Slashdot Mirror


'Smart' Car Alarm App Could Allow 3 Million Cars To Be Unlocked Remotely (cnet.com)

"Two popular smart alarm systems for cars had major security flaws that allowed potential hackers to track the vehicles, unlock their doors and, in some cases, cut off the engine," reports CNET: The vulnerabilities could be exploited with two simple steps, security researchers from Pen Test Partners, who discovered the flaw, said Friday. The problems were found in alarm systems made by Viper [known as Clifford in the U.K.] and Pandora Car Alarm System, two of the largest smart car alarm makers in the world. The two brands have as many as 3 million customers between them and make high-end devices that can cost thousands...

Both apps' API didn't properly authenticate for update requests, including requests to change the password or email address. Ken Munro, founder of Pen Test Partners, said that all his team needed to do was send the request to a specific host URL and they were able to change an account's password and email address without notifying the victim that anything happened. Once they had access to the account, the researchers had full control of the smart car alarm. This allowed them to learn where a car was and unlock it. You don't have to be near the car to do this, and the accounts can be taken over remotely, Munro said. Potential attackers could also use the apps' API to target specific types of cars, the security researcher added...

Pandora's alarm system also contained a microphone that would've allowed potential hackers to listen in on live audio, the security company found.

Both companies fixed the issue in less than a week, CNET reports, possibly due to the seriousness of the issue. In a video demonstrating the severity of the bug, security researcher Munro even uses the driver's app to set off a car's alarms remotely. When that driver began pulling over, Munro then used the app to cut off the car's engine. "So simple, so serious," he said.

ZDNet notes that one of the companies had been advertising their "smart" alarms as "unhackable".

27 comments

  1. Lol by Anonymous Coward · · Score: 0

    Must be some RUSSIANS!

    captcha: shiver

    1. Re: Lol by Anonymous Coward · · Score: 0

      I likk yerr tow cheez

  2. Holy shit they got website whips now? ( by Anonymous Coward · · Score: 0

    "Pandora went so far as to say that its smart alarm systems were "unhackable." (This claim has since been whipped off the vendor's website.)" - WHIPPED off the website? Wow, harsh?

    1. Re:Holy shit they got website whips now? ( by AmiMoJo · · Score: 4, Insightful

      Unhackable = "We don't understand security"

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    2. Re:Holy shit they got website whips now? ( by Anonymous Coward · · Score: 0

      Quite the CNET claim, no? One undone by a single URL string sent to a hardly-obfuscated address, changing account parameters without notice or even a 1st authorization attempt, no less. Poor Ziff-Davis, throwing themselves on grenades...

      "COMPLETELY UNHACKABLE, just come around back to the data stream and wash your feet in it."

    3. Re: Holy shit they got website whips now? ( by Anonymous Coward · · Score: 0

      When I heard "Whip", I thought they were talking about the cars.

      "Check out my new whip, ese!"

    4. Re:Holy shit they got website whips now? ( by Anonymous Coward · · Score: 0

      Unhackable = "We authorize you to use our service in any and every possible way since they are all authorized ways of using the service. Any response we send you will be an authorized, legal response. It is not possible for us to charge you with hacking since our system is immune from hacking."

      You hack them. They sue you. You sue them for false advertising.

  3. Hey Ivan... by Anonymous Coward · · Score: 0

    Is your car running? Then you better go to prison! A-Hahahahaa, oooh, Trump treason joke. You'll get it soon enough. (seriously.)

  4. Sure seems "smart" by Anonymous Coward · · Score: 0

    "President" Trump level smart. "Vladimir Putin is my friend, why not just let him touch my penis on TV like that? What's the worst that could happen?" - There's an app for that, unfortunately it only runs on ADX Florence hardware.

    1. Re: Sure seems "smart" by Anonymous Coward · · Score: 0

      Can you unlock all the cars at once and have the doors open and close an the horn beep etc etc etc. kind of like when all the cell doors open in an emergency at ADX Florence?

    2. Re: Sure seems "smart" by Anonymous Coward · · Score: 0

      " kind of like when all the cell doors open in an emergency at ADX Florence? " I haven't played a ton of Prison Architect, but I'm pretty sure they don't do that...

    3. Re: Sure seems "smart" by Anonymous Coward · · Score: 0

      I doubt it

      You have the worst of the worst in ADX Florence, many in solitary cells which are double doored and made soundproof to keep inmates from communicating with each other, and designed in a way where the prisoners don't even know where in the building they are at. If the C.O. "pushed the button", and opened all of the doors, you would have an instant blood bath with inmates and C.O.s decapitated by the dosen.

