Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

21–30 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#21
post #16
post #12

Earlier quoted context omitted.

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in the past when faced with intractable, deep-seated defects in a product, so it wouldn't be unexpected or unreasonable to assume.

All the notification would be is a courtesy, allowing them time to start designing and marketing a new product, instead of having the market get handed to their competitors when hotels suddenly have to start replacing their locks with less-flawed ones. And I'm not sure a company that produced a flawed products deserves that.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#22
Is the obvious fix to make the programming port available only from the inside of the room? That's where the screws for physical bolt locks go.

And you can still have a DC power port on the outside in case of a powered-down door, just no programming access.

Why have they not done it that way???

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#23
post #12
post #11

Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

Not cool, dude. Not cool at all. The company might be lazy and ignorant, but it doesn't mean they won't move when faced with a lingering public disclosure. You must give them a chance. What you are planning to do is egoistic, it serves your own interests, and it does that at the expense of people staying in the hotels. How is this even remotely ethical?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#24
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/

All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#25
post #12
post #11

Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

I agree that it's probably futile, but the white-hat thing to do is give them notice. If they say they will not fix it, or ignore you, then you release the info.

If they say they're working on it, you give them a reasonable timeframe for that, and then release it.

That way, you've done everything 'properly', and nobody can say otherwise. With the path you're on, everyone is going to blame you instead of them, even though they're at fault.

Please consider doing this the proper way, even though we both know it's most likely futile.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#26
post #20
post #17

Earlier quoted context omitted.

The article mentions Onity - what about other companies?

Everything I'm releasing is specific to Onity. I can't speak to the security of any of the others, as I haven't looked at them yet, but I'm planning on doing so in the near future. Next up is most likely Ving, though Timelox is a really clever system, so that could be fun.

The room I'm in has a Ving lock. I witnessed it being reprogrammed by hotel staff when I was having problems opening my door.

Ving may have security flaws but I'm assuming it will be a bit more expensive to exploit.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#27
post #21
post #16

Earlier quoted context omitted.

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

> what, exactly?

They could plug the access holes, with custom pentalobe screws. That's an under a dollar per lock fix.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#28
post #20

Earlier quoted context omitted.

Everything I'm releasing is specific to Onity. I can't speak to the security of any of the others, as I haven't looked at them yet, but I'm planning on doing so in the near future. Next up is most likely Ving, though Timelox is a really clever system, so that could be fun.

The room I'm in has a Ving lock. I witnessed it being reprogrammed by hotel staff when I was having problems opening my door. Ving may have security flaws but I'm assuming it will be a bit more expensive to exploit.

I can't speak to the actual security, but I know that it requires a contact card inside the slot to actually program the lock. That's not something you can likely build for a couple bucks in parts at Radioshack, so at least the barrier to entry is higher.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#29
post #24
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

You don't think this is a little nitpicky? He's at the "Black Hat Briefings".

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#30

Is the obvious fix to make the programming port available only from the inside of the room? That's where the screws for physical bolt locks go. And you can still have a DC power port on the outside in case of a powered-down door, just no programming access. Why have they not done it that way???

Probably because if the system glitches out and they can't into the room anymore (even with maintenance keys) then they wouldn't ever be able to fix it?
Post reply on HN