Watch I Stole a Car By Hacking This Hidden Device | Hacklab | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


With the press of a button on this homemade Android app,

I’m about to hack all of these cars.

[car horns beep]

In fact, this device inside all of these vehicles

makes it disturbingly easy for anyone to carjack them,

paralyze them, trigger chaotic effects like I just did,

or even silently steal a car and drive it away.

And the wildest part is that this hidden hackable device

is installed in millions of cars across America.

In about half of those vehicles,

the owners have never asked for it

and might have no idea it’s even in there.

[Yibo] There’s another one.

[Aaron] And there’s another one right there.

My goodness, they’re everywhere.

It may well be inside your car right now.

I’m Andy Greenberg.

I investigate the strange, dark,

and subversive sides of technology for Wired.

This is HackLab, the hidden hackable device

that lets me steal your car.

To learn about this new car hacking technique,

I traveled to the University of California at San Diego

to meet with the security researchers who discovered it,

computer science professor Aaron Schulman and his team.

Aaron, so this is the device.

This is a car alarm that is installed by dealers

into cars that they sell

while they’re sitting on the parking lot waiting to be sold.

In Southern California for years,

there was a big problem with theft from dealer lots.

They install it behind the dashboard.

They’ve really mounted this thing

quite deep inside of your car.

They actually cut the ignition wire at the dealer,

and they spliced this in the middle,

and that allows them to prevent the car from starting

when it’s sitting on that dealer’s lot.

I mean, I can see this is a module

with a million wires coming off of it.

What does it connect into in a car?

All the high security systems inside the car

that are used for access, so door locks,

lights, trunk, et cetera.

So this is actually a security device,

but what is the security issue that you found with it?

All of these systems actually have

the same universal key built into them.

Now the issue with that

is the system can be used by an attacker

to also immobilize your car.

And that key is unfortunately on millions of alarms

that have been deployed by these dealers,

mostly originating in Southern California,

but also now have been resold throughout the country.

How did it end up in cars on the road

and in people’s driveways and parking lots

around the country?

When you’re with a dealer

and they’re trying to negotiate the price,

they’ll actually say to you,

There’s also this alarm system.

We already put it in your car.

Do you want to perhaps pay for this as an upgrade,

and then you can have access from your smartphone

and you can control your car to unlock, lock,

activate the horn [horn honks]

[horn honks] from that smartphone app?

And then what happens if I say no?

You can, as the purchaser say,

I do not want this system in my car.

They will say, Okay, fine.

We’ll deactivate the system.

And once it’s deactivated,

we already put it in your car with all these wires,

it’s quite deep in there, but it won’t work anymore.

Now, unfortunately, what we found in our research

is even if the system has been deactivated,

it is still operating.

And whenever the car is turned on,

this actually wakes up and the Bluetooth radio turns on,

and now you can connect to it as an attacker

and remotely control it.

Wow, that is so insidious.

This thing people didn’t ask for,

in fact, they actively asked not to have it in their car,

is still in the guts of their vehicle

making it much less secure.

That’s right.

So how can people find out

if they have this device hidden in their car?

It’s really obvious, actually.

Let me show you.

Here’s the sticker right here.

If you have this sticker that says KARR,

you likely are vulnerable to this attack.

Yeah, that’s pretty clear.

And if you look down in the bottom here

under the dashboard, this little blinking light

indicates that you have this system running

and you have to get it patched.

Last year, the UCSD team warned Acrisure Protection Group,

the company that sells the car alarm device,

about the hacking technique they had discovered.

The company responded just this week

by rolling out a security update.

So if you have KARR installed on your vehicle,

you can now download or update your KARR app on your phone

to patch the device and protect your car.

But there’s no automatic software update mechanism.

Car owners will need to manually install the fix

or their vehicle stays vulnerable.

So this is actually Sumanth’s car, one of our students.

He was the first to volunteer to have their car hacked.

Did you actually pay for this?

Like do you have it active in your car?

No, I did not pay for this.

But as it turns out, with just a button click,

I can activate it as long as it’s parked

just a few minutes ago.

Or if the car is on and driving, right?

[Sumantha] Yes. So can you show us?

[Sumantha] Sure, so right now, I’m going to convert it

from this deactivated state into an active state.

