Earlier quoted context omitted.
Forgive me if I'm just naive but I don't get the 'scary' part. Locks have always been 'advisory' and people who have wanted to circumvent them for both good and evil rate them by their 'time to disable'. Hotel locks with hard keys had their issues as well, and were pretty trivially picked with simple tools. But the key is always that you need to bring the 'simple tools' which is to say that they aren't vulnerable in…
It should be noted that [some] hotel doors with electronic key cards also have physical key holes (as a backup) that are hidden, but are still susceptible to being picked. This just supports your point that hotel doors are not 100% secure for anyone who really wants to get through. Edit: Replaced all with some. The doors at the hotels I worked had backup physical keys in case the battery failed. It's cool that Onity…
HN's Daeken will expose security flaw in 4m hotel room keycard locks
101–110 of 144 posts
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#102Earlier quoted context omitted.
The battery lifetime depends on how much traffic the door gets, but generally I believe it's 4-6 months, which is pretty impressive for 4 AAs. As for reprogramming the doors, that only happens very rarely. The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. So really it only needs to be reprogrammed when the clock gets out of sync or t…
>The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. How interesting. Does that mean that you could theoretically have access to an empty room if there's no new occupant? It seems like you need some sort of expiry to prevent that from happening, but I can't imagine how that would work without some signal passing between the front desk…
You can't make cards out of nothing, though, so that helps mitigate it.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#103I wonder if any HN readers have access to an Onity lock to check whether this method works on them?
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#104Earlier quoted context omitted.
That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.
In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#105It won't be a surprise to learn that these types of locks are vulnerable, but I'll be fascinated to learn the details especially since it sounds like you can get access to an internal bus easily. The assassination of Mahmoud Al-Mabhouh ( http://en.wikipedia.org/wiki/Assassination_of_Mahmoud_al-Mab... ) allegedly by Mossad involved attacking an electronic hotel lock to get access to his room: "A readout of activity th…
Yep, bus is clearly accessible on the bottom of the lock. As for Ving, I think they're going to be next up; spent years honing my skills in reversing this sort of thing, seems like a shame to stop now.
You are cool, you know that?
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#106I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#107Earlier quoted context omitted.
Yep, bus is clearly accessible on the bottom of the lock. As for Ving, I think they're going to be next up; spent years honing my skills in reversing this sort of thing, seems like a shame to stop now.
How did you hone your skills for years? Have you been working with other lock providers? Or other methods, or just the process of reverse-engineering the software that hardware interacts with? You are cool, you know that?
And thanks, I like to think so.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#108Earlier quoted context omitted.
Little hard to lock the door with door chains while you're not in the room. Hotel occupancy is a lot lower on the weekend. I'm sure many people living in hotel rooms with more belonging than can fit in the safe will appreciated this information being released on a weekend.
Hotel safes in rooms are notoriously insecure.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#109I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…
My university uses Onity locks for universal access with ID cards. This means our campus (and residences) are vulnerable, too, right? Are you aware of many universities that use similar systems?
At some point I'd love to test the CT side, but 1) the hardware is tough to get hold of, and 2) it's not a very popular system, so it's not that interesting. I think it'd be pretty straightforward, though.
Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks
#110I'm not certain, but in the picture from the Forbes article the lock looks exactly like the kind used on many doors in my university - the shape is exactly the same, and ours had the same type of electrical connector in the same place at the bottom of the lock. I remember because I considered attacking this interface before noticing the torx security screw next to the connector; removing this screw allows the panel c…