BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: BLE Theft Auto: How a Dealer-Installed Anti-Theft Sy
 stem\n   Exposes Over a Million Cars to Theft\n   Tags: DEF CON Official T
 alk | Demo 💻 | Exploit 🪲\n   When: Sunday\, Aug 9\, 11:30 - 12:30 PD
 T\n   Where: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n
 \n   Description:\n\n   Car dealers predominantly in the Southwestern U.S.
  have been\n   pre-installing "KARR\," an aftermarket anti-theft alarm sys
 tem\, in\n   every car they sell. They offer these systems as an upgrade w
 hen you\n   purchase your car\, giving you smartphone-based control over y
 our car\n   locks and immobilizer\; if you decline the offer\, the dealer 
 says they\n   will deactivate the system. What they don't tell you: this s
 ecurity\n   system is authenticated by a global shared key\, so anyone who
  recovers\n   that key can remotely control nearby KARR units with a smart
 phone.\n\n   KARR is installed in an estimated 1.4 million cars\, and ever
 y\n   vulnerable unit shipped with the same authentication key\, allowing 
 an\n   attacker with a smartphone to unlock the doors\, disable the alarm 
 and\n   immobilizer\, and trigger the horn and lights of any KARR-equipped
 \n   vehicle. The core impact is unauthorized access\, which can enable\n 
   burglary\, OBD-II access\, and escalation including the key-programmer\n
    workflow we will demonstrate\; every owner with KARR installed needs to
 \n   update\, including those who declined the upsell or inherited it used
 .\n\n   We'll walk through how we discovered KARR\, how KARR ends up in\n 
   millions of cars\, how the attack works end-to-end\, and what owners can
 \n   do to fix it today. We'll also show that the same recipe revealed\n  
  vulnerabilities in other aftermarket BLE systems.\n\n   Our paper: Yibo W
 ei\, Jerry Yu\, Sumanth Rao\, Mohak Vaswani\, Jefferson\n   Chien\, Christ
 ian Dameff\, Nishant Bhaskar\, Aaron Schulman\, "BLE Theft\n   Auto: Evalu
 ating the Security of Aftermarket BLE-based Automotive\n   Remote Control 
 Systems"\, USENIX Security 2026. (to appear)\n\n   Aftermarket alarms: Ken
  Munro / Pen Test Partners\, "Gone in Six\n   Seconds: Exploiting Car Alar
 ms"\, 2019.\n   https://www.pentestpartners.com/security-blog/gone-in-six-
 seconds-exploiting-car-alarms/\n\n   Aftermarket alarms: VERSPRITE\, "How 
 Hackers Control & Steal Vehicles\n   Remotely" (Carlink remote-start vulne
 rability).\n   https://versprite.com/vs-labs/hacking-remote-start-system/\
 n\n   Automotive BLE and keyless entry: Xie et al.\, "Access Your Tesla\n 
   without Your Awareness: Compromising Keyless Entry System of Model 3"\,\
 n   NDSS 2023.\n   https://www.ndss-symposium.org/ndss-paper/access-your-t
 esla-without-your-awareness-compromising-keyless-entry-system-of-model-3/\
 n\n   Automotive BLE and keyless entry: NCC Group\, "Tesla BLE Phone-as-a-
 Key\n   Passive Entry Vulnerable to Relay Attacks"\, 2022.\n   https://www
 .nccgroup.com/research/technical-advisory-tesla-ble-phone-as-a-key-passive
 -entry-vulnerable-to-relay-attacks/\n\n   Automotive BLE and keyless entry
 : Francillon\, Danev\, Capkun\, "Relay\n   Attacks on Passive Keyless Entr
 y and Start Systems in Modern Cars"\,\n   NDSS 2011.\n\n   Foundational au
 tomotive security: Koscher et al.\, "Experimental\n   Security Analysis of
  a Modern Automobile"\, IEEE S&P 2010.\n   https://doi.org/10.1109/SP.2010
 .34\n\n   Foundational automotive security: Checkoway et al.\, "Comprehens
 ive\n   Experimental Analyses of Automotive Attack Surfaces"\, USENIX Secu
 rity\n   2011. https://www.autosec.org/pubs/cars-usenixsec2011.pdf\n\n   B
 LE application-layer auth: Sivakumaran and Blasco\, "A Study of the\n   Fe
 asibility of Co-located App Attacks against BLE and a Large-Scale\n   Anal
 ysis of the Current Application-Layer Security Landscape"\, USENIX\n   Sec
 urity 2019.\n   https://www.usenix.org/conference/usenixsecurity19/present
 ation/sivakumaran\n\n   Measurement and tooling: WiGLE\, Wireless Network 
 Mapping.\n   https://www.wigle.net/\n\n   Measurement and tooling: ILSpy\,
  open-source .NET assembly browser and\n   decompiler. https://github.com/
 icsharpcode/ILSpy\n\n   Speakers:Aaron Schulman\,Jerry Yu\,Yibo Wei\n\n   
 SpeakerBio:  Aaron Schulman\, University of California\, San Diego\n\n   A
 aron Schulman is an Associate Professor at University of California\,\n   
 San Diego. His research group works on problems that involve gathering\n  
  large-scale measurements to test whether assumptions about security\,\n  
  and sometimes reliability\, match reality. This work often leads his\n   
 students to gather data on rooftops\, at fast food restaurants\, gas\n   s
 tations\, and hospitals\, and while riding in cars\, trains\, and\n   airp
 lanes. He earned his PhD in Computer Science from University of\n   Maryla
 nd\, where he studied Internet reliability\, and he did a\n   postdoctoral
  fellowship at Stanford University\, where he investigated\n   bottlenecks
  in cellular infrastructure. Aaron co-discovered sensitive\n   unencrypted
  data sent over GEO satellites from cellular providers\,\n   governments\,
  militaries\, and power grid operators. He also\n   co-developed a Bluetoo
 th credit card skimmer detector that federal and\n   state law enforcement
  have used to stop millions of dollars in credit\n   card fraud. While in 
 Silicon Valley\, he co-founded a company that\n   helped Google improve th
 e battery life of the Chrome web browser. This\n   is his third year atten
 ding DEF CON.\n\n   SpeakerBio:  Jerry Yu\n\n   Jerry Yu is a wireless sys
 tems software engineer associated with the\n   SysNet research group at Un
 iversity of California\, San Diego. He\n   contributed to this work by rev
 erse-engineering the mobile apps behind\n   the aftermarket BLE automotive
  control systems we studied.\n\n   SpeakerBio:  Yibo Wei\, University of C
 alifornia\, San Diego\n\n   Yibo Wei is a PhD student at University of Cal
 ifornia\, San Diego\,\n   advised by Professor Aaron Schulman. He is the l
 ead author of the\n   forthcoming USENIX Security 2026 paper on BLE Theft 
 Auto (under\n   embargo)\, an ecosystem-wide study of aftermarket BLE-base
 d automotive\n   remote control systems. He led the reverse-engineering\, 
 protocol\n   analysis\, population estimation\, and disclosure for this wo
 rk. This\n   will be his first time attending DEF CON.\n\n   '\n\n   1. #L
 VCCW_Level1_Hall3\n\n\n
DTEND:20260809T193000Z
DTSTART:20260809T183000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Ov
 er a Million Cars to Theft
END:VEVENT
END:VCALENDAR