So that little honk was the only sign you’re going to get

that your car just became vulnerable?

Yes, just the honk.

Now, I can lock the car.

Go ahead, try to see if you can unlock it.

And as it turns out, we can also unlock the car.

[Andy] Yep.

So now you can honk the horn,

for instance, [horn honks]

and you can also turn on and off the lights.

So as it turns out, we can also immobilize the car.

So you can sit in, try to switch on the ignition,

and it’s not going to work.

[Aaron] So why don’t you go ahead and start it,

make sure it works?

[engine revs]

Now go ahead. Perfect, so.

Yeah, try it again.

[Aaron] Is it working, Andy?

[Andy] No, it’s not starting.

It’s not starting. Yeah.

Nothing.

It says key not found.

At this point, you would need to actually tow the car

if you want to drive it again,

because the person that owns it

has no idea why their car won’t even start anymore.

So you can basically paralyze any car

that’s in Bluetooth range of your phone?

[Sumantha] Exactly.

That seems like a very serious problem.

Before we demonstrate how this hacking technique works

by stealthily stealing a car

from the driveway of a private home,

I took a ride around La Jolla with Aaron and Yibo,

one of the researchers on his team,

to get a sense of just how many cars

had this secret vulnerability.

We’re scanning nearby signals that car alarms emit.

This is the counter mode of my app,

where here are all the serial numbers of car alarms nearby.

So far we’ve seen eight of those.

Oh, there’s nine.

There’s another one. Oh, 11.

Wow, two more.

Oh my goodness, they’re everywhere.

There’s 16. Most dealers,

they’re all operating this car system,

so essentially almost any of those cars

that we see in Southern California

is gonna have a car alarm in it.

Based on some experiments we’ve done

in looking at data across the country,

we see that these alarms show up

in every city in the United States.

Let’s see how many we count in this garage.

The number is going up very quickly.

We’re already at 20.

What we’re counting here are active car alarm systems.

It’s most likely to be active at once

because the active alarms, they stop beaconing

after they’re parked for a while.

[Andy] We’re 27 now. Yeah, we’re 27.

I just see two window stickers there.

Just as you drove by,

you could immobilize every vulnerable car

in the whole parking garage.

Yeah, that’s right.

We are at 37.

Vulnerable cars were everywhere,

all giving off the same telltale Bluetooth prefix.

Aaron’s team estimates

that more than two million cars nationwide

have the car system installed.

They got that number by studying data from WiGLE,

a crowdsourced app where users known as Wigglers

compete to log Wi-Fi and Bluetooth signals

they pick up with radio antenna.

Aaron’s team then used the serial numbers

of the devices in WiGLE with the car signature

to extrapolate how many of these systems may be out there.

But WiGLE also collects location data

tied to all those radio signals too, right?

Yes. And so does that mean

that you can track someone’s location

based on these car alarm radio signals also?

[Yibo] Oh yes, totally.

Now the problem with that is if you get that data,

the serial number does not change,

so you can track where someone lives, where someone works.

Somebody wouldn’t even need to follow you

back to your home or to where you parked the car.

They could just find that same radio signature on WiGLE.

As part of our research,

we investigated in the WiGLE database

how many cars were actually targetable,

and we noticed that there are quite a lot of cars,

where we see them stationary,

and that means likely they will be seen again and again

at the same location.

It could be the case that someone

could use those public databases to target individuals

that have that vulnerable vehicle.

I mean, this is all very creepy and scary.

We’re now in a pretty crowded parking lot.

Let’s see how much the count goes up.

It already goes up to 67.

[Aaron] There’s another one right there.

Now we’re up to 74.

In any parking lot in San Diego,

you’re going to see dozens and dozens of these things.

88, 89.

Oh, we have 90 right now.

I just want to note that we only drove around here

for about 20 minutes.

We stayed right next to the university’s campus.

We almost saw 100 cars that are vulnerable.

That is an insane amount of cars.

When you install something by default at a dealer

in every car that is sold,

the pervasiveness of that vulnerability

is going to be unimaginable.

Finding vulnerable cars is easy.

And what could someone do

with the power to unlock a car at will?

One disturbing possibility is carjacking.

