going to work.
[Aaron] So why don’t you go ahead and start it,
make sure it works?
[engine revs]
Now go ahead. Perfect, so.
Yeah, try it again.
[Aaron] Is it working, Andy?
[Andy] No, it’s not starting.
It’s not starting. Yeah.
Nothing.
It says key not found.
At this point, you would need to actually tow the car
if you want to drive it again,
because the person that owns it
has no idea why their car won’t even start anymore.
So you can basically paralyze any car
that’s in Bluetooth range of your phone?
[Sumantha] Exactly.
That seems like a very serious problem.
Before we demonstrate how this hacking technique works
by stealthily stealing a car
from the driveway of a private home,
I took a ride around La Jolla with Aaron and Yibo,
one of the researchers on his team,
to get a sense of just how many cars
had this secret vulnerability.
We’re scanning nearby signals that car alarms emit.
This is the counter mode of my app,
where here are all the serial numbers of car alarms nearby.
So far we’ve seen eight of those.
Oh, there’s nine.
There’s another one. Oh, 11.
Wow, two more.
Oh my goodness, they’re everywhere.
There’s 16. Most dealers,
they’re all operating this car system,
so essentially almost any of those cars
that we see in Southern California
is gonna have a car alarm in it.
Based on some experiments we’ve done
in looking at data across the country,
we see that these alarms show up
in every city in the United States.
Let’s see how many we count in this garage.
The number is going up very quickly.
We’re already at 20.
What we’re counting here are active car alarm systems.
It’s most likely to be active at once
because the active alarms, they stop beaconing
after they’re parked for a while.
[Andy] We’re 27 now. Yeah, we’re 27.
I just see two window stickers there.
Just as you drove by,
you could immobilize every vulnerable car
in the whole parking garage.
Yeah, that’s right.
We are at 37.
Vulnerable cars were everywhere,
all giving off the same telltale Bluetooth prefix.
Aaron’s team estimates
that more than two million cars nationwide
have the car system installed.
They got that number by studying data from WiGLE,
a crowdsourced app where users known as Wigglers
compete to log Wi-Fi and Bluetooth signals
they pick up with radio antenna.
Aaron’s team then used the serial numbers
of the devices in WiGLE with the car signature
to extrapolate how many of these systems may be out there.
But WiGLE also collects location data
tied to all those radio signals too, right?
Yes. And so does that mean
that you can track someone’s location
based on these car alarm radio signals also?
[Yibo] Oh yes, totally.
Now the problem with that is if you get that data,
the serial number does not change,
so you can track where someone lives, where someone works.
Somebody wouldn’t even need to follow you
back to your home or to where you parked the car.
They could just find that same radio signature on WiGLE.
As part of our research,
we investigated in the WiGLE database
how many cars were actually targetable,
and we noticed that there are quite a lot of cars,
where we see them stationary,
and that means likely they will be seen again and again
at the same location.
It could be the case that someone
could use those public databases to target individuals
that have that vulnerable vehicle.
I mean, this is all very creepy and scary.
We’re now in a pretty crowded parking lot.
Let’s see how much the count goes up.
It already goes up to 67.
[Aaron] There’s another one right there.
Now we’re up to 74.
In any parking lot in San Diego,
you’re going to see dozens and dozens of these things.
88, 89.
Oh, we have 90 right now.
I just want to note that we only drove around here
for about 20 minutes.
We stayed right next to the university’s campus.
We almost saw 100 cars that are vulnerable.
That is an insane amount of cars.
When you install something by default at a dealer
in every car that is sold,
the pervasiveness of that vulnerability
is going to be unimaginable.
Finding vulnerable cars is easy.
And what could someone do
with the power to unlock a car at will?
One disturbing possibility is carjacking.
Once a criminal has identified a target vehicle,
they could simply unlock it,
while someone is driving and exposed.
For demonstration purposes,
a UCSD employee has volunteered to pose as our victim.
All right, so let’s say we want to target
this vulnerable car up here.
All I have to do is we pull up behind it.
I’m going to activate.
You heard the beep?
It’s active.
