There are a couple of different ways that are significantly better than brute force (as in: works against real cars in seconds to a few minutes). (Though since key length is only 48 bit, even brute forcing might be practical.)
This might interest you:
https://www.usenix.org/system/files/conference/usenixsecurit...
Knowing nothing about how it was done, I'd just assume the security was really bad [2] and the box simply emitted all possible combinations. Has any industry ever taken security seriously before the first major breach?
Our solution is to never store anything of value in the car.
[1] Pretty sure because almost never leave a car unlocked. Two cars unlocked is even more unlikely.
[2] By way of example, unlocking my Chevy with its fob routinely set off a car alarm for a different car. That tells you right there that the car alarm receiver has zero security.
I have no idea if thats what all these devices are, or how legit the article was, but seems legit to me.