Live data from Hacker News

Hotel-room hacks: Picking the lock

economist.com

21–30 of 71 posts

Re: Hotel-room hacks: Picking the lock

#21
post #17

Earlier quoted context omitted.

The deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the…

I think he is referring to a manually operated dead bolt or those latches at the top of the door. The locks that can only be set and unset from inside of the room.

Latches will work, but 99.9% of doors with Onity locks will only have the deadbolt inside the Onity lock, which is vulnerable to the problem I detailed above. Just something to keep in mind.

Re: Hotel-room hacks: Picking the lock

#23
post #6
post #2

> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…

Don't shoot the messenger. The security hole was there for everyone to independently observe. Not telling the public just meant that the public couldn't take their own countermeasures. Blaming security researchers for finding holes is a very strange anti-pattern. We should be blaming vendors for shipping insecure products!

It's going to happen. Even with full care and diligence there will still be some products shipped with security flaws. It is not ethical to give the company no heads up, not even anonymously.

Re: Hotel-room hacks: Picking the lock

#24
post #14

Earlier quoted context omitted.

Yeah, this is what I found fascinating in your paper( http://demoseen.com/bhpaper.html ). I had always wondered how they invalidated the old keys automatically.

Out of curiosity, was that part clear? Writing the section on key rotation and lookaheads took me something like 4 days of editing, and I was never actually happy with it.

FWIW, I just read it and it was crystal clear to me.

Re: Hotel-room hacks: Picking the lock

#25
post #6

Earlier quoted context omitted.

Don't shoot the messenger. The security hole was there for everyone to independently observe. Not telling the public just meant that the public couldn't take their own countermeasures. Blaming security researchers for finding holes is a very strange anti-pattern. We should be blaming vendors for shipping insecure products!

It's going to happen. Even with full care and diligence there will still be some products shipped with security flaws. It is not ethical to give the company no heads up, not even anonymously.

For what it's worth, this isn't "some security flaws". The device itself allowed unauthenticated memory reads (as a matter of design -- it uses them), and the card crypto is done using a proprietary algorithm and a 32-bit key. It's not that there are security holes, it's that there are security Grand Canyons.

Re: Hotel-room hacks: Picking the lock

#26
>"I would like to point out that the '$30 microprocessor' in 2012 would have needed a refrigerator size computer 20 years ago when the Onity system was designed. Twenty years from now all of our current 'state of the art' security will be hackable with nothing more powerful than a 2032 edition pocket calculator."

Just read this comment on the site - perhaps a bit exaggerated, but I think a valid point nonetheless. Of course, Onity should have done something about the flaw.

Re: Hotel-room hacks: Picking the lock

#27

>"I would like to point out that the '$30 microprocessor' in 2012 would have needed a refrigerator size computer 20 years ago when the Onity system was designed. Twenty years from now all of our current 'state of the art' security will be hackable with nothing more powerful than a 2032 edition pocket calculator." Just read this comment on the site - perhaps a bit exaggerated, but I think a valid point nonetheless. Of…

Hah, I didn't see that comment on the story. It's funny, but it's completely untrue. The chip may have cost you $5 (rather than the $0.05 it costs now), but a PIC from 1993 -- when Onity released the HT locks, and they actually used for the locks themselves -- would've opened them just as well as a modern PIC/AVR/Propeller.

If someone didn't know about and exploit this flaw in 1998 (5 years later), I'd be downright flabbergasted. It's just way, way, way too simple.

Re: Hotel-room hacks: Picking the lock

#28
post #21

Earlier quoted context omitted.

I think he is referring to a manually operated dead bolt or those latches at the top of the door. The locks that can only be set and unset from inside of the room.

Latches will work, but 99.9% of doors with Onity locks will only have the deadbolt inside the Onity lock, which is vulnerable to the problem I detailed above. Just something to keep in mind.

No no you're missing the point I think. Nearly every hotel room has a big old manual separate bolt set up higher and away from key based locking system. Slides open maybe 2 inches etc. Twice in my life the hotel person has given my room to someone else by mistake (I travel a lot for work). That is, I'll be in there, twice late at night, and someone else puts in a key and it works. After the first time I always set that manual bolt no matter what - just in case. Not that I think there's any real merit to the original point that kicked off this particular thread.

Re: Hotel-room hacks: Picking the lock

#29
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

If these work like they used to - the connector is used to sync the lock with the key machines at the front desk. It requires a reprogram if the master keys need to change (ie someone is fired), batteries die in the lock, etc. Additionally it provides self test info and obviously if you need to force it open (i.e. Maintenance may send the open command in case of reader malfunction). That's why the mechanical solution doesn't involve physical changes to the lock guts - just the housing.

Re: Hotel-room hacks: Picking the lock

#30
post #10
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

Hotels can't even get their internet right. Shit is outsourced to some service company who can't fix on-site problems with their routers, and you just get a shrug of the shoulders from hotel maintenance personnel. How in the unholy fuck do you think a Ramada Inn is going to roll out hundreds of modded door locks?

How in the unholy fuck do you think a Ramada Inn is going to roll out hundreds of modded door locks?

'Internet' isn't their business - providing rooms, is.

But, really, this isn't a problem. The available maintenance staff takes care of it, or they have a local locksmith team spend a week at it.

Post reply on HN