Skip to content

Details

Speaker Name: Aaron Shulman

Title: BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft

Bio: Aaron Schulman is an Associate Professor at University of California, San Diego. His research group works on problems that involve gathering large-scale measurements to test whether assumptions about security, and sometimes reliability, match reality. This work often leads his students to gather data on rooftops, at fast food restaurants, gas stations, and hospitals, and while riding in cars, trains, and airplanes. He earned his PhD in Computer Science from University of Maryland, where he studied Internet reliability, and he did a postdoctoral fellowship at Stanford University, where he investigated bottlenecks in cellular infrastructure. Aaron co-discovered sensitive unencrypted data sent over GEO satellites from cellular providers, governments, militaries, and power grid operators. He also co-developed a Bluetooth credit card skimmer detector that federal and state law enforcement have used to stop millions of dollars in credit card fraud. While in Silicon Valley, he co-founded a company that helped Google improve the battery life of the Chrome web browser.

Talk Description: Car dealers predominantly in the Southwestern U.S. have been pre-installing "KARR," an aftermarket anti-theft alarm system, in every car they sell. They offer these systems as an upgrade when you purchase your car, giving you smartphone-based control over your car locks and immobilizer; if you decline the offer, the dealer says they will deactivate the system. What they don't tell you: this security system is authenticated by a global shared key, so anyone who recovers that key can remotely control nearby KARR units with a smartphone.
KARR is installed in an estimated 1.4 million cars, and every vulnerable unit shipped with the same authentication key, allowing an attacker with a smartphone to unlock the doors, disable the alarm and immobilizer, and trigger the horn and lights of any KARR-equipped vehicle. The core impact is unauthorized access, which can enable burglary, OBD-II access, and escalation including the key-programmer workflow we will demonstrate; every owner with KARR installed needs to update, including those who declined the upsell or inherited it used.
We'll walk through how we discovered KARR, how KARR ends up in millions of cars, how the attack works end-to-end, and what owners can do to fix it today. We'll also show that the same recipe revealed vulnerabilities in other aftermarket BLE systems.

Related topics

You may also like