This investigation exposes the disturbing irony where security hardware becomes a universal backdoor due to corporate negligence and a lack of transparency. It is a sobering reminder that the greatest threat to your property is often the very device installed to protect it.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
I Stole a Car By Hacking This Hidden Device
Added:With the press of a button on this homemade Android app, I'm about to hack all of these cars.
In fact, this device inside all of these vehicles makes it [music] disturbingly easy for anyone. Carjack them, paralyze them, trigger chaotic effects like I just [music] did, or even silently steal a car and drive it away. And the wildest part is that this hidden hackable device is installed in millions of cars across America. And about half of those vehicles, the owners have never asked for it and might have no idea it's even in there.
>> There's another one.
>> And there's another one right there.
>> My goodness, they're everywhere. It may well be inside your car right now. I'm Andy Greenberg. I investigate the strange, dark, and subversive sides of technology [music] for Wired. This is Hack Lab, the hidden hackable device that lets me steal your car.
To learn about this new car [music] hacking technique, I traveled to the University of California at San Diego to meet with the security researchers who discovered it, computer science professor Aaron Schulman and his team.
Aaron, so this is the device.
>> This is a car alarm that is installed by dealers into cars that they sell while they're sitting on the parking lot waiting to be sold. In Southern California, for years, there was a big problem with theft from dealer lots.
They install it behind the dashboard.
They've really mounted this thing quite deep inside of your car. They actually cut the ignition wire at the dealer and they spliced this in in the middle in that it allows them to prevent the car from starting when it's sitting on that dealer's lot.
>> I mean, I can see this as a module with a million wires coming off of it. What does it connect into in a car?
>> All the high security systems inside the car that are used for access. So, door locks, lights, trunk, etc. >> So, this is actually a security device, but what is the security issue that you found with it? All of these systems actually have the same universal key built into them. Now, the issue with that is the system can be used by an attacker to also immobilize your car.
And that key is unfortunately on millions of alarms that have been deployed by these dealers, mostly originating in Southern California, but also now have been resold throughout the country.
>> How did it end up in cars on the road and in people's driveways and parking lots around the country? When you're with a dealer and they're trying to negotiate the price, they'll actually say to you, "There's also this alarm system. We already put it in your car.
Do you want to perhaps pay for this as an upgrade?" And then you can have access from your smartphone and you can control your car to unlock, lock, activate the horn from that smartphone app.
>> And then what happens if I say no?
>> You can as the purchaser say, "I do not want this system in my car." They will say, "Okay, fine. will deactivate the system. And once it's deactivated, we already put it in your car with all these wires, it's quite deep in there, but it won't work anymore. Now, unfortunately, what we found in our research is even if the system has been deactivated, it is still operating. And whenever the car is turned on, this actually wakes up and the Bluetooth radio turns on and now you can connect to it as an attacker and remotely control it.
>> Wow, that is so insidious. This thing people didn't ask for. The fact they actively asked not to have it in their car is still in the guts of their vehicle, making it much less secure.
>> That's right.
>> So, how can people find out if they have this device hidden in their car?
>> It's really obvious, actually. Let me show you. Here's the sticker right here.
If you have this sticker that says KR, you likely are vulnerable to this attack.
>> Yeah, that's pretty clear.
>> And if you look down in the bottom here under the dashboard, this little blinking light indicates that you have the system running and you have to get it patched. Last year, the UCSD team warned Acur Protection Group, the company that sells the car alarm device, about the hacking technique they had discovered. The company responded just this week by rolling out a security update. So, if you have car installed on your vehicle, you can now download or update your car app on your phone to patch the device and protect your car.
But there's no automatic software update mechanism. Car owners will need to manually install the fix or their vehicle stays vulnerable.
>> So, this is actually Suman's car. One of our students, he was the first to volunteer to have their car hacked.
>> Did you actually pay for this? Like, do you have it active in your car?
>> No, I did not pay for this, but as it turns out, with just a button click, I can activate it as long as it's parked just a few minutes ago.
>> Or if the car is on and driving, right?
>> Yes.
