Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

121–130 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#121

duh? I'm sorry but low security systems like hotel rooms of course have wide vulnerabilities. The front desk will just give out keys based on trust since you don't have to register everyone staying in the room; they don't even have an audit trail if they wanted to use it. Keyless entry cars are mostly crackable ... garage door systems are trivial, you can bump pin tumbler locks, many home security systems have no bac…

I completely agree with you but I think you should read the following: http://sivers.org/obvious/

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#122
post #39

Earlier quoted context omitted.

Little hard to lock the door with door chains while you're not in the room. Hotel occupancy is a lot lower on the weekend. I'm sure many people living in hotel rooms with more belonging than can fit in the safe will appreciated this information being released on a weekend.

Hotel safes in rooms are notoriously insecure.

Hotel safes are there to secure insurance protection for your belongings.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#123
post #102

Earlier quoted context omitted.

>The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. How interesting. Does that mean that you could theoretically have access to an empty room if there's no new occupant? It seems like you need some sort of expiry to prevent that from happening, but I can't imagine how that would work without some signal passing between the front desk…

There is an expiration date on the card (the lock keeps time). However, with the crypto vulnerabilities I'm going to be announcing, it's possible to manipulate cards to change the expiration date or increment the code key value (which is what gets cycles); this would allow you to continue using a card indefinitely. You can't make cards out of nothing, though, so that helps mitigate it.

So they set the card to expire when you plan to check out. But I've extended my stay (and done late check out) and I didn't have to get a new card. Why did my room lock let me back in without getting a new or rewritten card?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#124
post #54

Earlier quoted context omitted.

I did plan to wear the shirt; I felt it injected a bit of fun into something that, frankly, is scary as hell.

Forgive me if I'm just naive but I don't get the 'scary' part. Locks have always been 'advisory' and people who have wanted to circumvent them for both good and evil rate them by their 'time to disable'. Hotel locks with hard keys had their issues as well, and were pretty trivially picked with simple tools. But the key is always that you need to bring the 'simple tools' which is to say that they aren't vulnerable in…

Agreed. The vast majority of locks on doors are to make the people inside feel safer, not to actually prevent a determined intruder from entering.

Given the dozens or hundreds of hotel staff that can easily gain access to your room, I fail to see why this is "scary."

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#125
post #47
post #21

Earlier quoted context omitted.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

> In order so that they could do ... what, exactly? They can either say "Thanks for telling us. We're fixing the locks. There a X thousand locks, and we expect it to take Y weeks to fix them Please consider delaying release of this informtion until after then" - in which case he's done the responsible thing and can chose what to do. Or they can say "We know, there's nothing we can do, don't tell anyone" in which case…

Or they can drag him through the courts to try to prevent the release of the information.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#126
post #102

Earlier quoted context omitted.

There is an expiration date on the card (the lock keeps time). However, with the crypto vulnerabilities I'm going to be announcing, it's possible to manipulate cards to change the expiration date or increment the code key value (which is what gets cycles); this would allow you to continue using a card indefinitely. You can't make cards out of nothing, though, so that helps mitigate it.

So they set the card to expire when you plan to check out. But I've extended my stay (and done late check out) and I didn't have to get a new card. Why did my room lock let me back in without getting a new or rewritten card?

I don't know about other systems, but with Onity systems you have to get a new card to extend the expiration date. Of course, it's possible they gave you a card with the incorrect expiration in the first place; happens all the time.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#127
post #12

Earlier quoted context omitted.

Given the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway.…

Since everyone else replying is telling you what a lazy horrible person you are, I'll go ahead and let you know that I agree. Theres nothing they can really do at this point. And because of that the companies only real option is to just stonewall you for as long as possible. EDIT: And if it weren't for the long history of large companies suing security researchers for blackmail/etc when they try responsible disclosur…

Agreed. The companies that have tried to shut people up with strategic lawsuits in the past have salted the earth.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#128
post #102

Earlier quoted context omitted.

>The cards have an expiration date and a code that cycles, meaning that when a new card is introduced, the old ones won't work anymore. How interesting. Does that mean that you could theoretically have access to an empty room if there's no new occupant? It seems like you need some sort of expiry to prevent that from happening, but I can't imagine how that would work without some signal passing between the front desk…

There is an expiration date on the card (the lock keeps time). However, with the crypto vulnerabilities I'm going to be announcing, it's possible to manipulate cards to change the expiration date or increment the code key value (which is what gets cycles); this would allow you to continue using a card indefinitely. You can't make cards out of nothing, though, so that helps mitigate it.

Thanks for your (patient) answering of my questions. It's funny how just asking how things work sort of naturally leads to thinking about vulnerabilities, eh? :)

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#129
post #21
post #16

Earlier quoted context omitted.

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

In order so that they could do ... what, exactly?

There may be lots of things the vendor could do. They could contact their customers so the hotels have a chance to consider their options. There is a good chance the vendor knows the protocol better than the guy who reverse engineered it; maybe there is a kill-code that they could give their hotels.

when hotels suddenly have to start replacing their locks with less-flawed ones. And I'm not sure a company that produced a flawed products deserves that.

You don't know that other products are better. In fact, he's said that there are other products he hasn't tested but still have the port. Maybe they are even easier to hack.

The company is going to have to deal with bad publicity regardless. It's just that know hotel managers are going to be in panic mode because of this guy is giving out all the directions so anyone can make their own skeleton key.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#130
post #21

Earlier quoted context omitted.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

...so that Fortune could publish an article saying he followed industry-standard guidelines of responsible disclosure, so that non-techies wouldn't get further ammo to say "there ought to be a law against this."

He hasn't even gone to the point of no return yet. The vendor's competitors -- assuming they aren't similarly vulnerable -- can point this news article out in their marketing literature.

The company can probably come up with a solution faster than a brand new third party can generate all of this guy's work.

Post reply on HN