"1 Button Press Can Hack Millions of Cars —
With the press of a button, millions of cars can be hacked. Professor Aaron Schulman and team discovered a universal vulnerability installed in more than 2,000,000 cars across the US. @WIRED@flipboard.com technology journalist Andy Greenberg exposes the novel hacking technique—including just how easy it is to steal a car—and explains what you need to do to patch a hidden device you may not even know is in your vehicle." /
"A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now — Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars."
TL;DR: ~2 million vehicles across the US affected, independent of car manufacturers, it's bad, needs manual patching via Bluetooth
YouTube video: https://youtu.be/FwA3CuJxbk4
WIRED article: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/ (https://archive.is/EvBjc)
#itSecurity #carHacking #hacking #karr
Remote
0
Followers
0
Following
3
Posts
Joined June 14, 2026
Posts
Open post
Replying to
@troed@swecyb.com
@troed@swecyb.com Thanks for your answer. The main problem is probably that there's no public documentation as it's proprietary. So it's a big guessing game. No debug strings in the firmware so I had started to drive everything bottom up, starting from SPI peripheral accesses of the MCU (which does have some SDK source code but again no public datasheet). I'd like to find how the peripheral on the other side works. Presumably, it's quite complex. Looks like it has some 16 bit registers that can be read and written, triggering some action. I guess that static analysis needs to be combined with dynamic analysis (logic analyzer tracing), trying to build up context/ a model.
0
0
0
0
Open post
Anyone here familiar with reverse engineering communication protocols between ICs? This specific one is based on SPI. The observations deducted from logic analyzer traces do match firmware binary reverse engineering observations. But from here on, it gets tedious. This is probably a skill issue. Disassembly and decompilation done my Ghidra. Also kind of looking for legal advice before I publish details. I am located in Germany.
1
0
6
0
Remote instance
infosec.exchange
Open on original server