The Security Arms Race
Anti-theft devices such as engine immobilizers have helped curb car theft, with Ford even offering a more advanced remote start-blocking feature called Start Inhibit. But despite these efforts, vehicle theft is far from eliminated, especially as thieves continue finding new and smarter ways to break in.
In an ironic twist, a new study from the University of California San Diego found that at least 2.2 million vehicles could be more vulnerable to theft because of a dealer-installed anti-theft device. Researchers found that an attacker within Bluetooth range could connect to affected devices and unlock the doors. Owners may be able to identify one by looking for the words “KARR” or “SWDS” on the driver’s-side window.
Ford
The Key to the Problem
All KARR-SWDS devices reportedly rely on the same authentication key, explaining why millions of vehicles are affected. Most were installed by dealerships in Southern California, but owners elsewhere should also take notice, as affected vehicles have been resold across the U.S., Canada, and even Japan.
Most of the affected vehicles were bought from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 onward. Researchers have avoided fully disclosing how they conducted the attacks to prevent thieves from replicating them.
Acrisure, the company behind the KARR-SWDS devices, released a firmware update addressing the vulnerability on July 20. Owners must install the update through the KARR app. Similar devices made by Rockledge may also be vulnerable, although they are reportedly harder to attack. Researchers could not validate those findings because Rockledge had not responded to their disclosure.
Check Before It’s Too Late
Dealers typically install these devices to manage inventory and prevent theft before marketing them to customers as paid upgrades with smartphone connectivity. Even when a buyer declines the upgrade, the device may remain active and vulnerable. Owners are therefore advised to check their vehicles for “KARR” or “SWDS” branding and install the update to reduce the risk of theft. Connected-vehicle technology has also faced legal scrutiny, with a separate proposed class action alleging that Toyota collected and shared drivers’ data without their consent.
This does not mean such devices are inherently flawed. They can still provide benefits such as real-time security alerts, GPS-based theft recovery, and smartphone controls. However, the study shows that manufacturers may need stronger security measures to prevent attackers from exploiting these features.
The researchers will share more details at DEF CON in Las Vegas on August 9 and the USENIX Security Symposium in Baltimore, Maryland, on August 12.
Honda
