Sy Computing Services

Sy Computing Services Official Page of Sy Computing Services, LLC. "Our Services, Your Peace of Mind!"
Residential & Commercial Computer Sales, Service and Remote Support.

Commercial Networking, Managed Services & Server Networks.

Trailer Lott is locally owned right here in Godley. Kelly called me out to figure out a firewall issue that was preventi...
08/06/2026

Trailer Lott is locally owned right here in Godley. Kelly called me out to figure out a firewall issue that was preventing her Kyocera CS 5053ci from scanning to a shared folder on her computer. The Kyocera tech had already been out there to look at it and he wasn't sure what was going wrong. I didn't bother messing with configuring Windows Firewall, I created a new shared folder on the root (the original was on her Desktop which is managed by OneDrive) and configured it. Got it up and working in under 30 minutes.

Need help with your commercial IT environment? Give me a call: (817) 240-4761

https://www.sycomputing.com

Thanks much to new client, Randy V., for bringing in his barely used HP laptop to figure out why it was sooooo ssssllllo...
08/04/2026

Thanks much to new client, Randy V., for bringing in his barely used HP laptop to figure out why it was sooooo sssslllloooooow. Well, unfortunately for Randy, it's because it came from the factory that way. Windows 11 with 4GB RAM (upgradeable to 8GB - as though that would help much!), a 5400 RPM spindle HDD, and Pentium Silver dual-core CPU. I hate to be the bearer of bad news (which is why I'm not smiling), but Ouch.

We're looking into getting him set up with a nice reconditioned unit with warranty: i7 11th Gen, 16GB RAM and NVMe HDD - a much needed upgrade!

Is your computer slow and you can't figure out why? I can!

Give me a call: (817) 240-4761
On the web: https://www.sycomputing.com

Thanks to new client and long time Godleyite, Eddie Maxwell, for trusting me to deal with an annoying pop-up issue with ...
08/03/2026

Thanks to new client and long time Godleyite, Eddie Maxwell, for trusting me to deal with an annoying pop-up issue with his computer. At first Eddie believed there was a problem and called the number on the pop-up, but shortly thereafter realized it was a scam. I took it in , got rid of the pop-ups, and did a good once-over maintenance run, cleaning it up. Need help with annoying pop-ups telling you your computer is infected with a virus? Don't call them, it's a scam! Give me a call instead!

(817) 240-4761
https://www.sycomputing.com

Thanks so much to my newest client, the lovely and gracious Carol McLaughlin, who trusted me to figure out what was goin...
07/24/2026

Thanks so much to my newest client, the lovely and gracious Carol McLaughlin, who trusted me to figure out what was going on with her beloved HP laptop. She was extremely slow to boot, and once she finally came up, some of the system menus were no longer working. This one had some malware issues, and, unfortunately, the hard drive is in the process of failing as we speak. I took care of the malware and did as much as I could to get her working a little bit faster than before. Unfortunately, it's only a matter of time. 😒 Got her fav pics backed up and she won't be saving anything to that machine any longer.

Is your machine slow? Can't figure out why? Give me a call. It's a good idea to get your machine checked out once in a while. After all, at least Carol is aware that hers is almost done and she can prep for the inevitable: (817) 240-4761

https://www.sycomputing.com

FYI folks!"If you bought a car from a dealer since 2017, take two minutes and check:β†’ Look for a KARR or SWDS sticker on...
07/23/2026

FYI folks!

"If you bought a car from a dealer since 2017, take two minutes and check:
β†’ Look for a KARR or SWDS sticker on the driver's-side window
β†’ Look under the dashboard on the driver's side for a small button with a blinking light
β†’ If you find either one, install the KARR app, connect to the alarm, and open Customer Service, then Firmware Update
β†’ Do not try to rip the device out yourself, it is wired into the ignition
A box got added to your car, sold as protection, and it turned out to be the easiest way in. The people most exposed are the ones who never knew it was there, driving a car that answers to a code pulled straight from a free app. The firmware fix is out, but it only reaches the owners who hear about it."

The alarm bolted into your car to protect it can now be used to steal it. A person standing a few steps away pulls out a phone, and your doors pop open. More than 2.2 million cars run this box, and a thief needs no key to open one.