This is a particularly scary idea, unlocked,
because a carjacker could remotely unlock the door
at a stoplight, then drag the occupant from the front seat,
or steal something from inside the car.
As real as that carjacking threat may be,
it’s not at all stealthy.
But if we wanted to actually steal a car
without confronting the owner,
all we would have to do is follow the driver home
or wherever they park,
or find those locations in the WiGLE database
and wait for a quiet moment to make our move.
In just a few minutes, we’ll show you how easy and stealthy
stealing that car can be.
So easy that even I,
with no experience using Aaron’s technique,
could probably do it in under two minutes.
But before we attempt hacking enabled Grand Theft Auto,
let me give you some quick historical context
on this technique and how we got here.
For over a decade, I’ve covered the evolution
of hacking techniques that affect modern connected vehicles
with digital features.
That story actually begins here
at the University of California San Diego.
So while I was on campus, I met with Stefan Savage,
who co-led the team at UCSD
that was the first to ever hack a car’s steering and brakes.
Back in 2008, we didn’t know what we were doing
and cars were really complicated,
and we had to reverse engineer how they work.
The big one was we reverse engineered
at the time how the OnStar cellular signal worked.
And so 1500 miles away, we could take over your car,
unlock it, lock it, turn off the engine.
We could make it skid on the brakes.
That experiment, which UCSD carried out
with the University of Washington
was the first time that cars were proven to be hackable.
But then, in the summer of 2015,
security researchers Charlie Miller and Chris Valasek
carried out an even more dramatic demonstration
that changed the auto industry forever,
with me behind the wheel as their crash test dummy.
Okay, hold on tight, hold on.
Oh [beep].
Miller and Valasek told me to drive a Jeep Cherokee
onto a highway in Missouri.
Then, the two hackers remotely took control of the vehicle
from miles away through its internet-connected
Uconnect infotainment system.
First, the radio blasted music,
then, the windshield wipers turned on,
the air conditioning failed,
and finally, the Jeep slowed to a stop on the highway
as the hackers disabled my transmission.
The fallout of our stunt was immediate.
Days after my story was published,
Fiat Chrysler issued the first major cybersecurity recall
in automotive history, recalling 1.4 million vehicles
to patch the vulnerability
that Miller and Valasek had exploited.
What began as a shocking experiment led to car makers
being suddenly forced to think like tech companies,
launching bug bounty programs
that pay independent researchers
for reporting hackable vulnerabilities,
hiring cybersecurity researchers,
and redesigning vehicle systems
to better isolate critical controls
from internet connected features.
These experiments showed that a malicious hacker
could pose a very real safety threat to modern vehicles,
but thankfully, none of those attacks
on cars’ driving systems have ever been seen in the wild.
Why do you think that it is that we’ve never actually
seen those attacks used in practice?
Because people don’t want to hijack cars.
There are easier, cheaper,
and more effective ways to kill somebody.
It’s not a solution to an actual problem that people have.
Where the action is is car theft.
We have made the security in cars strong enough
that there really is no way to steal a car today
without hacking it.
And the reason is, we’ve gotten so good
at protecting our cars,
like your cars now, they have immobilizers,
and so you can go in, you can break the window,
you can try to hotwire.
None of that stuff is going to work anymore.
If you want to steal a car, you have to hack the car today.
In other words, car hacking has continued to evolve
and it’s actually become much simpler.
It shifted from the highly complex attacks
that take over steering and brakes
to far, far easier exploits
that can simply take over cars’ smart features,
sometimes via their connection to a phone,
or even with simple web vulnerabilities.
In just the last few years,
security researchers have found Bluetooth exploits
that can unlock Teslas,
relay attacks that let thieves steal cars
using wireless key fobs,
and security flaws in the phone apps used by Kia,
Subaru, and dozens of other car makers
that expose vehicle controls or even location tracking.
So there is a huge black market of devices,
where you take out the front headlight
and try to plug into the CAN bus and reprogram it.
And so this is part and parcel of how car theft works now.
Devices that will steal the keyless entry signal
from someone’s house, that is where the action is.
So what do you think about Aaron’s team and their research
into this other third party device?
In some ways, it’s even creepier.
