Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

101–110 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#101
post #98

Earlier quoted context omitted.

Forgive me if I'm just naive but I don't get the 'scary' part. Locks have always been 'advisory' and people who have wanted to circumvent them for both good and evil rate them by their 'time to disable'. Hotel locks with hard keys had their issues as well, and were pretty trivially picked with simple tools. But the key is always that you need to bring the 'simple tools' which is to say that they aren't vulnerable in…

It should be noted that [some] hotel doors with electronic key cards also have physical key holes (as a backup) that are hidden, but are still susceptible to being picked. This just supports your point that hotel doors are not 100% secure for anyone who really wants to get through. Edit: Replaced all with some. The doors at the hotels I worked had backup physical keys in case the battery failed. It's cool that Onity…

That's not really the case. While some of these do exist, Onity's locks themselves do not contain any physical keyhole and I've never seen them installed in such a configuration. Other vendors may be different.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#102
post #84

Earlier quoted context omitted.

The battery lifetime depends on how much traffic the door gets, but generally I believe it's 4-6 months, which is pretty impressive for 4 AAs. As for reprogramming the doors, that only happens very rarely. The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. So really it only needs to be reprogrammed when the clock gets out of sync or t…

>The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. How interesting. Does that mean that you could theoretically have access to an empty room if there's no new occupant? It seems like you need some sort of expiry to prevent that from happening, but I can't imagine how that would work without some signal passing between the front desk…

There is an expiration date on the card (the lock keeps time). However, with the crypto vulnerabilities I'm going to be announcing, it's possible to manipulate cards to change the expiration date or increment the code key value (which is what gets cycles); this would allow you to continue using a card indefinitely.

You can't make cards out of nothing, though, so that helps mitigate it.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#103
I'm not certain, but in the picture from the Forbes article the lock looks exactly like the kind used on many doors in my university - the shape is exactly the same, and ours had the same type of electrical connector in the same place at the bottom of the lock. I remember because I considered attacking this interface before noticing the torx security screw next to the connector; removing this screw allows the panel covering the bottom part of the lock to be removed (the edge of this panel is visible in the Forbes photo), exposing the bolt mechanism of the lock. Turning this mechanism one way opened the lock, turning it the other double-locked it so it couldn't be opened with the proper keycard.

I wonder if any HN readers have access to an Onity lock to check whether this method works on them?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#104
post #21
post #16

Earlier quoted context omitted.

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

...so that Fortune could publish an article saying he followed industry-standard guidelines of responsible disclosure, so that non-techies wouldn't get further ammo to say "there ought to be a law against this."

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#105
post #6
post #5

It won't be a surprise to learn that these types of locks are vulnerable, but I'll be fascinated to learn the details especially since it sounds like you can get access to an internal bus easily. The assassination of Mahmoud Al-Mabhouh ( http://en.wikipedia.org/wiki/Assassination_of_Mahmoud_al-Mab... ) allegedly by Mossad involved attacking an electronic hotel lock to get access to his room: "A readout of activity th…

Yep, bus is clearly accessible on the bottom of the lock. As for Ving, I think they're going to be next up; spent years honing my skills in reversing this sort of thing, seems like a shame to stop now.

How did you hone your skills for years? Have you been working with other lock providers? Or other methods, or just the process of reverse-engineering the software that hardware interacts with?

You are cool, you know that?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#106
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

My university uses Onity locks for universal access with ID cards. This means our campus (and residences) are vulnerable, too, right? Are you aware of many universities that use similar systems?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#107
post #6

Earlier quoted context omitted.

Yep, bus is clearly accessible on the bottom of the lock. As for Ving, I think they're going to be next up; spent years honing my skills in reversing this sort of thing, seems like a shame to stop now.

How did you hone your skills for years? Have you been working with other lock providers? Or other methods, or just the process of reverse-engineering the software that hardware interacts with? You are cool, you know that?

I haven't been working on other lock hardware, but reversing the whole Onity system from the ground up has been quite an undertaking. I described a rough version of the whole process in another comment. I've also worked on a couple other devices, e.g. the Emotiv EPOC EEG.

And thanks, I like to think so.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#108
post #39

Earlier quoted context omitted.

Little hard to lock the door with door chains while you're not in the room. Hotel occupancy is a lot lower on the weekend. I'm sure many people living in hotel rooms with more belonging than can fit in the safe will appreciated this information being released on a weekend.

Hotel safes in rooms are notoriously insecure.

How so? Does it tend to stem from poor physical design, or the locking software?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#109
post #106
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

My university uses Onity locks for universal access with ID cards. This means our campus (and residences) are vulnerable, too, right? Are you aware of many universities that use similar systems?

So, those locks are the CT (commercial, Integra) locks. I strongly suspect that they're vulnerable to roughly the same thing, but I haven't tested them to see for sure. There are two reasons I believe this to be the case: the only difference between the PP20 (portable programmer used in the Onity HT system for hotels) and the CT PP is a swapped out EPROM. Given the similarity of the systems from a high-level perspective and the PP differences, I'd be very surprised if they weren't similarly vulnerable.

At some point I'd love to test the CT side, but 1) the hardware is tough to get hold of, and 2) it's not a very popular system, so it's not that interesting. I think it'd be pretty straightforward, though.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#110

I'm not certain, but in the picture from the Forbes article the lock looks exactly like the kind used on many doors in my university - the shape is exactly the same, and ours had the same type of electrical connector in the same place at the bottom of the lock. I remember because I considered attacking this interface before noticing the torx security screw next to the connector; removing this screw allows the panel c…

I'm looking at my test lock (which doesn't have panels on it) and it looks to me that there's no way you could access the lock mechanism from the battery panel. With the HT locks I've played with, the locking mechanism sits inside the door, between the lock itself (with the circuit board, card reader, batteries, etc) and the back plate containing the deadbolt and such. Don't think it's vulnerable to what you're describing. However, it should be noted that if it's used in the university, it's almost definitely the Integra/CT line from Onity, which is different.
Post reply on HN