Flaw in Bluetooth Technology Enables Unapproved Entry to Vehicle Lock Mechanisms and Engine Controls through Alarm Systems

Flaw in Bluetooth Technology Enables Unapproved Entry to Vehicle Lock Mechanisms and Engine Controls through Alarm Systems

Many dealerships provide optional alarm systems as an additional feature when purchasing a vehicle. One company, Karr, offers these systems and leads in this industry, with its technology installed in roughly 2 million cars across the United States. However, not all owners may realize that their vehicle is equipped with a Karr alarm initially, as some dealers install and maintain them irrespective of whether buyers opt to pay for their features.

This presents an issue, as UC San Diego researchers recently found a vulnerability in Karr’s system that may enable malicious individuals to send commands via Bluetooth to unlock car doors, deactivate the ignition, and trigger various other disruptive actions.

Fortunately, in this instance, security specialists have already informed Karr, and the company has released a firmware update to rectify the issue, as reported by Wired. This update can be installed through a mobile app that anyone can download, regardless of whether they are existing paying subscribers. If you happen to fall into the latter group, as I suspect many of us do, you might be curious about how to find out if your vehicle is equipped with Karr technology. It turns out that such cars display stickers stating “Karr” or “SWDS” on their driver-side windows.

According to Karr, this vulnerability shouldn’t be a cause for concern, and the firm plans to collaborate with dealers to inform owners of affected vehicles. “The vulnerability outlined in [UCSD’s] findings is quite complex and poses a minimal risk to customers under actual conditions,” a spokesperson for the company told Wired. “Nonetheless, we acted quickly and created a firmware update to remediate the problem.” (“Quickly,” in this context, carries significant weight, as it reportedly took 18 months for the company to roll out this fix.)

A screenshot from Karr’s website, highlighting the functionalities of its alarm systems. Karr Security Systems

The challenge with this calm reassurance is that researchers do not necessarily share that perspective. One UCSD professor referred to this situation as “possibly the worst” car hacking threat seen so far. These experts also showcased to Wired just how effortlessly a Karr-equipped vehicle without the recent update can be compromised, assuming the hacker possesses the right tools.

Vehicles with Karr alarms aren’t just vulnerable while in operation; the system’s Bluetooth transmitter remains active for 10 minutes after the vehicle has been switched off, extending the opportunity for potential breaches.

The prevalence of Karr’s technology in numerous cars, as opposed to its actual utilization, stems from the practices of some of the over 3,000 dealerships nationwide associated with the company, which implement the systems as a theft prevention strategy. Prior to sale, when cars are on the lot, dealers can use Karr’s technology to monitor their inventory. At the time of sale, dealers may offer buyers the option to pay a regular fee for that security service. However, if customers decline, the alarm may not be removed; they might need to request its removal, and even then, not all dealers will comply without complicating matters.

This scenario is yet another manifestation of contemporary connected car ownership. However, unlike the issues surrounding SignalTrace or Flock that we’ve been discussing recently (and unfortunately experiencing firsthand), this predicament appears to have a straightforward solution: legally require dealerships to uninstall alarms like these from their cars at the time of sale, unless that customer consents and agrees to pay for continued monitoring. The risk of bad actors taking advantage of unnecessary hardware that never needed to be in the vehicle originally is too significant to simply leave it, and the responsible dealerships must realize they are endangering everyone unless they address these situations seriously.

Have a tip? Contact us at [email protected]

With a decade of experience in covering vehicles and consumer technology, Adam Ismail serves as a Senior Editor at The Drive, focused on curating and producing the site’s array of daily articles.


**Security Flaw in Bluetooth Technology Allows Unauthorized Access to Vehicle Locks and Engine Functions via Alarm Systems**

In recent years, the inclusion of Bluetooth technology in automotive systems has transformed vehicle accessibility and connectivity. However, this progress has also unveiled significant vulnerabilities, especially regarding unauthorized access to vehicle locks and engine controls through alarm systems. This article examines the nature of these vulnerabilities, their repercussions, and possible mitigation strategies.

### Grasping Bluetooth Technology in Vehicles

Bluetooth technology facilitates wireless communication between devices, enabling features such as hands-free calling, audio streaming, and remote vehicle control. Many contemporary vehicles feature Bluetooth-enabled alarm systems that allow users to lock and unlock doors, start engines, and keep track of vehicle status remotely.

### The Vulnerability

Recent research and security evaluations have shown that specific Bluetooth configurations within vehicle alarm systems can be manipulated by malicious entities. The vulnerabilities predominantly arise from inadequate encryption protocols, insufficient authentication processes, and the utilization of obsolete Bluetooth versions lacking strong security measures.

1. **Inadequate Encryption**: Several vehicle systems employ outdated or weak encryption methods, making it simpler for attackers to intercept and decipher communications between the vehicle and the paired device.

2. **Insecure Pairing Procedures**: Numerous Bluetooth devices depend on pairing processes that can be bypassed or spoofed. Malicious individuals can exploit these weaknesses to obtain unauthorized access to vehicle systems.

3. **Obsolete Bluetooth Versions**: Vehicles operating on older Bluetooth versions may lack vital security updates, rendering them vulnerable to known exploits.

### Consequences of Unauthorized Access

The potential results of unauthorized access to vehicle locks and engine controls are dire. Attackers can:

– **Unlock Vehicles**: Access vehicles without the owner’s permission, resulting in the theft of personal belongings or the vehicle itself.
– **Start Engines**: Remotely initiate vehicles, enabling theft or unauthorized operation.
– **Disable Security Features**: Manipulate alarm systems, making them ineffective against theft.
– **Access Sensitive Information**: Extract personal details stored within the vehicle’s infotainment system, including contacts and navigation history.

### Case Studies

Multiple incidents have highlighted the dangers associated with Bluetooth vulnerabilities in vehicles. In one significant example, researchers showcased how they could exploit a flaw within a popular vehicle’s Bluetooth system to unlock doors and start the engine using a simple smartphone application. This event emphasized the pressing need for manufacturers to rectify security flaws in their Bluetooth systems.

### Mitigation Strategies

To address these vulnerabilities, both manufacturers and consumers must take proactive actions:

1. **Routine Software Updates**: Vehicle manufacturers should provide regular firmware updates to address security weaknesses and improve Bluetooth security protocols.

2. **Strengthened Encryption**: Implementing more robust encryption standards and secure pairing practices can significantly mitigate the risk of unauthorized access.

3. **Consumer Awareness**: Customers should be educated regarding the dangers associated with Bluetooth technology and encouraged to disable Bluetooth when not in use, as well as to avoid pairing with unfamiliar devices.

4. **Security Evaluations**: Manufacturers ought to conduct regular security reviews and penetration testing to uncover and address vulnerabilities in their systems.

### Conclusion

While Bluetooth technology has significantly enhanced the ease of vehicle access and control, it has also posed considerable security challenges. Unauthorized access to vehicle locks and engine controls via alarm systems presents a serious threat to vehicle owners. By understanding these vulnerabilities and executing effective mitigation strategies, both manufacturers and consumers can collaborate to strengthen the security of automotive Bluetooth systems and safeguard against potential risks.