The headlight is not a car part we ever thought would be a security weakness.

Modern vehicles are, for the most part, rather difficult to steal. Modern anti-theft devices and technology make them tougher to take, but that hasn't stopped thieves from dreaming up new ways of appropriating your prized wheels. According to Dr. Ken Tindell of Canis Automotive Labs, criminals are now accessing a vehicle's CAN bus system through the headlights.

In his latest blog post, Tindell explains how thieves access headlight modules to steal new cars. It all started when his friend, himself a cybersecurity expert, had his Toyota RAV4 stolen. After some sleuthing, the owner discovered a website that sells questionable tools that can act as a key fob when connected to the vehicle's CAN bus.

These items are sold on websites that purport to support car owners or locksmiths, but it's clear to see that's not the case. The tool, disguised as a JBL speaker, costs as much as $5,500 and can work on an array of cars, including Toyota, BMW, Volkswagen, Ford, and a host of GM and Stellantis vehicles.

video, offbeat, this is how thieves are using headlights to steal cars
Toyota

At that price, it's clear that this product isn't aimed at owners but rather at criminals who see it as an investment. Thieves damage the bumper and trim pieces around the headlight, giving them access to the CAN bus in the headlight cluster. Once the device is connected to the vehicle, it takes over most of the hard work.

By pressing “play” on the faux JBL speaker case, the ECU is instructed to unlock the doors, giving the thief access to your car. They can then get in and drive away. The video below shows that the entire process is over in just a few minutes.

This is undoubtedly a worrying development, but, as Tindell writes, this issue can be resolved in two ways. The first, described as “quick and dirty,” centers around a software update allowing the engine immobilizer to monitor the CAN controller for errors.


video, offbeat, this is how thieves are using headlights to steal cars
Toyota

“The gateway could be re-programmed to only forward a smart key CAN frame if it has recently transmitted a CAN frame without problems, and in the recent past, there have been no bit errors of this type on the CAN bus,” writes Tindell.

This is only partially proof, with the author noting that changing the CAN injector can overcome the fix. However, this could take criminal types a while to figure out and give the world's automakers time to develop a full-proof solution. Tindell believes that a “Zero Trust” approach is the best and would mean a vehicle's ECU doesn't simply trust messages from other ECUs and instead requires validation that it is, in fact, a genuine request.

It would require new chips and hardware, making a retrofit option impossible, but Tindell says a software emulation of the Hardware Security Module is possible. For now, we'd recommend parking in secure areas where thieves can't access your vehicle.

I know what they were doing, the car is gone! My @ToyotaUK app shows it's in motion. I only filled the tank last night. FCUK! https://t.co/SWl8PcmfZJ

— Ian Tabor (@mintynet) July 21, 2022

video, offbeat, this is how thieves are using headlights to steal cars
Ian Tabor/Twitter

Of course, not everyone has access to a locked garage, and many owners are forced to park their vehicles on the street. It's a small crumb of comfort, but this process requires thieves to work slowly in order to gain access to the headlights. This means they cannot be interrupted, and need constant access to your vehicle.

With the RAV4 used in this example, the thieves were forced to return, with the Toyota's owner discovering the damage to the bumper and front trim. If you return to your car in the morning and find similar signs of fettling, it's best to contact your local law enforcement and make provisions to secure the car.

Sadly, car thefts are a common occurrence in the United States, with brazen criminals even breaking into dealerships to get their hands on new vehicles. Elsewhere, Hyundai and Kia have been targeted by a bizarre social media trend that encourages people to steal these vehicles.

video, offbeat, this is how thieves are using headlights to steal cars
Toyota

Keyword: This Is How Thieves Are Using Headlights To Steal Cars

CAR'S NEWS RELATED

Mobil 1's Thinly Veiled Anti-EV Advert Isn't Fooling Anyone

It's hard not to see the anti-electric rhetoric, but we couldn't help but smile at the message. Mobil 1 has released a new video titled “Breaking Free – A Mobil 1 Film,” which wants us to break free from all the electric devices in our lives. It shows a dystopian ...