>> So, can you show us?
>> Sure. So, right now, I'm going to convert it from this deactivated state into an active state.
>> So, that little honk was the only sign you're going to get that your car just became vulnerable.
>> Yes, just the honk. Now I can lock the car. Go ahead. Try to see if you can unlock it. And as it turns out, we can also unlock the car.
>> Mhm.
>> Yep.
>> So now you can honk the horn, for instance. And you can also turn on and off the lights.
>> So as it turns out, we can also immobilize the car. So you can sit in, try to switch on the ignition, and it's not going to work.
>> So why don't you go ahead and start it, make sure it works.
>> Now go ahead.
>> Perfect. So, yeah. Try it again.
>> Is it working, Andy?
>> No, it's not starting.
>> It's not starting.
>> Yeah. Nothing. It says key not found.
>> At this point, you would need to actually tow the car if you want to drive it again because the person that owns it has no idea why their car won't even start anymore.
>> So, you can basically paralyze any car that's in Bluetooth range of your phone.
>> Exactly. That seems like a very serious problem.
Before we demonstrate how this hacking technique works by stealthily stealing a car from the driveway of a private home, I took a ride around La Hoya with Aaron and I, one of the researchers on his team, to get a sense [music] of just how many cars had this secret vulnerability.
>> We're scanning nearby signals that car alarms emit. This is the counter mode of my app where here are all the serial numbers of car alarms nearby. So far, we've seen eight of those. Oh, there's nine. There's another one. 11.
>> Wow. Two more. Oh my goodness. They're everywhere. [clears throat] There's 16.
>> Most dealers, they're all operating this car system. So, essentially, almost any of those cars that we see in Southern California is going to have a car alarm in it. Based on some experiments we've done in looking at data across the country, we see that these alarms show up in every city in the United States.
>> Let's see how many we count in this garage. The number is going up very quickly. We're already at 20. What we're counting here are active car alarm systems.
>> It's most likely to be active at once because deactive alarms, they stop beaconing after they parked for a while.
>> We're 27 now.
>> Yeah, we're 27. I just see two window stickers there.
>> Just as you drove by, you could immobilize every vulnerable car in the whole parking garage.
>> Yeah, that's right. We are at 37.
>> Vulnerable cars were everywhere, all giving off the same telltale Bluetooth prefix. Aaron's team estimates that more than two million cars nationwide have the car system installed. They got that number by studying data from Wiggle, a crowdsourced app where users known as Wiglers compete to log Wi-Fi and Bluetooth signals they pick up with radio antenna. Erin's team then used the serial numbers of the devices in Wiggle with the car signature to extrapolate how many of these systems may be out there. But Wiggle also collects location data tied to all those radio signals too, right?
>> Yes. And so does that mean that you can track someone's location based on these car alarm radio signals also?
>> Oh yes, totally. Now the problem with that is if you get that data, the serial number does not change. So you could track where someone lives, where someone works.
>> Somebody wouldn't even need to follow you back to your home or to where you park the car. They could just find that same radio signature on Wiggle. As part of our research, we investigated in the Wiggle database how many cars were actually targetable and we noticed that there are quite a lot of cars where we see them stationary and that means likely they will be seen again and again at the same location. It could be the case that someone could use those public databases to target individuals that have that vulnerable vehicle.
>> I mean, this is all very creepy and scary. We're now in a pretty crowded parking lot. Let's see how much the count goes up.
>> It already goes up to 67.
>> There's another one right there.
>> Now we're up to 74.
>> In any parking lot in San Diego, you're going to see dozens and dozens of these things.
>> 88 89.
>> Oh, we have 90 right now.
>> I just want to note that we only drove around here for about 20 minutes. We stayed right next to the university's campus. We almost saw 100 cars that are vulnerable. That is an insane amount of cars. When you install something by default at a dealer in every car that is sold, the pervasiveness of that vulnerability is going to be unimaginable.
>> Finding vulnerable cars is easy. [music] And what could someone do with the power to unlock a car at will? One disturbing possibility is [music] carjacking. Once a criminal has identified a target vehicle, they could simply unlock it while someone is driving and exposed.
