A Device Hidden in Cars Across the US Leaves Them at Risk of Theft and Disability. Patch It Now


Like modern cars it has changed multi-ton computers on wheelsDrivers are beginning to learn that they need to install safety updates in their vehicle codes, as they do phone or laptop. However, even the most tech-savvy car owners can’t expect to have to install a patch for an insecure device that they never installed or requested – and may not even know about – that has been plugged into the most vulnerable parts of their vehicles, leaving them vulnerable to random theft, tracking, and roadside breakdowns.

That’s the confusion of a group of security researchers at UC San Diego, who found that a version of the car alarm later called the KARR Security System, installed in more than 2 million cars in the US by their estimate, can allow any hacker through Bluetooth to send radio signals to unlock the car silently, turn off its alarm, turn off its horn, turn off its horn, or flash. unstable.

KARR alarm devices are usually installed by car dealers, not manufacturers or owners, and are used as a deterrent to car thefts on sales lots. However, when cars are sold, alarms are often not removed, even if the buyer refuses to pay as a separate item. This means that car owners across the US have a hackable device whose code they will need to change to secure their car – but which they often don’t buy and don’t even know exists.

The KARR Security System has been integrated into the complex systems of more than 2 million vehicles according to UCSD…

The KARR Security System is connected to the critical systems of more than 2 million vehicles according to UCSD’s estimate, all of which need the patch to protect them from hacking methods that can track, unlock, and break vehicles.

Photo: Courtesy of David Baillot/University of California San Diego

“This is a system added to cars and dealers, and unfortunately it has a huge risk that allows anyone to access all these cars,” says Aaron Schulman, a professor of computer science at UCSD who led the study. “It was designed to make cars safer, but in the end it created a vulnerability that needs to be quickly patched in millions of cars. We’re trying to get the word out that you should check your car for this device and put it on your hands now.”

The company that sells the KARR Security System, Acrisure Protection Group, today released a firmware update for a vulnerable Bluetooth version of its KARR alarm system to fix a security issue uncovered by UCSD. Owners of vehicles with the KARR Security mobile app installed should receive alerts about firmware updates, the UCSD team says. Those who do not have it will need to download the KARR Security System smartphone app (Android, iOS), connected to their car’s KARR alarm, then click “customer service” and “firmware update.”

Since about half of car owners who have a KARR device have not requested it in their cars, according to UCSD estimates, you can check if your car has the device by looking for the KARR sticker on your car’s driver’s side window – or sometimes a sticker reading, “SWDS” for SouthWest Dealer Services, a small Security panel – connected to a small Security button – connected to a small button. under the dashboard of your car. Car owners in Southern California are the most likely to install the device because of its popularity among car dealers in the region, but UCSD researchers warn that they have found devices installed in cars in the US and other countries.



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *