Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

111–120 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#111
post #28

Earlier quoted context omitted.

I can't speak to the actual security, but I know that it requires a contact card inside the slot to actually program the lock. That's not something you can likely build for a couple bucks in parts at Radioshack, so at least the barrier to entry is higher.

At least, high er . If you were in the business of robbing hotel rooms, I'm sure a onetime fee wouldn't be much of a barrier. Keep the small-time thieves at bay though.

I wonder if you could legally squad empty hotel rooms like this?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#112
post #59

Earlier quoted context omitted.

I agree that it's probably futile, but the white-hat thing to do is give them notice. If they say they will not fix it, or ignore you, then you release the info. If they say they're working on it, you give them a reasonable timeframe for that, and then release it. That way, you've done everything 'properly', and nobody can say otherwise. With the path you're on, everyone is going to blame you instead of them, even th…

> but the white-hat thing to do is give them notice That's why you _shouldn't_ do it that way. > Please consider doing this the proper way "whitehat" != "proper".

While, yeah, I'm in the security industry, I agree that the "whitehat way" isn't always the "proper" way.

That said, there is an easy way to compromise on this one, and is the way I generally go about disclosure:

1.) Email security contact with vulnerability, announce that you will be releasing information in 30 days.

2.) 30 days later, release the information.

If a month isn't enough time to apply a fix (I do 60 days if it's a particularly complex issue), then the organization pretty much doesn't care.

I don't support responsible disclosure because it's "whitehat approved," nor do I do it because I particularly care about the vendors themselves.

I'm a proponent of giving the vendor a chance because of all the sysadmins that would suddenly have an 0day on their hands and be forced into the difficult position of either:

(1) shutting down the effected service

(2) hoping they just don't get targeted, which is unlikely

(3) trying to release a patch themselves.

That is a shitty position to put people, in my opinion.

Daeken, I've chatted with you in #startups once or twice (as 'dshaw'), and I think you're a genuinely cool guy. This research is awesome, but I still think you should give vendors a chance. Assuming that they already know about the vulnerability might actually be giving them too much credit... they did create the issue, after all.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#113
post #109
post #106

Earlier quoted context omitted.

My university uses Onity locks for universal access with ID cards. This means our campus (and residences) are vulnerable, too, right? Are you aware of many universities that use similar systems?

So, those locks are the CT (commercial, Integra) locks. I strongly suspect that they're vulnerable to roughly the same thing, but I haven't tested them to see for sure. There are two reasons I believe this to be the case: the only difference between the PP20 (portable programmer used in the Onity HT system for hotels) and the CT PP is a swapped out EPROM. Given the similarity of the systems from a high-level perspect…

Neat. I've often wondered about the port on the bottom of the lock. Thanks for clarifying.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#114
post #39

Earlier quoted context omitted.

Hotel safes in rooms are notoriously insecure.

How so? Does it tend to stem from poor physical design, or the locking software?

I always figure that the maintenance guy and probably half the staff know the master code.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#115
post #36

Interesting, but it's not as if hotels in general have been high security installations. Very easy experiment: Just go to the front desk an thell them that you sadly seem to have lost your room card. 90% of the time they will just ask for your room number without requiring any kind of proof that it's actually your room.

Or there's those hotels where you have to leave the keys at the front desk. Each time you come back you say your room number and they give you the key.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#116
post #42

Earlier quoted context omitted.

It's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate? "Me of all people"? Am I a spokesperson for "Responsible disclosure" now? I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cod…

For clarification: lots of "very reputable security people" can also be total dicks. Hacker elitism does not encourage thoughtfulness.

As an industry we are a pretty awful people.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#117
post #24
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

It's pretty obviously tongue-in-cheek. He doesn't look at all evil (sorry Daeken, you look kind of... Jolly) and any real evil people don't let Forbes take their picture.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#118
post #110

I'm not certain, but in the picture from the Forbes article the lock looks exactly like the kind used on many doors in my university - the shape is exactly the same, and ours had the same type of electrical connector in the same place at the bottom of the lock. I remember because I considered attacking this interface before noticing the torx security screw next to the connector; removing this screw allows the panel c…

I'm looking at my test lock (which doesn't have panels on it) and it looks to me that there's no way you could access the lock mechanism from the battery panel. With the HT locks I've played with, the locking mechanism sits inside the door, between the lock itself (with the circuit board, card reader, batteries, etc) and the back plate containing the deadbolt and such. Don't think it's vulnerable to what you're descr…

Ah I see, no doubt a cheaper, lower-security line. Thanks for the info and congratulations on your hack.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#119
post #62

Earlier quoted context omitted.

You don't lock the bolt or the chain mechanism when you stay in a hotel room? Or are you saying they bypassed those also?

I think the primary threat in this situation is burglary of an unoccupied hotel room. Security chains are fairly easy to defeat; a bent clothes hanger will do. Deadbolts are probably pretty hard if there's no external key hole. Someone intending harm to the occupants of a hotel room might just break a window.

Not necessarily. Sometimes the master key card opens the deadbolt as well.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#120
post #24

Earlier quoted context omitted.

Was it necessary to wear a t-shirt that reads "It's fun to use learning for evil!" in the photo shoot for a Forbes spread? This doesn't help the negative perception of the word "hacker". :-/ All due respect to the work you're doing – I'm a former member of the security industry myself (worked on the IPS engine at TippingPoint).

It's pretty obviously tongue-in-cheek. He doesn't look at all evil (sorry Daeken, you look kind of... Jolly) and any real evil people don't let Forbes take their picture.

It's ok, I get "jolly" a lot.
Post reply on HN