For demonstration purposes, a UCSD employee has volunteered to pose as our victim.
>> All right, so let's say we want to target this vulnerable car up here. All I have to do is we pull up behind it.
I'm going to activate.
You heard the beep. It's active. This is a particularly scary idea of unlocked because a carjacker could remotely unlock the door at a stoplight, then drag the occupant from the front seat or steal [music] something from inside the car. As real as that carjacking threat may be, it's not at all stealthy. But if we wanted to actually steal a car [music] without confronting the owner, all we would have to do is follow the driver home or wherever they park or find those locations in the Wiggle database and wait for a quiet moment to make our move. In just a few minutes, we'll show you how easy and stealthy stealing [music] that car can be. So easy that even I with no experience using Aaron's technique could probably do it in under [music] 2 minutes. But before we attempt hacking enabled Grand Theft Auto, let me give you some quick historical context on this technique [music] and how we got here. For over a decade, I've covered the evolution of hacking techniques that affect modern connected vehicles [music] with digital features. That story actually begins here at the University of California, San Diego. So, while I was on campus, I met with Stefan Savage, who co-led the team at UCSD that was the first to ever hack a car's steering and brakes.
>> Back in 2008, we didn't know what we were doing, and cars were really complicated, and we had to reverse engineer how they work. The big one was we reverse engineered at the time how the OnStar cellular signal worked. And so 1500 miles away, we could take over your car, unlock it, lock it, turn off the engine, we could make it skid on the brakes.
>> That experiment, which UCSD carried out with the University of Washington, was the first time that cars were proven to be hackable. But then in the summer of 2015, security researchers Charlie Miller and Chris Valisk, carried out an even more dramatic demonstration that changed the auto industry [music] forever with me behind the wheel as their crash test dummy.
>> Okay, hold on tight. Hold on.
Miller and Valisc told me to drive a Jeep Cherokee onto a highway in Missouri. Then the two hackers remotely took control of the vehicle from miles away through its internet connected UK Connectnect infotainment system. First, the radio blasted [music] music, then the windshield wipers turned on, the air conditioning failed, and finally the Jeep slowed to a stop on the highway as the hackers disabled my transmission.
The fallout of our stunt was [music] immediate. Days after my story was published, Fiat Chrysler issued the first major cyber security recall in automotive history, recalling [music] 1.4 million vehicles to patch the vulnerability that Miller and Valisc had exploited. What began as a shocking experiment led to car makers being suddenly forced to think like tech companies, launching bug bounty programs that pay independent [music] researchers for reporting hackable vulnerabilities, hiring cyber security researchers, and redesigning vehicle [music] systems to better isolate critical controls from internet connected features. These experiments showed that a malicious hacker could pose a very real safety threat to modern vehicles. But thankfully, none of those attacks on cars driving systems have ever been seen in the [music] wild. Why do you think that it is that we've never actually seen those attacks used in practice?
Because people don't want to hijack cars. There are easier, cheaper, and more effective ways to kill somebody.
It's not a solution to an actual problem that people have. Where the action is is car theft. We have made the security in cars strong enough that there really is no way to steal a car today without hacking it. And the reason is we've gotten so good at protecting our cars.
Like your cars now, they have immobilizers. And so you can go in, you can break the window, you can try to hotwire. None of that stuff is going to work anymore. If you want to steal a car, you have to hack the car today.
>> In other words, car hacking has continued to evolve and it's actually become much simpler.
>> [music] >> It's shifted from the highly complex attacks that take over steering and brakes to far far easier exploits [music] that can simply take over cars smart features sometimes via their connection to a phone or even with simple web vulnerabilities. In just the last few years, security researchers have found Bluetooth exploits that can unlock Teslas, relay attacks that let thieves steal cars using wireless key fobs, and security flaws in the phone apps used by Kia, Subaru, and dozens of other car makers that expose vehicle controls or even location tracking. So there is a huge black market of devices where you take out the front headlight and try to plug into the canvas and reprogram it. And so this is part and parcel of how car theft works now.
