Live data from Hacker News

Hotel-room hacks: Picking the lock

economist.com

41–50 of 71 posts

Re: Hotel-room hacks: Picking the lock

#41
post #21

Earlier quoted context omitted.

Latches will work, but 99.9% of doors with Onity locks will only have the deadbolt inside the Onity lock, which is vulnerable to the problem I detailed above. Just something to keep in mind.

No no you're missing the point I think. Nearly every hotel room has a big old manual separate bolt set up higher and away from key based locking system. Slides open maybe 2 inches etc. Twice in my life the hotel person has given my room to someone else by mistake (I travel a lot for work). That is, I'll be in there, twice late at night, and someone else puts in a key and it works. After the first time I always set th…

I think you're missing the point - Onity locks don't usually have this "big old manual separate bolt" as they're sold as "deadbolt inclusive".

Re: Hotel-room hacks: Picking the lock

#42
post #17
post #16

Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.

The deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the…

Does anyone actually assume hotels are secure (in a sense other than good faith) though? There are so many points for allocation errors on the cards themselves, dozens of "all-access" cards available to both internal and contracted staff, and different people in every room most nights (e.g. no neighbour familiarity about an issue).

Re: Hotel-room hacks: Picking the lock

#43
post #35

Earlier quoted context omitted.

can you expand on what would have made it rock solid?

Well, from what I know of its failures: - Use an industry-standard (for the time) crypto algorithm for cards, and use the biggest key size possible. As it stands, they use a (horrible) proprietary algorithm and 32-bit keys. - Make the lock know which door it's actually for and encode a list of acceptable lists along with the code key values on the card. This prevents a card from one door from opening another door. No…

You were planning to do a Reddit AMA on reversing in General.

Did that ever happen? Have you written anything on that?

Re: Hotel-room hacks: Picking the lock

#44
post #21

Earlier quoted context omitted.

Latches will work, but 99.9% of doors with Onity locks will only have the deadbolt inside the Onity lock, which is vulnerable to the problem I detailed above. Just something to keep in mind.

No no you're missing the point I think. Nearly every hotel room has a big old manual separate bolt set up higher and away from key based locking system. Slides open maybe 2 inches etc. Twice in my life the hotel person has given my room to someone else by mistake (I travel a lot for work). That is, I'll be in there, twice late at night, and someone else puts in a key and it works. After the first time I always set th…

You mean like one of these, right? http://cache4.asset-cache.net/xc/87800053-deadbolt-lock-and-...

Re: Hotel-room hacks: Picking the lock

#45
post #43
post #35

Earlier quoted context omitted.

Well, from what I know of its failures: - Use an industry-standard (for the time) crypto algorithm for cards, and use the biggest key size possible. As it stands, they use a (horrible) proprietary algorithm and 32-bit keys. - Make the lock know which door it's actually for and encode a list of acceptable lists along with the code key values on the card. This prevents a card from one door from opening another door. No…

You were planning to do a Reddit AMA on reversing in General. Did that ever happen? Have you written anything on that?

I did indeed -- http://www.reddit.com/r/IAmA/comments/yeiac/iama_reverse_eng...

It went better than I could've ever imagined; it was topping the front page for a while! Seriously awesome experience.

Re: Hotel-room hacks: Picking the lock

#46
post #17

Earlier quoted context omitted.

The deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the…

Does anyone actually assume hotels are secure (in a sense other than good faith) though? There are so many points for allocation errors on the cards themselves, dozens of "all-access" cards available to both internal and contracted staff, and different people in every room most nights (e.g. no neighbour familiarity about an issue).

Few people assume hotels are truly secure, but generally when something goes wrong, you have an accurate audit trail. That is, if someone breaks into room 413 using a legitimate card, I can go back and say "ok, Michael was the one who encoded this card for him, after the guest had already checked in". You can't do that with the opening device.

Re: Hotel-room hacks: Picking the lock

#47
post #29
post #4

Real engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board…

If these work like they used to - the connector is used to sync the lock with the key machines at the front desk. It requires a reprogram if the master keys need to change (ie someone is fired), batteries die in the lock, etc. Additionally it provides self test info and obviously if you need to force it open (i.e. Maintenance may send the open command in case of reader malfunction). That's why the mechanical solution…

Not sure why this was downvoted (was in the grey a moment ago). This is dead on.

Re: Hotel-room hacks: Picking the lock

#48
post #37

Earlier quoted context omitted.

Well for one thing less people would know about the flaw and potentially be able to take advantage of it.

That's called "security through obscurity," which isn't really security at all. It didn't prevent daeken from discovering the vulnerability, which means it's likely others with more malicious intent also know about it and are keeping the fact quiet. When the problem goes unpublished, unsuspecting customers will continue to trust the locks on their rooms. When published, customers can make more informed decisions abou…

No, it didn't prevent daeken and probably others from discovering it, but we can be sure it did prevent a lot of less competent people from exploiting it. "Security through obscurity" is still better than a big door with a sign saying "hack me!"

Re: Hotel-room hacks: Picking the lock

#49
post #16

Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.

> When you leave, take your valuables.

So I'm in a foreign land, and I should carry around all my worldly possessions with me?

How is that safer?

(Why can't the hotel provide a lock that works?)

Re: Hotel-room hacks: Picking the lock

#50
What can people do about it? barricade their hotel door? No, this is much more of help to people looking to get to other people and now they just got an extra option. This really opened a market.

If you really care about hotel customers you would be on the company side that made all these locks, because they really need help. Yes they screwed up, they deserve punishment but do the customers have to be the victim?

Post reply on HN