Live data from Hacker News

Hotel-room hacks: Picking the lock

economist.com

11–20 of 71 posts

Re: Hotel-room hacks: Picking the lock

#12
post #7
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

Even if you fix the vulnerability present in the lock firmware (which you can't do without replacing the Portable Programmer as well), the encryption on the cards is still completely broken. I've written at length about how this can be fixed; Onity has not yet responded with an effective solution. (I'm the original researcher) Edit: Link to my post is here: http://daeken.com/onitys-plan-to-mitigate-hotel-lock-hack No…

Yeah, this is what I found fascinating in your paper(http://demoseen.com/bhpaper.html). I had always wondered how they invalidated the old keys automatically.

Re: Hotel-room hacks: Picking the lock

#13
post #6
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

Don't shoot the messenger. The security hole was there for everyone to independently observe. Not telling the public just meant that the public couldn't take their own countermeasures. Blaming security researchers for finding holes is a very strange anti-pattern. We should be blaming vendors for shipping insecure products!

[deleted]

Re: Hotel-room hacks: Picking the lock

#14
post #7

Earlier quoted context omitted.

Even if you fix the vulnerability present in the lock firmware (which you can't do without replacing the Portable Programmer as well), the encryption on the cards is still completely broken. I've written at length about how this can be fixed; Onity has not yet responded with an effective solution. (I'm the original researcher) Edit: Link to my post is here: http://daeken.com/onitys-plan-to-mitigate-hotel-lock-hack No…

Yeah, this is what I found fascinating in your paper( http://demoseen.com/bhpaper.html ). I had always wondered how they invalidated the old keys automatically.

Out of curiosity, was that part clear? Writing the section on key rotation and lookaheads took me something like 4 days of editing, and I was never actually happy with it.

Re: Hotel-room hacks: Picking the lock

#15
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

[D]o some real enginerering and calculate the ADDITION of bits to set to disable the exploit.

That is very unlikely to be possible. The ROM may be a masked ROM, in which case it is not re-programmable at all. Quite likely it is a one-time programmable (OTP) ROM. For a OTP, at best you can flip "1" bits to "0", but you cannot change "0" bits to "1". It would take a large amount of luck to be able to patch "1"s to "0"s (and not need to change any "0"s to "1"s) to vector to patched code fixing the vulnerabilities.

In addition, many programmable memories require special programming voltages and they all need the proper control signals - very often the ROM is not in-circuit programmable or is in-circuit programmable only via a test/programming circuit at the factory, not in the field.

WRT #1 and #2, the reason for the connector is to allow the hotel staff to recover from Bad Things like dead batteries and confused/mis-keyed locks. I know I've been the victim of dead batteries more than once... if the only recourse is to destroy the lock to get into the room, the hotel is going to be very unhappy and the guest isn't going to be very pleased either.

#3 is "security through obscurity", which will be effective briefly until the next security researcher figures out how to defeat the change.

Re: Hotel-room hacks: Picking the lock

#16
Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables.

The easiest way into a hotel room is social engineering via the housekeeping staff.

Re: Hotel-room hacks: Picking the lock

#17
post #16

Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.

The deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the deadbolt, as it's disengaged by the lock mechanism when you turn the handle.

Re: Hotel-room hacks: Picking the lock

#18
post #9
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

I've covered this a number of times. Simply put, I felt that the best route for hotel owners and customers (who I care about, unlike J. Random Vendor) was to make them aware of the vulnerability and make them aware that they've had a horribly insecure product on their doors for nearly 20 years. Given how ridiculously simple the vulnerabilities are, I'd put money on many others having discovered them in the past, almo…

I appreciate your appearance here. One of the wonderful things about HN is that we often get the facts from the first party source.

I also agree about disclosure - it might have been nice to drop them a note beforehand, but what could they honestly do about it? Nothing more than they are already doing.

Re: Hotel-room hacks: Picking the lock

#19
post #10
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

Hotels can't even get their internet right. Shit is outsourced to some service company who can't fix on-site problems with their routers, and you just get a shrug of the shoulders from hotel maintenance personnel. How in the unholy fuck do you think a Ramada Inn is going to roll out hundreds of modded door locks?

They don't mod the locks, they call up Onity and say "send us 600 new locks that are not flawed." Onity replies "Sorry, no." Then they fight in court for the next 10 years over whether Onity owes the hotel replacement locks.

Assuming the hotel wins, Onity sends a team in to replace the locks (a relatively simple and already solved problem - that is how the original locks were installed). Then Onity sends the hotel the bill for the replacement service and the hotel says "Sorry, no." Then everybody fights in court over the retrofit bill for another 10 years.

Re: Hotel-room hacks: Picking the lock

#20
post #17
post #16

Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.

The deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the…

I think he is referring to a manually operated dead bolt or those latches at the top of the door. The locks that can only be set and unset from inside of the room.
Post reply on HN