Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

Your dealer's 'anti-theft' upsell turned out to be a skeleton key for 2.2 million cars

Your Dealer's 'Anti-Theft' Upsell Turned Out to Be a Skeleton Key for 2.2 Million Cars
Your Dealer's 'Anti-Theft' Upsell Turned Out to Be a Skeleton Key for 2.2 Million Cars

Somewhere in Southern California, a Honda, Toyota, Mazda, Ford, or Jeep dealership sold you a box bolted under your dashboard and called it protection. It came with a sticker for your window, a smartphone app, and a straight-faced pitch about stopping thieves. Nobody in that finance office mentioned that the box uses the exact same digital key as every other one of the roughly 2.2 million units installed since 2017. That's the real finding...

Somewhere in Southern California, a Honda, Toyota, Mazda, Ford, or Jeep dealership sold you a box bolted under your dashboard and called it protection. It came with a sticker for your window, a smartphone app, and a straight-faced pitch about stopping thieves. Nobody in that finance office mentioned that the box uses the exact same digital key as every other one of the roughly 2.2 million units installed since 2017.

That's the real finding buried inside a new University of California San Diego study published this week: the dealer-installed security systems marketed under names like KARR and SWDS don't each get their own unique credentials. They share one. Crack it once, as UC San Diego researchers did, and you have functional access to lock, unlock, honk, flash, and immobilize millions of cars parked anywhere from Los Angeles to Osaka.

Here's the part that should bother anyone who ever sat through an intro cryptography lecture. Good security design assigns every device its own private key, so breaking into one unit never breaks into the rest. These systems skipped that step entirely. It's the digital equivalent of a locksmith deciding every deadbolt he installs nationwide opens with the same key, then stamping "anti-theft" on the box anyway.

Some automakers already treat this kind of testing as standard practice. Porsche runs a bug bounty program that pays outside researchers to break its systems before criminals do. Whoever engineered the KARR and SWDS hardware either skipped that step or ignored what it would have found.

The device itself talks to a phone app over Bluetooth, and dealers pitch it as both a theft deterrent and a convenience feature: lock the doors, kill the engine, track the car, all from a phone. It's the same appetite for remote immobilization technology that shows up in Ford's new kill switch hardware, minus the manufacturer's engineering scrutiny and plus, apparently, one shared password for the entire installed base.

Now here's the detail that should make owners angry rather than just uneasy. Buyers who declined the "anti-theft" upgrade at the dealership still drove off with an active, vulnerable device wired into their car. Saying no in the finance office didn't disconnect anything. It just meant they didn't pay for the privilege of being exposed.

An attacker doesn't need to touch the car, or even get particularly close. From roughly five yards away, over Bluetooth, someone holding the cracked key can unlock the doors and disable the engine immobilizer, then use ordinary locksmith tools to start the car and drive off. No broken glass, no forced entry, nothing for a dash cam to catch. Compare that to the $1.3 million supercar theft ring Ventura County prosecutors broke up this month, which needed cloned key fobs and physical proximity to the target vehicle. This method is simpler and works from farther away.

Removing the device isn't a realistic option for most owners. It's spliced into the wiring beneath the dashboard and tied into the ignition system, and pulling it out means cutting and reconnecting harnesses most owners have no business touching. The manufacturer, Acrisure, shipped a firmware patch this week, but it only works if the owner downloads an app that most people don't know they need. A separate company making similar hardware, Rockledge, has a comparable weakness and, according to the researchers, hasn't even responded to their disclosure yet.

This is where the story stops being about one sloppy security chip and turns into a regulatory blind spot. When an automaker builds a defective part, NHTSA can force a recall and make the manufacturer notify every owner directly. We just watched that logic play out when Winnebago and Grand Design both recalled the same fire-prone fan even though neither company actually built it. Dealer-installed aftermarket add-ons live in a grayer zone than that. The researchers looped in NHTSA anyway, but the actual remedy here is a voluntary app update from a vendor, not a mandated recall with owner letters. Nobody is required to track down every affected driver and tell them their car has this box installed.

And plenty of owners won't know. The sticker that flags a vulnerable car fades, peels, or disappears at a car wash years before the vehicle changes hands on the used market. It's a familiar shape for anyone who followed the CarGurus breach earlier this year: the damage rarely stays contained to the original owner or the original transaction.

Buyers rarely know these boxes exist. Sellers rarely disclose them. Thieves, it turns out, knew before almost anyone else.

There's a quieter finding in the study worth sitting with. The same public databases that let a dealership track its lot inventory also store location data for vehicles carrying these devices, which means the vulnerability isn't only about unlocking a door. It's about knowing exactly where a specific car is parked before anyone ever walks up to it.

