Somewhere in Southern California, a Honda, Toyota, Mazda, Ford, or Jeep dealership sold you a box bolted under your dashboard and called it protection. It came with a sticker for your window, a smartphone app, and a straight-faced pitch about stopping thieves. Nobody in that finance office mentioned that the box uses the exact same digital key as every other one of the roughly 2.2 million units installed since 2017.
That’s the real finding buried inside a new University of California San Diego study published this week: the dealer-installed security systems marketed under names like KARR and SWDS don’t each get their own unique credentials. They share one. Crack it once, as UC San Diego researchers did, and you have functional access to lock, unlock, honk, flash, and immobilize millions of cars parked anywhere from Los Angeles to Osaka.
Here’s the part that should bother anyone who ever sat through an intro cryptography lecture. Good security design assigns every device its own private key, so breaking into one unit never breaks into the rest. These systems skipped that step entirely. It’s the digital equivalent of a locksmith deciding every deadbolt he installs nationwide opens with the same key, then stamping “anti-theft” on the box anyway.
Some automakers already treat this kind of testing as standard practice. Porsche runs a bug bounty program that pays outside researchers to break its systems before criminals do. Whoever engineered the KARR and SWDS hardware either skipped that step or ignored what it would have found.
The device itself talks to a phone app over Bluetooth, and dealers pitch it as both a theft deterrent and a convenience feature: lock the doors, kill the engine, track the car, all from a phone. It’s the same appetite for remote immobilization technology that shows up in Ford’s new kill switch hardware, minus the manufacturer’s engineering scrutiny and plus, apparently, one shared password for the entire installed base.
Now here’s the detail that should make owners angry rather than just uneasy. Buyers who declined the “anti-theft” upgrade at the dealership still drove off with an active, vulnerable device wired into their car. Saying no in the finance office didn’t disconnect anything. It just meant they didn’t pay for the privilege of being exposed.
An attacker doesn’t need to touch the car, or even get particularly close. From roughly five yards away, over Bluetooth, someone holding the cracked key can unlock the doors and disable the engine immobilizer, then use ordinary locksmith tools to start the car and drive off. No broken glass, no forced entry, nothing for a dash cam to catch. Compare that to the $1.3 million supercar theft ring Ventura County prosecutors broke up this month, which needed cloned key fobs and physical proximity to the target vehicle. This method is simpler and works from farther away.
Removing the device isn’t a realistic option for most owners. It’s spliced into the wiring beneath the dashboard and tied into the ignition system, and pulling it out means cutting and reconnecting harnesses most owners have no business touching. The manufacturer, Acrisure, shipped a firmware patch this week, but it only works if the owner downloads an app that most people don’t know they need. A separate company making similar hardware, Rockledge, has a comparable weakness and, according to the researchers, hasn’t even responded to their disclosure yet.
This is where the story stops being about one sloppy security chip and turns into a regulatory blind spot. When an automaker builds a defective part, NHTSA can force a recall and make the manufacturer notify every owner directly. We just watched that logic play out when Winnebago and Grand Design both recalled the same fire-prone fan even though neither company actually built it. Dealer-installed aftermarket add-ons live in a grayer zone than that. The researchers looped in NHTSA anyway, but the actual remedy here is a voluntary app update from a vendor, not a mandated recall with owner letters. Nobody is required to track down every affected driver and tell them their car has this box installed.
And plenty of owners won’t know. The sticker that flags a vulnerable car fades, peels, or disappears at a car wash years before the vehicle changes hands on the used market. It’s a familiar shape for anyone who followed the CarGurus breach earlier this year: the damage rarely stays contained to the original owner or the original transaction.
Buyers rarely know these boxes exist. Sellers rarely disclose them. Thieves, it turns out, knew before almost anyone else.
There’s a quieter finding in the study worth sitting with. The same public databases that let a dealership track its lot inventory also store location data for vehicles carrying these devices, which means the vulnerability isn’t only about unlocking a door. It’s about knowing exactly where a specific car is parked before anyone ever walks up to it.
UC San Diego professor Aaron Schulman, one of the study’s senior authors, put it plainly: “Many car owners don’t even know that their vehicle is vulnerable.” That’s not a caveat. That’s the sentence the dealership never wanted printed on a sticker.
If you bought a Honda, Toyota, Mazda, Ford, or Jeep in Southern California anytime in the last nine years, check the driver’s side window and the underside of your dashboard for a KARR or SWDS badge, then update the app before doing anything else. But the bigger lesson has nothing to do with one vendor’s bad cryptography. Dealerships have spent decades selling add-on boxes nobody asked for, from VIN etching to fabric guard to nitrogen in the tires, with no outside party ever auditing whether any of them actually work. This time the audit came from a university lab instead of the dealership’s own quality control. It found that the anti-theft device was the theft risk.