It’s definitely creepier.
There is a device that has been added to your car,
unbeknownst to you,
that already does all the things you need to do.
You just need to tell it to do it.
So of all the car hacking techniques
that you’ve seen and witnessed
and even developed yourself in the last decade and a half,
how would you say that this car alarm exploit stacks up?
Like, how does it compare in terms of severity?
As far as severity, I think it’s probably the worst,
and the reason is it affects a large number of vehicles
and the manufacturer of your car can’t fix it,
and you don’t even know you have the problem.
It provides all of the elements that a car thief would want,
but you have none of the advantages we normally have,
in terms of defending it,
because you are disconnected from the supply chain
that put it there.
That means the security vulnerability that UCSD found
puts a huge number of cars at risk of stealthy theft,
as I’ll demonstrate in a moment.
To understand how the team found it,
I spoke with them inside their actual hardware hacking lab.
Can you tell me the story of how you found this device
and how you figured out that it was hackable?
So back in 2019, we were working on a different project.
This was to investigate Bluetooth skimmers
that criminals actually used to steal your credit card info
and plant them at gas stations.
And during that time,
I was doing a lot of Bluetooth device scanning,
and I would keep seeing these Bluetooth devices
with a very particular name
that would show up often at these gas stations.
And then eventually I started seeing them also
in parking lots and parking garages.
I initially thought it was some form of a payment system,
perhaps, but then these would also show up
as we were driving along the freeways.
So I figured it was a particular type of vehicle.
Eventually as I looked further,
we realized that this was not just a type of vehicle,
this was basically any consumer vehicle out there.
So you knew that it was something inside of vehicles
all over the place that you were seeing, even on the road,
but how did you figure out
that it was specifically this KARR car alarm?
As Nishant mentioned, there was a particular device name.
So we took the prefix of that device name,
searched it up on Google, and we actually found a FCC filing
that allowed us to link that device to its manufacturer,
that is KARR.
[Andy] The team then turned their focus to the KARR app,
which allows users
to control their security system via Bluetooth.
So once we reverse engineered their application,
we quickly realized,
after understanding their internal authentication protocol,
that it was so simple that we could actually just extract it
and re-implement it as our own application, which we did.
So basically you took their app,
which is meant to just authenticate and unlock a single car,
and instead, you built an app that can unlock any car.
Every single car that they have ever put this in.
So it was actually more than 18 months ago
that you first told Acrisure Protection Group
about this discovery.
Did they leave this vulnerable all that time?
They’ve been developing a patch
and they did actually give it to us to test.
Do you believe that this problem actually can be fixed?
This is a Bluetooth only device.
It has no cellular modem,
no connectivity online all the time.
That means that it has to be manually patched
on every single one of these alarms
and every single car that has been deployed.
To show just how important it is to install that fix,
I’m going to attempt to steal a car
without setting off the alarm,
smashing a window, [glass breaks]
or jimmying the lock.
In other words, without doing any of the things
that usually make it possible
to catch a car thief in the act.
Our victim is inside the house.
We’ve set up a camera to monitor her
and see whether or not she can hear me
or see any sign I’m stealing her car.
I know that your hacking technique
can unlock the target vehicle.
How do I actually start the car and drive it away?
So there’s actually a tool that car thieves commonly use
that’s originally actually a tool for locksmiths.
What it essentially does
is let them clone the key of the car.
Normally, the car thieves have to connect it inside the car
and to get in there they’re smashing windows.
But with this alarm, when you bypass it,
you can get in the car silently, plug this thing in,
and you’ll be able to steal the car.
Aaron and his team’s theft technique
focuses on allowing a car thief
to silently and instantly get inside a car,
where they can use a fairly standard locksmith tool
to connect to the dashboard and clone the key.
Here we go.
All right, I’m starting the timer now.
[Andy] Normally a thief would need to smash a window
or use some other trick to get the door open,
often setting off the alarm.
With Aaron’s team’s hacking technique, though,
I don’t need to do any of that.
I quietly unlock the car.
The alarm is suppressed and I’m in.
[Aaron] He’s going to now connect the system.