When you buy a car at a dealership, the sales desk often offers a security upgrade called KARR. A small device gets wired in under the dashboard on the driver's side, and it talks to an app on your phone over Bluetooth. Through the app it behaves like a key fob: it locks and opens the doors, honks the horn, flashes the lights, and it can stop the car from starting. Dealers use it to keep track of the cars on their lot and to sell theft protection to buyers. The names to look for are KARR and SWDS, which stands for SouthWest Dealer Services, and the company behind the hardware is Acrisure.

Computer scientists at the University of California San Diego took the KARR system apart to see how well it was secured. What they found is the kind of mistake that undoes what the product is for.

These devices share one secret key. Not one key per car. The same key sits in millions of them.

The team downloaded the official KARR app, took it apart, and found that key inside it. Once they had it, they could send commands to any of these devices within Bluetooth range.

A hardcoded key means the secret is written straight into the software and ships the same in each copy of the app. Whoever installs the app is holding it too, they just have to go looking. The general way to pull a secret out of an Android app is to unpack the install file and read the strings inside it. As a simplified illustration of the technique, not the exact steps the team used:

$ apktool d KARR.apk -o karr_app
$ grep -rIn "key\|secret" karr_app/smali/

Once that constant turns up, you hold the same secret these devices trust. That is the weakness in one line: a password baked into the app, identical across millions of cars, and it cannot be rotated or revoked.

With that key, a person within Bluetooth range can do the same things the app can do. From as far as five yards away, they can open the doors, shut off the alarm, sound the horn, flash the lights, and stop the car from starting. That last part only works while the car is parked and not already running, so your engine will not cut out while you drive. The danger is at the curb: your car sits there, the doors open without a scratch, and from that point a thief uses the kind of tools available to locksmiths to start it and drive off.

Car theft normally starts with a smashed window, and that leaves a trace. This leaves the car untouched, so the owner comes back to an empty spot with no broken glass and nothing to point at.

It gets worse than a car that opens itself. The device keeps broadcasting over Bluetooth while the car runs and for up to ten minutes after it is switched off, and that signal is identifiable enough to mark it as a KARR device rather than a headset or a speaker. Public databases like WiGLE, which volunteers fill by driving around and logging the wireless signals they pass, already store where those signals have been seen. So an attacker does not have to walk a parking lot hoping to find a vulnerable car. Those records show where a given KARR car has turned up before, which is enough to point someone straight at it.

There is a second way this bites, and it has nothing to do with driving your car away. The same feature that keeps a car from starting can be turned on the owner. The radio stays awake for up to ten minutes after you park, so a person within range can catch you as you pull in, switch on the immobilizer, and walk off. Your car will not start, and nothing is physically wrong with it, because the block sits in a box the owner never knew was there.

There is a cruel twist in who gets warned. On a system the owner never paid for, that remote wake-up briefly sounds the horn and flashes the lights, so there is at least something to notice. On a system the owner did pay to activate, the same commands come through silent. The customers who spent money on protection are the ones who get no warning at all.

They counted at least 1.4 million vulnerable cars at first, then kept digging and raised the number to at least 2.2 million. Most were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 onward. Because those cars get resold, vulnerable ones now sit in driveways across the United States, in Canada, and as far away as Japan. The device stays active even if the buyer said no to the upgrade and never paid a cent for it.

To feel what 2.2 million means: on a single twenty-minute drive near their campus, the team picked up 97 KARR cars with an ordinary phone.

The discovery started by accident, and years ago. Back in 2018, a group led by then UC San Diego PhD student Nishant Bhaskar was hunting for credit card skimmers hidden inside gas pumps, the kind that steal your card while you fill up. While scanning for those, they kept picking up Bluetooth signals they could not identify. It took serious digging to trace those signals back to the KARR and Rockledge devices. The team, now led by professor Aaron Schulman with Jerry Yu and Yibo Wei as co-first authors, spent the years since taking the systems apart. They will lay out exactly how they did it at the DEF CON conference on August 9 and USENIX Security on August 12, in a paper called BLE Theft Auto.

They are deliberately holding back the step-by-step of the reverse engineering so thieves cannot copy it, and they reported the flaw to the manufacturers and to the National Highway Traffic Safety Administration before going public.

The researchers told Acrisure about the flaw in January 2025. The fix landed on July 20, 2026, about eighteen months later, and twenty days before the team was due to present it at DEF CON. Acrisure called the attack highly complex and a low risk in normal use, while the researchers pulled it off with an ordinary Android phone running their own app.

The update closes the hole, but it runs through the KARR app and the owner has to install it. If half the owners do not know the device exists, half of them are not opening an app to patch it. Pulling the device out is not a practical option for the average owner either, because it is wired deep into the car's computer and ignition, so getting it out means opening the dashboard and cutting wires that are tangled up with how the car starts.