Once a criminal has identified a target vehicle,

they could simply unlock it,

while someone is driving and exposed.

For demonstration purposes,

a UCSD employee has volunteered to pose as our victim.

All right, so let’s say we want to target

this vulnerable car up here.

All I have to do is we pull up behind it.

I’m going to activate.

You heard the beep?

It’s active.

This is a particularly scary idea, unlocked,

because a carjacker could remotely unlock the door

at a stoplight, then drag the occupant from the front seat,

or steal something from inside the car.

As real as that carjacking threat may be,

it’s not at all stealthy.

But if we wanted to actually steal a car

without confronting the owner,

all we would have to do is follow the driver home

or wherever they park,

or find those locations in the WiGLE database

and wait for a quiet moment to make our move.

In just a few minutes, we’ll show you how easy and stealthy

stealing that car can be.

So easy that even I,

with no experience using Aaron’s technique,

could probably do it in under two minutes.

But before we attempt hacking enabled Grand Theft Auto,

let me give you some quick historical context

on this technique and how we got here.

For over a decade, I’ve covered the evolution

of hacking techniques that affect modern connected vehicles

with digital features.

That story actually begins here

at the University of California San Diego.

So while I was on campus, I met with Stefan Savage,

who co-led the team at UCSD

that was the first to ever hack a car’s steering and brakes.

Back in 2008, we didn’t know what we were doing

and cars were really complicated,

and we had to reverse engineer how they work.

The big one was we reverse engineered

at the time how the OnStar cellular signal worked.

And so 1500 miles away, we could take over your car,

unlock it, lock it, turn off the engine.

We could make it skid on the brakes.

That experiment, which UCSD carried out

with the University of Washington

was the first time that cars were proven to be hackable.

But then, in the summer of 2015,

security researchers Charlie Miller and Chris Valasek

carried out an even more dramatic demonstration

that changed the auto industry forever,

with me behind the wheel as their crash test dummy.

Okay, hold on tight, hold on.

Oh [beep].

Miller and Valasek told me to drive a Jeep Cherokee

onto a highway in Missouri.

Then, the two hackers remotely took control of the vehicle

from miles away through its internet-connected

Uconnect infotainment system.

First, the radio blasted music,

then, the windshield wipers turned on,

the air conditioning failed,

and finally, the Jeep slowed to a stop on the highway

as the hackers disabled my transmission.

The fallout of our stunt was immediate.

Days after my story was published,

Fiat Chrysler issued the first major cybersecurity recall

in automotive history, recalling 1.4 million vehicles

to patch the vulnerability

that Miller and Valasek had exploited.

What began as a shocking experiment led to car makers

being suddenly forced to think like tech companies,

launching bug bounty programs

that pay independent researchers

for reporting hackable vulnerabilities,

hiring cybersecurity researchers,

and redesigning vehicle systems

to better isolate critical controls

from internet connected features.

These experiments showed that a malicious hacker

could pose a very real safety threat to modern vehicles,

but thankfully, none of those attacks

on cars’ driving systems have ever been seen in the wild.

Why do you think that it is that we’ve never actually

seen those attacks used in practice?

Because people don’t want to hijack cars.

There are easier, cheaper,

and more effective ways to kill somebody.

It’s not a solution to an actual problem that people have.

Where the action is is car theft.

We have made the security in cars strong enough

that there really is no way to steal a car today

without hacking it.

And the reason is, we’ve gotten so good

at protecting our cars,

like your cars now, they have immobilizers,

and so you can go in, you can break the window,

you can try to hotwire.

None of that stuff is going to work anymore.

If you want to steal a car, you have to hack the car today.

In other words, car hacking has continued to evolve

and it’s actually become much simpler.

It shifted from the highly complex attacks

that take over steering and brakes

to far, far easier exploits

that can simply take over cars’ smart features,

sometimes via their connection to a phone,

or even with simple web vulnerabilities.

In just the last few years,

security researchers have found Bluetooth exploits

that can unlock Teslas,

relay attacks that let thieves steal cars

using wireless key fobs,

and security flaws in the phone apps used by Kia,

Subaru, and dozens of other car makers

that expose vehicle controls or even location tracking.

So there is a huge black market of devices,

where you take out the front headlight

and try to plug into the CAN bus and reprogram it.

