Edit: just read below that these things are battery powered, which raises two questions, first, ok, how are they reprogrammed, and second, how does a hotel not go bankrupt replacing thousands of batteries all the time?
HN's Daeken will expose security flaw in 4m hotel room keycard locks
41–50 of 144 posts
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#42Earlier quoted context omitted.
So, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.
C'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options. (edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities. -- Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?
"Me of all people"? Am I a spokesperson for "Responsible disclosure" now?
I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cody did.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#43Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…
Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…
EDIT: And if it weren't for the long history of large companies suing security researchers for blackmail/etc when they try responsible disclosure I'd have probably sided with everyone above.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#44I was always curious about elock systems, particularly about how they are reprogrammed. Presumably they are reprogrammed by the front desk, centrally, but how does the signal reach the lock? Presumably there must be wires attached (at least for power). So why is there an external port on the lock at all? Also, what is the possibility that a lock exploit could affect the central reprogramming system? Edit: just read b…
(Note: This is all specific to Onity locks)
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#45Earlier quoted context omitted.
In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…
But imagine, if he had told them a year ago, perhaps the locks would be mostly replaced with a fixed version by now! I think it's unbelievable that he wouldn't disclose this information because he "just knows" they wouldn't do anything. He's not a damn mind reader. Hell, he might even be right, but you've still got to give the company the chance.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#46I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…
Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#47Earlier quoted context omitted.
That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.
In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…
They can either say "Thanks for telling us. We're fixing the locks. There a X thousand locks, and we expect it to take Y weeks to fix them Please consider delaying release of this informtion until after then" - in which case he's done the responsible thing and can chose what to do.
Or they can say "We know, there's nothing we can do, don't tell anyone" in which case he's done the responsible thing and can decide what to do.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#48Earlier quoted context omitted.
Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).
You don't think this is a little nitpicky? He's at the "Black Hat Briefings".
I do stand by my general point, though. I think it's worth thinking about how we represent ourselves to the general public. The word "Hacker" has an unfortunate negative reputation, and I don't think messages like this help. It really jumped out at me when I opened the article (otherwise I would have kept this nit to myself).
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#49Earlier quoted context omitted.
C'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options. (edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities. -- Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?
It's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate? "Me of all people"? Am I a spokesperson for "Responsible disclosure" now? I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cod…
"You" as a "sensible security guy". Or at least that was my impression of you based on what you post here.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#50thanks for answering those 3 little questions.