View more: Mobil 1's Thinly Veiled Anti-EV Advert Isn't Fooling Anyone

This Ferrari Purosangue Costs Less Than A Mitsubishi Mirage

Just don't expect to go anywhere in it. If you can't quite afford the hefty price required to purchase the new Ferrari Purosangue, famed model car creator Amalgam has created a more cost-effective solution that will be even rarer than the real thing. While it looks like the real deal, ...

View more: This Ferrari Purosangue Costs Less Than A Mitsubishi Mirage

Bugatti's Latest Chiron-Inspired Timepiece Is A Million-Dollar Tribute To Molsheim

This $1,000,000 timepiece comes with the French tricolor. Jacob & Co. has released a new Bugatti Chiron-inspired timepiece that could be considered a fitting tribute to the French automaker. Dubbed the Bugatti Chiron Tourbillon Molsheim Edition, it's a timepiece that features the colors of the French flag using precious gems. ...

View more: Bugatti's Latest Chiron-Inspired Timepiece Is A Million-Dollar Tribute To Molsheim

eBay Reveals Priciest Car Parts Sold In 2023 So Far

Someone paid more than $11,000 for a custom luggage set designed to fit in a Ferrari 512 TR. eBay has revealed the top 10 most expensive car parts to be sold in 2023 thus far, and it makes for interesting reading. The site has nearly everything a gearhead needs and ...

View more: eBay Reveals Priciest Car Parts Sold In 2023 So Far

Watch: Amazon Delivery Driver Gets Lost On Active Drag Strip

Here's something you don't see every day. A drag strip is a safe place for many speed seekers to get their kicks in a legal setting, far away from potential dangers, other motorists, and dithering delivery drivers – unless you're the guy in the video below. Originally posted to Reddit, ...

View more: Watch: Amazon Delivery Driver Gets Lost On Active Drag Strip

Michael Andretti Tried Buying Existing F1 Teams, But There Aren't Any For Sale

The “buy a team” option is off the table. Michael Andretti is open to buying an existing Formula 1 (F1) team to join the grid but says the current teams are unwilling to sell. Andretti responded after Mercedes-AMG Petronas Formula One team principal Toto Wolff said that prospective new entrants ...

View more: Michael Andretti Tried Buying Existing F1 Teams, But There Aren't Any For Sale

Formula 1 Car Made From Tractor Parts Allegedly Has 174-MPH Top Speed

Meet the MTZ 50 Formula 1 Tractor. Anything associated with Formula 1 undoubtedly has something to do with blistering speeds. In that spirit, Belarusian agricultural machinery manufacturer Minsk Tractor Works boldly named a tractor the MTZ 50 Formula 1. For the uninitiated, the term tractoris often used to ridicule slow ...

View more: Formula 1 Car Made From Tractor Parts Allegedly Has 174-MPH Top Speed

Mini Creating AI Clones Of People To Convince Them To Buy Electric

Talk yourself into buying a Mini EV. Mini is the latest brand to use artificial intelligence (AI), but instead of giving it a serious job, the British brand is using it to have a bit of marketing fun. Using a bit of camera and audio trickery, Mini has given the ...

View more: Mini Creating AI Clones Of People To Convince Them To Buy Electric

Boxy Car Champions: 10 Models Dominating the Square-Car Segment

Mazda CX-60 Aces Moose Test, Will CX-70 Be As Good?

Official Porsche Paint For Your House Is The Ultimate Car Guy Flex

1:8 Scale Aston Martin DB5 Model Car Costs More Than A Nissan Versa

Alef's Electric Flying Car Has 800 Orders Worth Over $250 Million

Spy Shots Of The Week: Hyundai Ioniq 5 N, Dacia Duster, Renault 5 EV, VW Tiguan PHEV, and Facelifted eGolf

