Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

141–144 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#141
post #21
post #16

Earlier quoted context omitted.

That's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

> the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible

While that may be "profit-maximizing", it's not necessarily "rational". I'd sooner call it "short-sighted", "single-minded" or "primitive".

It might be "rational" from the pov of such a corporation as a single organism but it's not from the view of the humans that make up its arms, legs and eyes. And they live in the same society as the hotel owners and hotel guests, unless they choose not to, but it's getting harder and harder to make that choice thanks to people like Daeken.

And about the corporate organism? In its own competitive environment, it's got a primitive predatory intelligence, roughly comparable to that of a big spider (its products may be clever and complex, but its behaviour is not). If that's "rationality", we should probably consider setting the bar a bit higher for ourselves.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#142
post #31
post #21

Earlier quoted context omitted.

In order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in th…

But imagine, if he had told them a year ago, perhaps the locks would be mostly replaced with a fixed version by now! I think it's unbelievable that he wouldn't disclose this information because he "just knows" they wouldn't do anything. He's not a damn mind reader. Hell, he might even be right, but you've still got to give the company the chance.

May I suggest you read up on some more stories about disclosure in the security industry. There have been many, many people before him that wanted to give them that chance and they've been sorely disappointed, time and time again. Hell you don't even know if Daeken maybe gone through this route from, you know, his own experience?

Fool me once, shame on me, fool me twice, and I'm supposed to be a damn mind reader?!

Also see: http://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#143
post #36

Interesting, but it's not as if hotels in general have been high security installations. Very easy experiment: Just go to the front desk an thell them that you sadly seem to have lost your room card. 90% of the time they will just ask for your room number without requiring any kind of proof that it's actually your room.

Or there's those hotels where you have to leave the keys at the front desk. Each time you come back you say your room number and they give you the key.

Yeah, that was our hostel in NYC. I asked about that, and they kind of looked at me funny, as if I was paranoid or something. If figured the best way would be to semi-jokingly show her my ID regardless and be friendly and chatty in the hopes she'd remember my face with the room number.

In hindsight I might have tried asking for a different room number's key to see if she was paying attention and then quickly correct myself "No, just kidding, my room's 208 not 210. I just wanted to see if you'd give people any room key they ask for". Maybe that would've made them see the issue.

Instead, I took the easy route and made sure to never leave my netbook, passport, tickets, etc in the room (all the rest was replaceable and we were travelling light).

I would have probably done differently if I wasn't in a foreign country on a different continent and still getting used to the cultural uncanny valley of NYC being "almost, but not quite like Europe", so I opted for the safe choice of not being a bother to these obviously hard-working people.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#144
post #74
post #72

Earlier quoted context omitted.

Do you use Backtrack at all, or do you simply craft/download/build-from-source your own tools as you need them? Also, did you switch from Windows to Linux because of the available tools and development environment, or because the Linux desktop had matured enough you could get sh*t done without worrying about driver compatibility issues or other common complaints about Linux [lap|desk]tops?

I don't use Backtrack or similar tools; the only tools I use that I didn't write myself are IDA Pro and Burp Proxy (if I'm doing websec work). As for switching OSes, the primary reason I did so is that my work for my day job all requires Linux. In terms of reversing, Windows is really the only way to fly; the tools just aren't there otherwise.

> In terms of reversing, Windows is really the only way to fly; the tools just aren't there otherwise.

Curious, why is that, and what tools are those then?

Post reply on HN