Devices that will steal the keyless entry signal from someone's house. That is where the action is.
>> So what do you think about Aaron's team and their research into this other third party device? In some ways it's even creepier.
>> It's definitely creepier. There is a device that has been added to your car, unbeknownst to you, that already does all the things you need to do. You just need to tell it to do it.
>> So, of all the car hacking techniques that you've seen and witnessed and even developed yourself in the last decade and a half, how would you say that this car alarm exploit stacks up? Like, how does it compare in terms of severity?
>> As far as severity, I think it's probably the worst. And the reason is it affects a large number of vehicles and the manufacturer of your car can't fix it and you don't even know you have the problem. It provides all of the elements that a car thief would want, but you have none of the advantages we normally have in terms of defending it because you're disconnected from the supply chain that put it there.
>> That means the security vulnerability that UCSD found puts a huge number of cars at risk of stealthy theft, as I'll demonstrate in a moment. To understand how the team found it, I spoke with them inside their actual hardware hacking lab.
>> Can you tell me the story of how you found this device and how you figured out that it was hackable? So back in 2019, we were working on a different project. This was to investigate Bluetooth skimmers that criminals actually use to steal your credit card info and plant them at gas stations. And during that time, I was doing a lot of Bluetooth device scanning. And I would keep seeing these Bluetooth devices with a very particular name that would show up often at these gas stations. And then eventually I started seeing them also in parking lots and parking garages. I initially thought it was some form of a payment system perhaps, but then these would also show up as we were driving along the freeways. So I figured it was a particular type of vehicle. Eventually as I looked further, we realized that this was not just a type of vehicle.
This was basically any consumer vehicle out there.
>> So you knew that it was something inside of vehicles all over the place that you were seeing even on the road. But how did you figure out that it was specifically this KR car alarm? As Michelle mentioned, there was a particular device name. So, we took the prefix of that device name, searched it up on Google, and we actually found a FCC filing that allowed us to link that device to its manufacturer that is car.
>> The team then turned their focus to the car app, which allows users to control their security system via Bluetooth.
>> So, once we reverse engineered their application, we quickly realized after understanding their internal [music] authentication protocol that it was so simple that we could actually just extract it and reimplement it as our own application, [music] which we did. So basically you took their app which is meant to just authenticate and unlock a single car and instead you built an app that can unlock any car >> every single car that they have ever put this in.
>> So it was actually more than 18 months ago that [music] you first told aure protection group about this discovery.
Did they leave this vulnerable all that time?
>> They've been developing a patch and they did actually give it to us to test.
>> Do you believe [music] that this problem actually can be fixed?
>> This is a Bluetooth only device. It has no cellular modem, no connectivity online all the time. That means that it has to be manually patched on every single one of these alarms in every single car that has been deployed.
To show just how important it is to install that fix, I'm going to attempt to steal a car without setting off the alarm, smashing a window, or jimmying the lock. In other words, without doing any of the things that usually make it possible to catch a car thief in the act. Our victim is inside the house.
We've set up a camera to monitor her and see whether or not she can hear me or see any sign I'm stealing her car. I know that your hacking technique can unlock the target vehicle. How do I actually start the car and drive it away?
>> So, there's actually a tool that car thieves commonly used that's originally actually a tool for locksmiths. What it essentially does is let them clone the key of the car. Normally, the car thieves have to connect it inside the car and to get in there. They're smashing windows. But with this alarm, when you bypass it, you can get in the car silently, plug this thing in, and you'll be able to steal the car.
>> Eron and his team's theft [music] technique focuses on allowing a car thief to silently and instantly get inside a car where they can use a fairly standard locksmith tool to connect to the dashboard and clone the key.
>> Here we go.
>> All right, I'm starting the timer now.
>> Normally, a thief would need to smash [music] a window or use some other trick to get the door open, often setting off the alarm. With Aaron's team's hacking technique, [music] though, I don't need to do any of that. I quietly unlock the car. The alarm is suppressed and I'm in.
>> He's going to now connect the system.
>> That part is easy. [music] >> 20 seconds in.
