Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

41–50 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#41
I was always curious about elock systems, particularly about how they are reprogrammed. Presumably they are reprogrammed by the front desk, centrally, but how does the signal reach the lock? Presumably there must be wires attached (at least for power). So why is there an external port on the lock at all? Also, what is the possibility that a lock exploit could affect the central reprogramming system?

Edit: just read below that these things are battery powered, which raises two questions, first, ok, how are they reprogrammed, and second, how does a hotel not go bankrupt replacing thousands of batteries all the time?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#42
post #33

Earlier quoted context omitted.

So, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.

C'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options. (edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities. -- Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?

It's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate?

"Me of all people"? Am I a spokesperson for "Responsible disclosure" now?

I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cody did.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#43
post #12
post #11

Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlike…

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

Since everyone else replying is telling you what a lazy horrible person you are, I'll go ahead and let you know that I agree. Theres nothing they can really do at this point. And because of that the companies only real option is to just stonewall you for as long as possible.

EDIT: And if it weren't for the long history of large companies suing security researchers for blackmail/etc when they try responsible disclosure I'd have probably sided with everyone above.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#44

I was always curious about elock systems, particularly about how they are reprogrammed. Presumably they are reprogrammed by the front desk, centrally, but how does the signal reach the lock? Presumably there must be wires attached (at least for power). So why is there an external port on the lock at all? Also, what is the possibility that a lock exploit could affect the central reprogramming system? Edit: just read b…

The locks are programmed by the front desk, but then the data is transferred to the Portable Programmer which then is used to update the doors. The doors themselves are not connected to power, but are rather completely battery-driven. The likelihood of anything impacting the front desk equipment is effectively nil.

(Note: This is all specific to Onity locks)

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#45
post #31
post #21

Earlier quoted context omitted.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

But imagine, if he had told them a year ago, perhaps the locks would be mostly replaced with a fixed version by now! I think it's unbelievable that he wouldn't disclose this information because he "just knows" they wouldn't do anything. He's not a damn mind reader. Hell, he might even be right, but you've still got to give the company the chance.

[deleted]

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#46
post #24
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

Counterpoint: I love that you wore it, I think the content of the article makes it hard to come to a negative conclusion (especially the comments about stopping development), and most anything that supports dieselsweeties.com is a good thing!

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#47
post #21
post #16

Earlier quoted context omitted.

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

> In order so that they could do ... what, exactly?

They can either say "Thanks for telling us. We're fixing the locks. There a X thousand locks, and we expect it to take Y weeks to fix them Please consider delaying release of this informtion until after then" - in which case he's done the responsible thing and can chose what to do.

Or they can say "We know, there's nothing we can do, don't tell anyone" in which case he's done the responsible thing and can decide what to do.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#48
post #29
post #24

Earlier quoted context omitted.

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

You don't think this is a little nitpicky? He's at the "Black Hat Briefings".

Fair enough, and that's why I attempted to tone down the message with my statement of respect. I've followed Cody's work with interest for years.

I do stand by my general point, though. I think it's worth thinking about how we represent ourselves to the general public. The word "Hacker" has an unfortunate negative reputation, and I don't think messages like this help. It really jumped out at me when I opened the article (otherwise I would have kept this nit to myself).

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#49
post #42

Earlier quoted context omitted.

C'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options. (edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities. -- Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?

It's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate? "Me of all people"? Am I a spokesperson for "Responsible disclosure" now? I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cod…

Not in bulk. Hotel technicians install and service locks, I'm sure they'll manage to screw a bolt into a hole. They are salaried.

"You" as a "sensible security guy". Or at least that was my impression of you based on what you post here.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#50
let's do this AMA thing right here, because my questions might get lost in the reddit noise. You seem like the prototype hacker to me - what's your personal stack? like OS, text editor, the computer you use daily?

thanks for answering those 3 little questions.

Post reply on HN