1 Button Press Can Hack Millions of Cars
WIRED Investigations
K-A-R-R car alarm: hidden universal key in millions of cars
Andy Greenberg (Wired) summarizes security research from UCSD (Aaron Schulman, Stefan Savage, Abel and team) showing a dealer‑installed Bluetooth alarm identified as 'K-A-R-R' is widely deployed and contains a universal authentication key that attackers can reuse. The module is often spliced deep into the vehicle (ignition wire), sometimes installed even when buyers decline it; a dashboard sticker reading 'K-A-R-R' and a blinking light under the dash are visible indicators.
UCSD reverse‑engineered the alarm's Bluetooth protocol, reimplemented the app and demonstrated that a device that owners thought was 'deactivated' still wakes when the car is turned on, enabling remote control: honk, lock/unlock, lights, and complete immobilization ('key not found') while the owner is present. Using Wiggle crowd‑sourced radio logs, the team extrapolated that 'more than two million cars' nationwide carry the system. Because the alarm's serial number is static, Wiggle data (and similar logs) can be used to track stationary vehicles and map where a car lives or works.
Greenberg demonstrates attack chains: (1) remote activation to unlock a stopped or parked car (enabling 'car‑jacking'), and (2) stealth theft by reactivating the alarm, entering quietly, using a common locksmith cloning tool to produce a working key fob and drive away — a process he completed in roughly two minutes in the demo. Historical context: UCSD's 2008 research and the 2015 Charlie Miller/Chris Valasek Uconnect Jeep Cherokee hack (which prompted a 1.4 million vehicle Fiat Chrysler recall) shifted automakers toward security, but third‑party modules like this evade those protections.
The vendor appears in the transcript as 'AcroShirt Protection Group', 'Aperture Protection Group', and 'Acresure Protection Group'; UCSD reported the bug to the vendor over '18 months' ago. The vendor issued a firmware patch this week; owners must manually install it via the 'K-A-R-R security smartphone app' (tap Customer Service → firmware update). There is no automatic remote update mechanism, so Greenberg urges a broad awareness campaign to reach people who never opted into the device and may not know it is in their cars.
Takeaway: check for a 'K-A-R-R' sticker and blinking dash LED, install the K-A-R-R firmware update from the app, and be aware that third‑party connected hardware can introduce large, stealthy risks even when OEM vehicle security is strong.