>> Now, I'm going to take the locksmith tool and make a key for this car. I'm not going to give you the details of how this device works. I don't want to create a how-to [music] video here. But the process takes about 2 minutes, even when I screw it up the first time.
>> Didn't work the first time. Got to try again.
>> It turns out for this model of car, I have [music] to turn the hazard lights on to make a new key. But there's no audible alert to get the victim's attention. It's worth noting here that if you do spot your car's [music] hazard lights turning on unexpectedly in the middle of the night, it could be a sign that a car thief is inside cloning the key.
>> He's looking around like he might be getting to the [music] point he's about to start it.
>> The tool has created a new key fob. I press it to the ignition button and the engine comes alive.
>> Lights are on. That's a good sign.
>> Oh, here we go. And I got it.
There it goes.
Wow, he's really taking that thing [laughter] away. Is he going to bring it back?
>> Hi.
>> Hey, how's it going? Andy stole your car. [music] >> I was struck by just how smoothly the process wins. I basically got away without alerting the owner.
>> Good job.
>> How did that feel, Andy? That is >> What was my >> It was about 2 and 1/2 minutes. A little bit longer than I expected, but >> not quite gone in 60 seconds, but [laughter] >> you know what? There's always some issues, but you nailed it.
>> Around the time of our car theft demo, I reached out to Acraure Protection Group, the company that sells the car alarm device, and asked them about the vulnerability in their system. Like the team at UCSD had told me, the company said it developed a firmware patch, which is now available to install if you download the car. That's K A R security smartphone app. Just tap customer service on the home screen to find the firmware update option. Acer PG also wrote in a statement that the vulnerability described in the research is highly complex and presents a low risk to customers under real [music] world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue.
Whether the car alarm vulnerability represents a quote unquote low risk of abuse, [music] I'll leave to you to decide based on seeing the demos we just showed you. As for the company's claims that it responded quote unquote promptly, aure protection group actually took well over 18 months to roll out its patch after [music] UCSD first contacted its security team. The company also noted it would warn customers about the patch through [music] inapp alerts, dealer communications, and on its website. But that strategy of contacting affected [music] drivers also leaves unanswered how Acer PG will reach car owners who aren't the company's customers. That includes car owners who don't even know they have its vulnerable device in their vehicle. Everyone that has this in their car, including people that don't even know they have it because they said no to having the system installed, now needs to run a firmware update from their phone onto this device in order to patch this universal key that's on there.
>> But the complication here is that this isn't like a product somebody bought that they're now just being told to install an update on. It's something that people actually asked not to have in their cars. They don't even know that it's there. How do you reach those people to get them [music] to patch?
Actually, that is one of the reasons I'm doing this interview right now. Doing that kind of massive update is going to require a huge awareness campaign. I want as much media attention as possible onto this because in the end, there is no other way we can reach the millions of people than to just make it widely known this is happening and get them to install that patch on their car.
>> It's been more than a decade since I personally witnessed the problem of cars digital insecurity in a very [music] firstirhand demonstration. But now, the most imminent automotive cyber security threat may not be elite hackers taking over your vehicle from miles away and driving your car off a cliff. Instead, it's [music] the invisible ecosystem of third-party connected hardware silently embedded in modern vehicles [music] by manufacturers, dealerships, insurers, and vendors. That means you need to be aware of digital threats to your car, think twice about the security of gadgets you plug [music] into it, and install security updates and patches.
Modern technology has made cars safer, [music] more convenient, and more reliable than ever before. But some of those same upgrades and features have also created serious security vulnerabilities, including in at least one device that plenty of drivers don't even know is under their hood. This is Hacklab. [music] I'm Andy Greenberg.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

One Must Imagine Sisyphus Happy
vlogbrothers
61K views•2026-07-21

Future of Taylor Farms
maighstirtarot5385
11K views•2026-07-21

The Downfall of OnePlus!
techwiser
65K views•2026-07-21

My Friend Locked Up The Engine On His K-Swapped Bug...
boostedboiz
128K views•2026-07-21