Nothing official stands behind the fix. There is no CVE number for it, and because the hardware is not the automaker's, it cannot be pushed out through a normal car software update. No official channel reaches an owner on its own. The only reliable way to know is to look under your own dashboard.

The team points at what would close a hole like this: connecting a new phone should require someone to physically press a button inside the car first. A key that lives only in software, shared across millions of units, was never going to hold.

KARR is not the only one. A second company, Rockledge, makes similar devices the team believes may also be attackable, though it is harder. An attacker would have to be nearby while the owner uses the system, record the exchange, and play it back later. Rockledge had not responded to them by the time they published.

If you bought a car from a dealer since 2017, take two minutes and check:
β†’ Look for a KARR or SWDS sticker on the driver's-side window
β†’ Look under the dashboard on the driver's side for a small button with a blinking light
β†’ If you find either one, install the KARR app, connect to the alarm, and open Customer Service, then Firmware Update
β†’ Do not try to rip the device out yourself, it is wired into the ignition

A box got added to your car, sold as protection, and it turned out to be the easiest way in. The people most exposed are the ones who never knew it was there, driving a car that answers to a code pulled straight from a free app. The firmware fix is out, but it only reaches the owners who hear about it.

Capturing and replaying wireless traffic, putting an adapter in monitor mode to see what devices broadcast, and mapping exposed devices with tools like Shodan are exactly the skills the wireless and IoT chapter of my ethical hacking course builds, step by step:
β†’ https://www.udemy.com/course/ethical-hacking-complete-course-zero-to-expert/?couponCode=JULY2026B

Hacking is not a hobby but a way of life. 🎯

Research & writing: Jolanda de Koff | HackingPassion.com
Sharing is fine. Copying without credit is not.

Read the full breakdown:
β†’ https://hackingpassion.com/karr-alarm-bluetooth-car-theft/

Thanks to new client Aaron Petty for bringing in his company laptop to troubleshoot a freezing issue. Aaron was trying t...
07/20/2026

Thanks to new client Aaron Petty for bringing in his company laptop to troubleshoot a freezing issue. Aaron was trying to install a Windows Update when something went wrong and he was forced into a hard shutdown. Well that pretty much hosed Windows upon the next boot. It's another TLDR saga, but I want to reiterate this folks: If you use Bitlocker or otherwise encrypt your system drive, make SURE you have your key backed up somewhere! Furthermore, backup, backup, backup your critical data! In Aaron's case he hadn't either, and his machine was tied to a Microsoft account to which he no longer had access. It was scary there for a couple hours, but I got her to come back to life without reinstalling Windows. Without the Bitlocker key, this could've meant all of his data would've been lost. Thanks Aaron!

Need help with your home or commercial IT environment? Give me a call: (817) 240-4761

https://www.sycomputing.com

Thanks to new client and Army vet, JW (who did not wish to be photographed for Facebook), for trusting me to troubleshoo...
07/17/2026

Thanks to new client and Army vet, JW (who did not wish to be photographed for Facebook), for trusting me to troubleshoot why his ASUS Vivotech laptop was not able to process Windows Updates. JW brought this machine in to figure out why he couldn't install any Windows Critical/Security updates with a factory 64GB SSD HHD and 4GB of RAM installed. Well that's because there just wasn't any room to process the updates on the machine.

Folks, if you have one of these, do expect there to be issues like this. When you're buying a new computer with Windows 11 installed, I recommend at least 16GB RAM and 512GB SSD HHD as minimum specs. Yes, you can get away with less than that, however, I'm thinking about your long-term needs here. In the long run, you'll have a much better computing experience with even more system resources than these, but these should get you along for a little while. I'm not exactly sure why any OEM like Asus would offer to sell such a machine like this to anything other than, say, industrial clients, who might never need anything other than a basic Win11 install in the first place, but here we are.

Need help with your Windows Updates, or anything else with your home, office, or commercial IT environment? Give me a call: (817) 240-4761.

https://www.sycomputing.com

Address

417 W. Graham Avenue
Godley, TX
76044

Opening Hours

Monday 10am - 6pm
Tuesday 10am - 6pm
Wednesday 10am - 6pm
Thursday 10am - 6pm
Friday 10am - 6pm
Saturday 10am - 2pm

Alerts

Be the first to know and let us send you an email when Sy Computing Services posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share