And so this is part and parcel of how car theft works now.

Devices that will steal the keyless entry signal

from someone’s house, that is where the action is.

So what do you think about Aaron’s team and their research

into this other third party device?

In some ways, it’s even creepier.

It’s definitely creepier.

There is a device that has been added to your car,

unbeknownst to you,

that already does all the things you need to do.

You just need to tell it to do it.

So of all the car hacking techniques

that you’ve seen and witnessed

and even developed yourself in the last decade and a half,

how would you say that this car alarm exploit stacks up?

Like, how does it compare in terms of severity?

As far as severity, I think it’s probably the worst,

and the reason is it affects a large number of vehicles

and the manufacturer of your car can’t fix it,

and you don’t even know you have the problem.

It provides all of the elements that a car thief would want,

but you have none of the advantages we normally have,

in terms of defending it,

because you are disconnected from the supply chain

that put it there.

That means the security vulnerability that UCSD found

puts a huge number of cars at risk of stealthy theft,

as I’ll demonstrate in a moment.

To understand how the team found it,

I spoke with them inside their actual hardware hacking lab.

Can you tell me the story of how you found this device

and how you figured out that it was hackable?

So back in 2019, we were working on a different project.

This was to investigate Bluetooth skimmers

that criminals actually used to steal your credit card info

and plant them at gas stations.

And during that time,

I was doing a lot of Bluetooth device scanning,

and I would keep seeing these Bluetooth devices

with a very particular name

that would show up often at these gas stations.

And then eventually I started seeing them also

in parking lots and parking garages.

I initially thought it was some form of a payment system,

perhaps, but then these would also show up

as we were driving along the freeways.

So I figured it was a particular type of vehicle.

Eventually as I looked further,

we realized that this was not just a type of vehicle,

this was basically any consumer vehicle out there.

So you knew that it was something inside of vehicles

all over the place that you were seeing, even on the road,

but how did you figure out

that it was specifically this KARR car alarm?

As Nishant mentioned, there was a particular device name.

So we took the prefix of that device name,

searched it up on Google, and we actually found a FCC filing

that allowed us to link that device to its manufacturer,

that is KARR.

[Andy] The team then turned their focus to the KARR app,

which allows users

to control their security system via Bluetooth.

So once we reverse engineered their application,

we quickly realized,

after understanding their internal authentication protocol,

that it was so simple that we could actually just extract it

and re-implement it as our own application, which we did.

So basically you took their app,

which is meant to just authenticate and unlock a single car,

and instead, you built an app that can unlock any car.

Every single car that they have ever put this in.

So it was actually more than 18 months ago

that you first told Acrisure Protection Group

about this discovery.

Did they leave this vulnerable all that time?

They’ve been developing a patch

and they did actually give it to us to test.

Do you believe that this problem actually can be fixed?

This is a Bluetooth only device.

It has no cellular modem,

no connectivity online all the time.

That means that it has to be manually patched

on every single one of these alarms

and every single car that has been deployed.

To show just how important it is to install that fix,

I’m going to attempt to steal a car

without setting off the alarm,

smashing a window, [glass breaks]

or jimmying the lock.

In other words, without doing any of the things

that usually make it possible

to catch a car thief in the act.

Our victim is inside the house.

We’ve set up a camera to monitor her

and see whether or not she can hear me

or see any sign I’m stealing her car.

I know that your hacking technique

can unlock the target vehicle.

How do I actually start the car and drive it away?

So there’s actually a tool that car thieves commonly use

that’s originally actually a tool for locksmiths.

What it essentially does

is let them clone the key of the car.

Normally, the car thieves have to connect it inside the car

and to get in there they’re smashing windows.

But with this alarm, when you bypass it,

you can get in the car silently, plug this thing in,

and you’ll be able to steal the car.

Aaron and his team’s theft technique

focuses on allowing a car thief

to silently and instantly get inside a car,

where they can use a fairly standard locksmith tool

to connect to the dashboard and clone the key.

Here we go.

All right, I’m starting the timer now.

[Andy] Normally a thief would need to smash a window

or use some other trick to get the door open,

often setting off the alarm.

With Aaron’s team’s hacking technique, though,

I don’t need to do any of that.

