Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

1–10 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#4
I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild.

Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reversing questions or background questions or whatnot, feel free.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#5
It won't be a surprise to learn that these types of locks are vulnerable, but I'll be fascinated to learn the details especially since it sounds like you can get access to an internal bus easily.

The assassination of Mahmoud Al-Mabhouh (http://en.wikipedia.org/wiki/Assassination_of_Mahmoud_al-Mab...) allegedly by Mossad involved attacking an electronic hotel lock to get access to his room:

"A readout of activity that took place on the hotel room's electronic door lock indicated that an attempt was made to reprogram al-Mabhouh’s electronic door lock at this time. The investigators believe that the electronic lock on al-Mabhouh’s door may have been reprogrammed and that the killers gained entry to his room this way. The locks in question, VingCard Locklink brand (Dubai police video, 21:42), can be accessed and reprogrammed directly at the hotel room door."

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#6
post #5

It won't be a surprise to learn that these types of locks are vulnerable, but I'll be fascinated to learn the details especially since it sounds like you can get access to an internal bus easily. The assassination of Mahmoud Al-Mabhouh ( http://en.wikipedia.org/wiki/Assassination_of_Mahmoud_al-Mab... ) allegedly by Mossad involved attacking an electronic hotel lock to get access to his room: "A readout of activity th…

Yep, bus is clearly accessible on the bottom of the lock.

As for Ving, I think they're going to be next up; spent years honing my skills in reversing this sort of thing, seems like a shame to stop now.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#7
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Do you kindly mind only leaking the information on Friday?

Thanks from all us who spend our weekdays living in hotels.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#8
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Random question: His former employer [..], sold the intellectual property behind Brocious’s hack to the locksmith training company the Locksmith Institute (LSI) for $20,000 last year.

Are these guys "buying up" security flaws in locks similar to others who sell these kinds of things for software?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#9
post #7
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Do you kindly mind only leaking the information on Friday? Thanks from all us who spend our weekdays living in hotels.

Regardless of which hotel you're in and what locks they use, always use the physical security mechanisms provides, e.g. door chains. Deadbolts are engaged by the lock mechanism and will be retracted by, say, maintenance key cards.

While this definitely opens up new bad things, the message is the same: don't trust the software, trust the physical. Then again, after doing this for a few years, I may be a bit on the paranoid side.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#10
post #8
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Random question: His former employer [..], sold the intellectual property behind Brocious’s hack to the locksmith training company the Locksmith Institute (LSI) for $20,000 last year. Are these guys "buying up" security flaws in locks similar to others who sell these kinds of things for software?

Don't know what they're doing, quite honestly. Though I should mention that they didn't buy it from us, they got a non-exclusive license to use the technology. Just wanted to clarify.
Post reply on HN