UC San Diego professor Aaron Schulman, one of the study's senior authors, put it plainly: "Many car owners don't even know that their vehicle is vulnerable." That's not a caveat. That's the sentence the dealership never wanted printed on a sticker.

If you bought a Honda, Toyota, Mazda, Ford, or Jeep in Southern California anytime in the last nine years, check the driver's side window and the underside of your dashboard for a KARR or SWDS badge, then update the app before doing anything else. But the bigger lesson has nothing to do with one vendor's bad cryptography. Dealerships have spent decades selling add-on boxes nobody asked for, from VIN etching to fabric guard to nitrogen in the tires, with no outside party ever auditing whether any of them actually work. This time the audit came from a university lab instead of the dealership's own quality control. It found that the anti-theft device was the theft risk.

Join our Newsletter, follow our Instagram page, and connect with us on Facebook.

Read full story on The Auto Wire

Related News

More stories you might be interested in.

Honda's rear windows keep shattering for no reason. Honda found a legal word that isn't 'recall.'
The Auto Wire·7 hours ago

Honda's rear windows keep shattering for no reason. Honda found a legal word that isn't 'recall.'

Somewhere in Montreal last January, in the kind of cold that turns steering wheels into ice cubes, a man closed the tailgate of his 2019 Acura RDX. Not hard. Just closed it. And the rear window came apart — not cracked, not chipped, but reduced instantly to a pile of pebbled glass, with a bang owners keep comparing to a gunshot. Garage Deals: Nowell Leather’s Hand-Stitched EDC Gear Belongs in Every Gearhead’s Glovebox That moment is now Exhibit...

America's Car-Mart buried a footnote about bad loans. A third of its dealerships just paid for it.
The Auto Wire·8 hours ago

America's Car-Mart buried a footnote about bad loans. A third of its dealerships just paid for it.

Sometime around April 14 of this year, America's Car-Mart shut the lights off at 42 of its 136 dealerships. Not because the cars stopped selling. Not because a storm rolled through the South-Central United States, where nearly all of its lots sit. The company's own SEC filing gives a much less dramatic reason: it couldn't line up a specific kind of loan for itself. Car-Mart, a used-car chain built almost entirely around lending money to buyers...

One faulty chip can shut down almost every new Land Rover on the road — and there's still no fix
The Auto Wire·9 hours ago

One faulty chip can shut down almost every new Land Rover on the road — and there's still no fix

Forget the part number for a second. The real story buried inside Jaguar Land Rover's newest recall isn't a bad component. It's a business decision made years ago, and it's now playing out exactly the way any powertrain engineer could have predicted: when you build an entire brand's electrical architecture around one shared system, a single flawed microchip doesn't just cause a recall. It causes a fleet-wide reckoning. Garage Deals: Nowell...

The US banned Chinese connected-car tech. The company racing to replace it started with a Chinese license
The Auto Wire·10 hours ago

The US banned Chinese connected-car tech. The company racing to replace it started with a Chinese license

Forget the model years for a second. The number that actually matters in America's ban on Chinese connected-car technology isn't 2027 or 2030. It's 1,000. Garage Deals: Nowell Leather’s Hand-Stitched EDC Gear Belongs in Every Gearhead’s Glovebox That's how many employees a small Ohio electronics maker called Eagle Wireless expects to have within three years, up from 140 today. Eagle builds the circuit boards that let a modern car talk to the...

DHS Secretary Markwayne Mullin threatens 'prison time' for state officials who refuse to cooperate with the Trump admin on the midterm elections
Wonderwall·19 hours ago

DHS Secretary Markwayne Mullin threatens 'prison time' for state officials who refuse to cooperate with the Trump admin on the midterm elections

Homeland Security Secretary Markwayne Mullin warned that state election officials who refuse to comply with the Trump administration’s proposed election security requirements could face steep penalties, including possible prison time. The SAVE America Act Markwayne Mullin said states must adopt new election security requirements for federal funding. By: MEGA Speaking at a press conference, Mullin...

A Senate committee just unanimously advanced a bill that could ban new Mercedes-Benz vehicles from America in 2027
BackfireNews·16 hours ago

A Senate committee just unanimously advanced a bill that could ban new Mercedes-Benz vehicles from America in 2027

Mercedes-Benz Group AG has a shareholder problem that has nothing to do with sales figures or software glitches. Two of its largest investors are Chinese, their combined stake sits just under 20 percent, and the U.S. Senate is now advancing legislation that treats anything above 15 percent Chinese ownership in a vehicle manufacturer as a national security threat. On July 22, 2026, the Senate Commerce, Science, and Transportation Committee marked...

Top