Mach-Lee
Well-Known Member
- First Name
- Lee
- Joined
- Jul 16, 2021
- Threads
- 264
- Messages
- 11,484
- Reaction score
- 25,415
- Location
- Wisconsin
- Vehicles
- 2022 Mach-E Premium AWD
- Occupation
- Sci/Eng
WIRED has published a video showing the hack in action. They were able to silently unlock and steal someone's car in under 5 minutes. Even if you keep your keys in Faraday pouches, your car is vulnerable if it has this KARR system. The researchers drove around a parking garage and found almost 100 vulnerable vehicles in under 20 minutes. They could wirelessly unlock every single one if they wanted to. That would be a smash-and-grab thief's paradise.
In terms of magnitude, this is comparable to the Jeep hack a decade ago that caused automakers to completely overhaul their approach to securing vehicle digital networks. All those affected Jeeps were recalled, and the affected owners were automatically mailed a USB flash drive to patch their car. However, the difference here is that there is no comprehensive record of who has these KARR devices in their vehicles. If the owner declined to pay for it when buying their car, they may have been told it was removed or deactivated, when in fact it lies idle, still connected to wiring and ready to take commands from a hacker. Many owners will have no idea this thing is in their car making it vulnerable. It's only a matter of time before the hack becomes widespread with thieves to unlock cars.
Again, everyone should check if they have one of these devices in all of their vehicles (affects ALL brands). Look for the pushbutton near the pedals like the photo in my previous post, or a blinking light under the dash. You could also search for them using a BLE scanner app on your phone; I believe they start with a QT prefix. If you have one, update the firmware with the app or remove it completely.
Sponsored