[Andy] That part is easy.
[Aaron] 20 seconds in.
Now I’m going to take the locksmith tool
and make a key for this car.
I’m not going to give you the details
of how this device works.
I don’t want to create a how-to video here,
but the process takes about two minutes,
even when I screw it up the first time.
It didn’t work the first time.
I’ve gotta try again.
It turns out for this model of car,
I have to turn the hazard lights on to make a new key,
but there’s no audible alert to get the victim’s attention.
It’s worth noting here
that if you do spot your car’s hazard lights
turning on unexpectedly in the middle of the night,
it could be a sign that a car thief
is inside cloning the key.
[Aaron] He’s looking around like he might be getting
to the point he’s about to start it.
[Andy] The tool has created a new key fob.
I press it to the ignition button
and the engine comes alive.
Lights are on, that’s a good sign.
Oh, here we go.
And I got it.
There it goes.
Wow, he’s really taking that thing away.
Is he going to bring it back?
[phone rings]
Hi. Hey, how’s it going?
Andy stole your car.
[Andy] I was struck by just how smoothly the process went.
I basically got away without alerting the owner.
Good job,
[Aaron] Andy. How did
that feel, Andy?
That is insane. How did I do?
What was my [indistinct]? It was about
two and a half minutes, a little bit longer than I expected,
but. Not quite
gone in 60 seconds,
but close. You know what?
There’s always some issues, but you nailed it.
Around the time of our car theft demo,
I reached out to Acrisure Protection Group,
the company that sells the car alarm device,
and asked them about the vulnerability in their system.
Like the team at UCSD had told me,
the company said it developed a firmware patch,
which is now available to install if you download the KARR,
that’s K-A-R-R Security smartphone app.
Just tap Customer Service on the home screen
to find the firmware update option.
Acrisure PG also wrote in a statement that,
The vulnerability described in the research
is highly complex and presents a low risk to customers
under real-world conditions.
Nevertheless, we responded promptly
and developed a firmware update to address the issue.
Whether the car alarm vulnerability
represents a quote unquote, low risk of abuse,
I’ll leave to you to decide
based on seeing the demos we just showed you.
As for the company’s claims that it responded
quote unquote promptly, Acrisure Protection Group
actually took well over 18 months to roll out its patch
after UCSD first contacted its security team.
The company also noted it would warn customers
about the patch Through in-app alerts,
dealer communication, and on its website,
but that strategy of contacting affected drivers
also leaves unanswered how Acrisure PG will reach car owners
who aren’t the company’s customers.
That includes car owners
who don’t even know they have its vulnerable device
in their vehicle.
Everyone that has this in their car,
including people that don’t even know they have it,
because they said no to having the system installed,
now needs to run a firmware update
from their phone onto this device
in order to patch this universal key that’s on there.
But the complication here
is that this isn’t like a product somebody bought
that they’re now just being told to install an update on.
It’s something that people actually asked
not to have in their cars.
They don’t even know that it’s there.
How do you reach those people to get them to patch?
Actually, that is one of the reasons
I’m doing this interview right now.
Doing that kind of massive update
is going to require a huge awareness campaign.
I want as much media attention as possible onto this,
because in the end, there is no other way
we can reach the millions of people
than to just make it widely known this is happening
and get them to install that patch on their car.
It’s been more than a decade
since I personally witnessed the problem
of KARR’s digital insecurity
in a very firsthand demonstration.
But now the most imminent automotive cybersecurity threat
may not be elite hackers
taking over your vehicle from miles away
and driving your car off a cliff.
Instead, it’s the invisible ecosystem
of third-party connected hardware
silently embedded in modern vehicles
by manufacturers, dealerships, insurers, and vendors.
That means you need to be aware
of digital threats to your car,
think twice about the security of gadgets you plug into it,
and install security updates and patches.
Modern technology has made cars safer, more convenient,
and more reliable than ever before,
but some of those same upgrades and features
have also created serious security vulnerabilities,
including in at least one device
that plenty of drivers don’t even know is under their hood.
This is Hacklab.
I’m Andy Greenberg.
[upbeat music]
Click Here For The Original Source.