      (Hopefully), they don't have such a release mechanism, and if they ever had an emergency where part of the prison needs to be evacuated, they would send in a massive platoon of heavily armored and armed CERT members, and shackle the inmates in full restraints before carting anybody out of there.

  5. Security means fewer features by Anonymous Coward · · Score: 0

    Keep it simple. Security is difficult. You don't add security features. If you show people all the things they can do with your security app, you're doing it wrong. Complexity is the enemy.

  6. Viper, as in Darryl Issa's company? by Anonymous Coward · · Score: 0

    Recently "retired" congressman Darryl Issa (R-Vista) was the wealthiest ($280M+) member of the House of Representatives as a result of sales of auto alarms, including Viper (notorious in previous versions for saying "Protected by Viper, stand back" or some such nonsense when someone got too close.)

  7. The Viper is a security threat by sjames · · Score: 1

    I once saw the viper get a car destroyed. Someone, lat's call him Angry Young Man was walking through a parking lot when he passed within 3 feet of a car with the Viper installed. It started going into the car alarm version of the internet tough guy speech about how it was the Viper and you needed to step away from the car.

    AYM, who was about to walk harmlessly by, turned and yelled "OH YEAH, WELL FUCK YOU!!!" He then began kicking the grille in, smashing the headlights, etc repeating "FUCK YOU" over and over. By the time I left he was working on the windshield.

    1. Re:The Viper is a security threat by iggymanz · · Score: 1

      So a mentally unbalanced young man can come unglued hearing synthesized voices and becomes a criminal.

      Not sure there is a lesson here other than another justification for concealed carry, probably best someone put that two-legged animal down

    2. Re:The Viper is a security threat by sjames · · Score: 1

      Perhaps the alarm system shouldn't annoy everyone who walks near the car, especially in a parking lot. I'm guessing the AYM probably wasn't a stranger to minor criminal charges, but from the car owner's perspective, it would have been better if the alarm system had just kept quiet unless someone actually messed with the car.

    3. Re:The Viper is a security threat by Anonymous Coward · · Score: 0

      "So a mentally unbalanced young man can come unglued hearing synthesized voices and becomes a criminal." - Good self knowledge, you're criminally stupid. Yes, a hospital telepresence robot IS A ROBOT, MORON. Lol.

      You're failing even basic shit tests.

    4. Re: The Viper is a security threat by Anonymous Coward · · Score: 0

      In a world where everybody is seen as a potential criminal and must be tracked and watched everyhere they go, it dosen't take much to set somebody off.

      Just have a bad day at work, and you too can become that "mentally unhinged" person trashing a car that smarts off at you.

    5. Re: The Viper is a security threat by Anonymous Coward · · Score: 0

      True story: A douchbag goes on vacation, leaving his car behind with the alarm activated. The alarm goes off, and blairs for hours.

      When the owner came back, he found the windows smashed out and the car covered in dog shit.

      Moral: Don't let your car alarm piss off your neighbors

    6. Re:The Viper is a security threat by iggymanz · · Score: 1

      So people have a right to destroy things that annoy them? or do only criminals who should be in jail do that?

    7. Re:The Viper is a security threat by sjames · · Score: 1

      I made no such claim. I claimed only that because the viper was more interested in self promotion and a bit of theater than it was in actual security, it attracted a bad actor who would have otherwise walked by without incident, just as he did with all of the other cars that remained silent.

      It's well and good to learn some self defense, but if you then go to a dive bar and yell "I'm the biggest badass in this bar!" repeatedly, right or wrong you're going to get your ass kicked. It's a stupid strategy.

  8. 'smart' anything is for 'dumb' asses by Anonymous Coward · · Score: 0

    With my foot up your dumb ass.

  9. Car alarms are people too, they should carry guns by Anonymous Coward · · Score: 0

    How is a car alarm going to get licensed to conceal carry a gun? You 'merkins and your guns. Still haven't learned after a couple hundred years. No wonder you live in a shithole. You deserve what you get.

  10. hindu dindu (any testing) by Anonymous Coward · · Score: 0

    Typical Indian shovelware.

  11. Cocospy App by cdion709 · · Score: 0

    cocospy is one of the millions playing, creating and exploring the endless possibilities of Roblox. click on https://cocospy.com/snapchat-s...

  12. Cocospy App by cdion709 · · Score: 1

    cocospy is one of the millions playing, creating and exploring the endless possibilities of Roblox. click on https://cocospy.com/snapchat-s...