🟠 High  |  Source: The Register — Security


Researchers at UC San Diego have discovered that KARR/SWDS aftermarket vehicle security systems, installed by dealers across California, all share a single hardcoded cryptographic key. This means an attacker within Bluetooth range can authenticate to any affected vehicle and potentially unlock, track, or remotely start millions of cars. The scale of deployment makes this a widespread physical security risk affecting everyday consumers.

Security Architect’s Take: While this is not a direct cloud infrastructure issue, it is a sharp reminder of the risks of hardcoded shared secrets and the importance of per-device unique key provisioning in any IoT or embedded system your organisation procures or oversees. If your fleet management or connected vehicle strategy involves aftermarket telematics devices, audit vendor key management practices immediately and enforce unique credential requirements in procurement contracts.

Original advisory: Millions of California-bought cars can be hijacked via Bluetooth