This Viper V10 Engine From 1996 Has Never Been Used

The Ultimate Dream Garage Is This Street Built Inside A Warehouse

McLaren F1 Team Revives Chrome Livery For Silverstone Grand Prix

New Lego Chevy Corvette C1 Celebrates Model's 70th Anniversary

Audi Celebrates Uruguay And It Has Nothing To With The Country

VW ID. Buzz Does Better Than Expected In Moose Test

OTHER CAR NEWS

; Top List in the World https://www.pinterest.com/newstopcar/pins/
Top Best Sushi Restaurants in SeoulTop Best Caribbean HoneymoonsTop Most Beautiful Islands in PeruTop Best Outdoor Grill BrandsTop Best Global Seafood RestaurantsTop Foods to Boost Your Immune SystemTop Best Foods to Fight HemorrhoidsTop Foods That Pack More Potassium Than a BananaTop Best Healthy Foods to Gain Weight FastTop Best Cosmetic Brands in the U.STop Best Destinations for Food Lovers in EuropeTop Best Foods High in Vitamin ATop Best Foods to Lower Your Blood SugarTop Best Things to Do in LouisianaTop Best Cities to Visit in New YorkTop Best Makeup Addresses In PennsylvaniaTop Reasons to Visit NorwayTop Most Beautiful Islands In The WorldTop Best Law Universities in the WorldTop Richest Sportsmen In The WorldTop Biggest Aquariums In The WorldTop Best Peruvian Restaurants In MiamiTop Best Road Trips From MiamiTop Best Places to Visit in MarylandTop Best Places to Visit in North CarolinaTop Best Electric Cars For KidsTop Best Swedish Brands in The USTop Best Skincare Brands in AmericaTop Best American Lipstick BrandsTop Michelin-starred Restaurants in MiamiTop Best Secluded Getaways From MiamiTop Best Things To Do On A Rainy Day In MiamiTop Most Instagrammable Places In MiamiTop Interesting Facts about FlorenceTop Facts About The First Roman Emperor - AugustusTop Best Japanese FoodsTop Most Beautiful Historical Sites in IsraelTop Best Places To Visit In Holy SeeTop Best Hawaiian IslandsTop Reasons to Visit PortugalTop Best Hotels In L.A. With Free Wi-FiTop Best Scenic Drives in MiamiTop Best Vegan Restaurants in BerlinTop Most Interesting Attractions In WalesTop Health Benefits of a Vegan DietTop Best Thai Restaurant in Las VegasTop Most Beautiful Forests in SwitzerlandTop Best Global Universities in GermanyTop Most Beautiful Lakes in GuyanaTop Best Things To Do in IdahoTop Things to Know Before Traveling to North MacedoniaTop Best German Sunglasses BrandsTop Highest Mountains In FranceTop Biggest Hydroelectric Plants in AmericaTop Best Spa Hotels in NYCTop The World's Scariest BridgeTop Largest Hotels In AmericaTop Most Famous Festivals in JordanTop Best European Restaurants in MunichTop Best Japanese Hiking Boot BrandsTop Best Universities in PolandTop Best Tips for Surfing the Web Safely and AnonymouslyTop Most Valuable Football Clubs in EuropeTop Highest Mountains In ColombiaTop Real-Life Characters of Texas RisingTop Best Beaches in GuatelamaTop Things About DR Congo You Should KnowTop Best Korean Reality & Variety ShowsTop Best RockstarsTop Most Beautiful Waterfalls in GermanyTop Best Fountain Pen Ink BrandsTop Best European Restaurants in ChicagoTop Best Fighter Jets in the WorldTop Best Three-Wheel MotorcyclesTop Most Beautiful Lakes in ManitobaTop Best Dive Sites in VenezuelaTop Best Websites For Art StudentsTop Best Japanese Instant Noodle BrandsTop Best Comedy Manhwa (Webtoons)Top Best Japanese Sunglasses BrandsTop Most Expensive Air Jordan SneakersTop Health Benefits of CucumberTop Famous Universities in SwedenTop Most Popular Films Starring Jo Jung-sukTop Interesting Facts about CougarsTop Best Hospitals for Hip Replacement in the USATop Most Expensive DefendersTop Health Benefits of GooseberriesTop Health Benefits of ParsnipsTop Best Foods and Drinks in LondonTop Health Benefits of Rosehip TeaTop Best Air Fryers for Low-fat CookingTop Most Asked Teacher Interview Questions with AnswersTop Best Shopping Malls in ZurichTop The Most Beautiful Botanical Gardens In L.A.Top Best Mexican Restaurants in Miami for Carb-loading rightTop Best Energy Companies in GermanyTop Best Garage HeatersTop Largest Banks in IrelandTop Leading Provider - Audit and Assurance In The USTop Best Jewelry Brands in IndiaTop Prettiest Streets in the UKTop Best Lakes to Visit in TunisiaTop Highest Mountains in Israel