Hotel-room hacks: Picking the lock
51–60 of 71 posts
Re: Hotel-room hacks: Picking the lock
#52Earlier quoted context omitted.
That's called "security through obscurity," which isn't really security at all. It didn't prevent daeken from discovering the vulnerability, which means it's likely others with more malicious intent also know about it and are keeping the fact quiet. When the problem goes unpublished, unsuspecting customers will continue to trust the locks on their rooms. When published, customers can make more informed decisions abou…
No, it didn't prevent daeken and probably others from discovering it, but we can be sure it did prevent a lot of less competent people from exploiting it. "Security through obscurity" is still better than a big door with a sign saying "hack me!"
Re: Hotel-room hacks: Picking the lock
#53Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.
Re: Hotel-room hacks: Picking the lock
#54Nothing is secure. I don't see how the electronic lock is any less secure than the glass used on most house windows. It's like saying glass manufacturers aren't making glass secure enough to protect home owners from intruders when someone can throw a piece of brick and smash it.
Re: Hotel-room hacks: Picking the lock
#55> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…
I've covered this a number of times. Simply put, I felt that the best route for hotel owners and customers (who I care about, unlike J. Random Vendor) was to make them aware of the vulnerability and make them aware that they've had a horribly insecure product on their doors for nearly 20 years. Given how ridiculously simple the vulnerabilities are, I'd put money on many others having discovered them in the past, almo…
You obviously knew about the flaw at least few days before your interview with Forbes (or whatever it was). Shooting a one-liner email to Onity was a no-brainer. "I found a major flaw in your locks. Contact me for details." They reply - great, they don't - fine, proceed as planned. I come from a reverse engineering background and I'm sorry to say but I have lost all professional respect for you, regardless of how good of a reverser you are.
Re: Hotel-room hacks: Picking the lock
#56> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing…
I've covered this a number of times. Simply put, I felt that the best route for hotel owners and customers (who I care about, unlike J. Random Vendor) was to make them aware of the vulnerability and make them aware that they've had a horribly insecure product on their doors for nearly 20 years. Given how ridiculously simple the vulnerabilities are, I'd put money on many others having discovered them in the past, almo…
You could have informed Onity first and then simply threatened them with full disclosure if they didn't start owning up to the problem themselves. You intentionally didn't do that. And the only good reason I can see for you not doing that is so you can get more publicity. It was a selfish decision on your part.
Re: Hotel-room hacks: Picking the lock
#57Are hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.
> When you leave, take your valuables. So I'm in a foreign land, and I should carry around all my worldly possessions with me? How is that safer? (Why can't the hotel provide a lock that works?)
Re: Hotel-room hacks: Picking the lock
#58Earlier quoted context omitted.
> When you leave, take your valuables. So I'm in a foreign land, and I should carry around all my worldly possessions with me? How is that safer? (Why can't the hotel provide a lock that works?)
Leave them in the hotel safe (many will give you one in your room) if you prefer. It just doesn't seem worth the hotel putting serious effort into the lock on the room door, because that's always going to be insecure, if only because the minimum-wage cleaning staff need access to all the rooms.
If the hotel wants to fit a lock that doesn't prevent easy access to my room, and my stuff gets stolen, they can meet my lawyer.
Re: Hotel-room hacks: Picking the lock
#59Earlier quoted context omitted.
> When you leave, take your valuables. So I'm in a foreign land, and I should carry around all my worldly possessions with me? How is that safer? (Why can't the hotel provide a lock that works?)
Leave them in the hotel safe (many will give you one in your room) if you prefer. It just doesn't seem worth the hotel putting serious effort into the lock on the room door, because that's always going to be insecure, if only because the minimum-wage cleaning staff need access to all the rooms.
The BLS says that the median wage for "Maids and Housekeeping Cleaners" is $9.32. Federal minimum wage is $7.25 per hour. Obviously then, most are not paid minimum wage.
In any case, people also want a long-term job. An aspect of keycard entry is that you have a record of what people entered the room. If only one person entered when something was stolen, then that person is a definite suspect, and may be fired. But if it's possible to circumvent that security, then it's also possible to frame others.
Re: Hotel-room hacks: Picking the lock
#60Earlier quoted context omitted.
Leave them in the hotel safe (many will give you one in your room) if you prefer. It just doesn't seem worth the hotel putting serious effort into the lock on the room door, because that's always going to be insecure, if only because the minimum-wage cleaning staff need access to all the rooms.
What's the point of mentioning minimum-wage here? Would your logic change if the staff weren't paid minimum wage? If you are staying at a hotel were the staff was paid above minimum wage, would you feel more secure? The BLS says that the median wage for "Maids and Housekeeping Cleaners" is $9.32. Federal minimum wage is $7.25 per hour. Obviously then, most are not paid minimum wage. In any case, people also want a lo…
Yes. Seriously, is that even a question? Wouldn't you?
Higher wages mean two things: the staff have more to lose by being fired, and by implication the hotel puts more effort into its staff. Which means they're probably recruiting more carefully and putting more effort into staff loyalty once they're there.