Live data from Hacker News

Hotel-room hacks: Picking the lock

economist.com

1–10 of 71 posts

Re: Hotel-room hacks: Picking the lock

#2
> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time.

That seems like rather an asshole move on his part. I understand the argument for disclosing security flaws to force a reluctant vendor to deal with them, but in this case he didn't even give them a chance.

Re: Hotel-room hacks: Picking the lock

#3
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

Right, and mitigation doesn't necessarily have to take the form of fixing the electronics.

Re: Hotel-room hacks: Picking the lock

#4
Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity.

alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock.

1) De-solder the connector on the board and cut the traces/pads off the board - it won't stop everyone, but enough that have read of the exploit and try to follow through on it without applying any more critical thinking will be thwarted.

2) epoxy over the connector (they kind of did this with the security screw fix, but not really)

3) leave the connector, but add so much resistance between the connector and uP that you have to use a special interface cable to talk to the uP. no one will be able to tell until they pull the lock apart that its not stock.

Re: Hotel-room hacks: Picking the lock

#6
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

Don't shoot the messenger. The security hole was there for everyone to independently observe. Not telling the public just meant that the public couldn't take their own countermeasures.

Blaming security researchers for finding holes is a very strange anti-pattern. We should be blaming vendors for shipping insecure products!

Re: Hotel-room hacks: Picking the lock

#7
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

Even if you fix the vulnerability present in the lock firmware (which you can't do without replacing the Portable Programmer as well), the encryption on the cards is still completely broken.

I've written at length about how this can be fixed; Onity has not yet responded with an effective solution.

(I'm the original researcher)

Edit: Link to my post is here: http://daeken.com/onitys-plan-to-mitigate-hotel-lock-hack Note that their statement about how they would fix it was pulled after Forbes quoted my post.

Re: Hotel-room hacks: Picking the lock

#9
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

I've covered this a number of times. Simply put, I felt that the best route for hotel owners and customers (who I care about, unlike J. Random Vendor) was to make them aware of the vulnerability and make them aware that they've had a horribly insecure product on their doors for nearly 20 years. Given how ridiculously simple the vulnerabilities are, I'd put money on many others having discovered them in the past, almost definitely using them for malicious purposes. In addition, there's absolutely no way that Onity did not know about this themselves -- it would not have required digging, but been immediately obvious from the design of the system.

The route I took may not have been pretty, but it will get the issue fixed in a timely fashion, I believe, and hopefully alert people to the fact that we need real security processes in place around such things; not having your equipment audited in the case of a security product is simply not acceptable. Not now, and not in 1993.

Re: Hotel-room hacks: Picking the lock

#10
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

Hotels can't even get their internet right. Shit is outsourced to some service company who can't fix on-site problems with their routers, and you just get a shrug of the shoulders from hotel maintenance personnel. How in the unholy fuck do you think a Ramada Inn is going to roll out hundreds of modded door locks?
Post reply on HN