I quietly unlock the car.

The alarm is suppressed and I’m in.

[Aaron] He’s going to now connect the system.

[Andy] That part is easy.

[Aaron] 20 seconds in.

Now I’m going to take the locksmith tool

and make a key for this car.

I’m not going to give you the details

of how this device works.

I don’t want to create a how-to video here,

but the process takes about two minutes,

even when I screw it up the first time.

It didn’t work the first time.

I’ve gotta try again.

It turns out for this model of car,

I have to turn the hazard lights on to make a new key,

but there’s no audible alert to get the victim’s attention.

It’s worth noting here

that if you do spot your car’s hazard lights

turning on unexpectedly in the middle of the night,

it could be a sign that a car thief

is inside cloning the key.

[Aaron] He’s looking around like he might be getting

to the point he’s about to start it.

[Andy] The tool has created a new key fob.

I press it to the ignition button

and the engine comes alive.

Lights are on, that’s a good sign.

Oh, here we go.

And I got it.

There it goes.

Wow, he’s really taking that thing away.

Is he going to bring it back?

[phone rings]

Hi. Hey, how’s it going?

Andy stole your car.

[Andy] I was struck by just how smoothly the process went.

I basically got away without alerting the owner.

Good job,

[Aaron] Andy. How did

that feel, Andy?

That is insane. How did I do?

What was my [indistinct]? It was about

two and a half minutes, a little bit longer than I expected,

but. Not quite

gone in 60 seconds,

but close. You know what?

There’s always some issues, but you nailed it.

Around the time of our car theft demo,

I reached out to Acrisure Protection Group,

the company that sells the car alarm device,

and asked them about the vulnerability in their system.

Like the team at UCSD had told me,

the company said it developed a firmware patch,

which is now available to install if you download the KARR,

that’s K-A-R-R Security smartphone app.

Just tap Customer Service on the home screen

to find the firmware update option.

Acrisure PG also wrote in a statement that,

The vulnerability described in the research

is highly complex and presents a low risk to customers

under real-world conditions.

Nevertheless, we responded promptly

and developed a firmware update to address the issue.

Whether the car alarm vulnerability

represents a quote unquote, low risk of abuse,

I’ll leave to you to decide

based on seeing the demos we just showed you.

As for the company’s claims that it responded

quote unquote promptly, Acrisure Protection Group

actually took well over 18 months to roll out its patch

after UCSD first contacted its security team.

The company also noted it would warn customers

about the patch Through in-app alerts,

dealer communication, and on its website,

but that strategy of contacting affected drivers

also leaves unanswered how Acrisure PG will reach car owners

who aren’t the company’s customers.

That includes car owners

who don’t even know they have its vulnerable device

in their vehicle.

Everyone that has this in their car,

including people that don’t even know they have it,

because they said no to having the system installed,

now needs to run a firmware update

from their phone onto this device

in order to patch this universal key that’s on there.

But the complication here

is that this isn’t like a product somebody bought

that they’re now just being told to install an update on.

It’s something that people actually asked

not to have in their cars.

They don’t even know that it’s there.

How do you reach those people to get them to patch?

Actually, that is one of the reasons

I’m doing this interview right now.

Doing that kind of massive update

is going to require a huge awareness campaign.

I want as much media attention as possible onto this,

because in the end, there is no other way

we can reach the millions of people

than to just make it widely known this is happening

and get them to install that patch on their car.

It’s been more than a decade

since I personally witnessed the problem

of KARR’s digital insecurity

in a very firsthand demonstration.

But now the most imminent automotive cybersecurity threat

may not be elite hackers

taking over your vehicle from miles away

and driving your car off a cliff.

Instead, it’s the invisible ecosystem

of third-party connected hardware

silently embedded in modern vehicles

by manufacturers, dealerships, insurers, and vendors.

That means you need to be aware

of digital threats to your car,

think twice about the security of gadgets you plug into it,

and install security updates and patches.

Modern technology has made cars safer, more convenient,

and more reliable than ever before,

but some of those same upgrades and features

have also created serious security vulnerabilities,

including in at least one device

that plenty of drivers don’t even know is under their hood.

This is Hacklab.

I’m Andy Greenberg.

[upbeat music]



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW