Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

51–60 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#51
post #50

let's do this AMA thing right here, because my questions might get lost in the reddit noise. You seem like the prototype hacker to me - what's your personal stack? like OS, text editor, the computer you use daily? thanks for answering those 3 little questions.

Haha, it seems we already are doing the AMA here.

My stack now is a Lenovo W520 running Ubuntu and KDE, and Sublime Text as my editor. Over the years when I did this, I was running everything from a cheapo, hacked-together box to a 13" Macbook Pro, all running Windows Vista/7.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#52
post #35
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

> But on three Onity locks installed on real hotel doors he and I tested at well-known independent and franchise hotels in New York, results were much more mixed This is a long shot, but I was in a chain hotel in midtown recently and heard someone tampering with the lock, and found the door ajar in the morning. I realize you probably can't name specific hotels, but was one by any chance a chain hotel in midtown aroun…

I used to travel fairly extensively for work, on at least 3 separate occasions I had Marriott check me into an already occupied room.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#53
post #29
post #24

Earlier quoted context omitted.

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

You don't think this is a little nitpicky? He's at the "Black Hat Briefings".

It's fairly easy to change a T-shirt. Whether or not anyone agrees with his appearance or not being relevant, he wasn't photographed in the audience at the conference or up on stage.

He posed for a photograph in a hotel.

Even if he didn't have a spare shirt, the gift shop in a hotel generally does. That's if he had thought of that issue. No problem with telling the photographer you had to change. Even if they noted that in the story it's the picture that's worth 1000 words.

I had a story done a number of years ago and they sent a photographer to the office. I took several hours to arrange everything to get a good setup for the photo. It paid off. The photo was good and the photo editor liked and made it the centerpoint of a story where many people were quoted. It ran all over in syndication. My point is simply it's important to think ahead when the media comes knocking. (Along those lines hmm, maybe he did the right thing with that t-shirt publicity wise).

In any case people can now learn from the "nitpick" and decide for themselves if they are ever in the spotlight what they want to do.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#54
post #53
post #29

Earlier quoted context omitted.

You don't think this is a little nitpicky? He's at the "Black Hat Briefings".

It's fairly easy to change a T-shirt. Whether or not anyone agrees with his appearance or not being relevant, he wasn't photographed in the audience at the conference or up on stage. He posed for a photograph in a hotel. Even if he didn't have a spare shirt, the gift shop in a hotel generally does. That's if he had thought of that issue. No problem with telling the photographer you had to change. Even if they noted t…

I did plan to wear the shirt; I felt it injected a bit of fun into something that, frankly, is scary as hell.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#55
post #35
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

> But on three Onity locks installed on real hotel doors he and I tested at well-known independent and franchise hotels in New York, results were much more mixed This is a long shot, but I was in a chain hotel in midtown recently and heard someone tampering with the lock, and found the door ajar in the morning. I realize you probably can't name specific hotels, but was one by any chance a chain hotel in midtown aroun…

You don't lock the bolt or the chain mechanism when you stay in a hotel room? Or are you saying they bypassed those also?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#56
post #28

Earlier quoted context omitted.

The room I'm in has a Ving lock. I witnessed it being reprogrammed by hotel staff when I was having problems opening my door. Ving may have security flaws but I'm assuming it will be a bit more expensive to exploit.

I can't speak to the actual security, but I know that it requires a contact card inside the slot to actually program the lock. That's not something you can likely build for a couple bucks in parts at Radioshack, so at least the barrier to entry is higher.

At least, higher. If you were in the business of robbing hotel rooms, I'm sure a onetime fee wouldn't be much of a barrier. Keep the small-time thieves at bay though.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#57
post #28

Earlier quoted context omitted.

The room I'm in has a Ving lock. I witnessed it being reprogrammed by hotel staff when I was having problems opening my door. Ving may have security flaws but I'm assuming it will be a bit more expensive to exploit.

I can't speak to the actual security, but I know that it requires a contact card inside the slot to actually program the lock. That's not something you can likely build for a couple bucks in parts at Radioshack, so at least the barrier to entry is higher.

Exactly my point. :)

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#58
post #24
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

Ugh, a dyed-in-the-wool corporate whitehat bitching about a real hacker wearing an ironic black t-shirt while posing for a magazine interview.

It's 2012. Your argument is twenty years late to the discussion. Deal with it.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#59
post #12

Earlier quoted context omitted.

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

I agree that it's probably futile, but the white-hat thing to do is give them notice. If they say they will not fix it, or ignore you, then you release the info. If they say they're working on it, you give them a reasonable timeframe for that, and then release it. That way, you've done everything 'properly', and nobody can say otherwise. With the path you're on, everyone is going to blame you instead of them, even th…

> but the white-hat thing to do is give them notice

That's why you _shouldn't_ do it that way.

> Please consider doing this the proper way

"whitehat" != "proper".

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#60
post #21

Earlier quoted context omitted.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

> what, exactly? They could plug the access holes, with custom pentalobe screws. That's an under a dollar per lock fix.

Now the device used to break into the rooms costs $57 instead of $50.

Cool story, bro.

Post reply on HN