Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

11–20 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#11
Could you explain a little more why you didn't go for responsible disclosure to Onity?

In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlikely I know!).

Given that you sat on this for a year before publishing, there was ample oppurtunity to inform Onity before you publish.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#12
post #11

Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this.

Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway. Simply put, I have zero confidence in their ability to mitigate this properly, and I believe that the only proper course of action is to make this public and let the hotels make themselves secure by whatever means possible.

I know that's a bit of a strange answer, but this is a strange situation; it's taken me a while to figure out the correct course of action, and I feel that this really is the best way for the safety of the public.

Edit: Toned down some of the wording; unnecessary.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#13
post #9
post #7

Earlier quoted context omitted.

Do you kindly mind only leaking the information on Friday? Thanks from all us who spend our weekdays living in hotels.

Regardless of which hotel you're in and what locks they use, always use the physical security mechanisms provides, e.g. door chains. Deadbolts are engaged by the lock mechanism and will be retracted by, say, maintenance key cards. While this definitely opens up new bad things, the message is the same: don't trust the software, trust the physical. Then again, after doing this for a few years, I may be a bit on the par…

Little hard to lock the door with door chains while you're not in the room.

Hotel occupancy is a lot lower on the weekend. I'm sure many people living in hotel rooms with more belonging than can fit in the safe will appreciated this information being released on a weekend.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#14
post #9
post #7

Earlier quoted context omitted.

Do you kindly mind only leaking the information on Friday? Thanks from all us who spend our weekdays living in hotels.

Regardless of which hotel you're in and what locks they use, always use the physical security mechanisms provides, e.g. door chains. Deadbolts are engaged by the lock mechanism and will be retracted by, say, maintenance key cards. While this definitely opens up new bad things, the message is the same: don't trust the software, trust the physical. Then again, after doing this for a few years, I may be a bit on the par…

>trust the physical

A lock-picker might say different, no?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#15
post #14
post #9

Earlier quoted context omitted.

Regardless of which hotel you're in and what locks they use, always use the physical security mechanisms provides, e.g. door chains. Deadbolts are engaged by the lock mechanism and will be retracted by, say, maintenance key cards. While this definitely opens up new bad things, the message is the same: don't trust the software, trust the physical. Then again, after doing this for a few years, I may be a bit on the par…

>trust the physical A lock-picker might say different, no?

Probably not.

Wait until you see the flaws, man. Not being robbed is sort of a matter of being slightly more tedious to pick than the next guy.

The stuff Daeken has worked makes it ludicrously easy.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#16
post #12
post #11

Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do.

Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#17
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

The article mentions Onity - what about other companies?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#18
post #7
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Do you kindly mind only leaking the information on Friday? Thanks from all us who spend our weekdays living in hotels.

Do you think all the locks are going to be fixed by Monday?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#19
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

[deleted]

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#20
post #17
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

The article mentions Onity - what about other companies?

Everything I'm releasing is specific to Onity. I can't speak to the security of any of the others, as I haven't looked at them yet, but I'm planning on doing so in the near future. Next up is most likely Ving, though Timelox is a really clever system, so that could be fun.
Post reply on HN