A while back, he taught us how to break a combination lock in less than nine tries. Now, with his latest security-breaching breakthrough, presented at Def Con 23, he's cooked up a device that can take over just about any electronically powered remote controlled lock—and it only costs about $30 to make.
The way the device works is fairly simple: most keyless entry systems (think the Audi key fob above and your garage door opener) use something called a rolling code. Every time you press the button to unlock the door, you're sending out a code which changes each time for security purposes. The only problem is once you use a code once, it works forever.
The RollJam, when placed in the vicinity of an intended target, blocks the wireless signal and records it for later use. Once retrieved, you essentially have free reign over the previously locked device.
All you need to make yourself a RollJam: a Teensy3.1 development board ($20) and two CC1101 wireless modules ($6 each). Kamkar has released his presentation from Def Con public and promises to follow with the instructions for the build shortly.
Some manufacturers have realized the breach in security and have taken steps to combat the problem, setting codes to expire quickly after use, but most haven't. Until all remote controlled companies jump on board, though, keep an eye out: someone can swipe your ride for less than the cost of a pair of shoes.