Live data from Hacker News

HN's Daeken will expose security flaw in 4m hotel room keycard locks

forbes.com

61–70 of 144 posts

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#61
post #54
post #53

Earlier quoted context omitted.

It's fairly easy to change a T-shirt. Whether or not anyone agrees with his appearance or not being relevant, he wasn't photographed in the audience at the conference or up on stage. He posed for a photograph in a hotel. Even if he didn't have a spare shirt, the gift shop in a hotel generally does. That's if he had thought of that issue. No problem with telling the photographer you had to change. Even if they noted t…

I did plan to wear the shirt; I felt it injected a bit of fun into something that, frankly, is scary as hell.

Forgive me if I'm just naive but I don't get the 'scary' part. Locks have always been 'advisory' and people who have wanted to circumvent them for both good and evil rate them by their 'time to disable'.

Hotel locks with hard keys had their issues as well, and were pretty trivially picked with simple tools. But the key is always that you need to bring the 'simple tools' which is to say that they aren't vulnerable in a way that someone who decides on the spur of the moment to enter the room can easily duplicate. They need the plug that fits the power cord, they need the software which does the JTAG wiggler etc etc.

So if it is 'scary' that people who are not affiliated with the hotel either as guests or as staff can, with pre-meditation, open a hotel room door without damage. Then you need to re-define scary. This has always been true, and will probably always be true by the nature of hotels and motels.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#62
post #35

Earlier quoted context omitted.

> But on three Onity locks installed on real hotel doors he and I tested at well-known independent and franchise hotels in New York, results were much more mixed This is a long shot, but I was in a chain hotel in midtown recently and heard someone tampering with the lock, and found the door ajar in the morning. I realize you probably can't name specific hotels, but was one by any chance a chain hotel in midtown aroun…

You don't lock the bolt or the chain mechanism when you stay in a hotel room? Or are you saying they bypassed those also?

I think the primary threat in this situation is burglary of an unoccupied hotel room.

Security chains are fairly easy to defeat; a bent clothes hanger will do. Deadbolts are probably pretty hard if there's no external key hole. Someone intending harm to the occupants of a hotel room might just break a window.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#63
post #33

Earlier quoted context omitted.

> what, exactly? They could plug the access holes, with custom pentalobe screws. That's an under a dollar per lock fix.

So, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.

Financial reports are typically in 1000s of dollars - UTX's net reported in 03/2012 were $330 million USD.

edit: source is http://finance.yahoo.com/q/is?s=UTX ('All numbers in thousands' in upper right of the statement). Easy mistake! I just happened to be passingly familiar with United Technologies, which is a large diversified industrial conglomerate that includes Carrier (A/C systems), Sikorsky (helicopters), and Pratt & Whitney (aircraft engines) among other subsidiaries.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#64
post #63
post #33

Earlier quoted context omitted.

So, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.

Financial reports are typically in 1000s of dollars - UTX's net reported in 03/2012 were $330 million USD. edit: source is http://finance.yahoo.com/q/is?s=UTX ('All numbers in thousands' in upper right of the statement). Easy mistake! I just happened to be passingly familiar with United Technologies, which is a large diversified industrial conglomerate that includes Carrier (A/C systems), Sikorsky (helicopters), and…

URL? I got mine from Google Finance, but only quickly eyeballed it; it's very likely you're right.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#65
post #54
post #53

Earlier quoted context omitted.

It's fairly easy to change a T-shirt. Whether or not anyone agrees with his appearance or not being relevant, he wasn't photographed in the audience at the conference or up on stage. He posed for a photograph in a hotel. Even if he didn't have a spare shirt, the gift shop in a hotel generally does. That's if he had thought of that issue. No problem with telling the photographer you had to change. Even if they noted t…

I did plan to wear the shirt; I felt it injected a bit of fun into something that, frankly, is scary as hell.

"did plan"

The most important thing was that you gave it thought in advance! That is good. You had your reason for wearing the shirt it might not be the same decisions others would have made but the decision is yours to make based on what you were trying to achieve.

By "scary" did you mean the media attention?

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#66
post #65
post #54

Earlier quoted context omitted.

I did plan to wear the shirt; I felt it injected a bit of fun into something that, frankly, is scary as hell.

"did plan" The most important thing was that you gave it thought in advance! That is good. You had your reason for wearing the shirt it might not be the same decisions others would have made but the decision is yours to make based on what you were trying to achieve. By "scary" did you mean the media attention?

I mean the vulnerabilities. While my exploit has issues (which, as far as I can tell, are issues with timing when reading data from the lock; I lose the first bit of every byte) it's only a matter of time before someone fixes that and has these rolling off the assembly line. All you need is a microcontroller, a resistor, and a connector; that scares me.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#67
duh? I'm sorry but low security systems like hotel rooms of course have wide vulnerabilities. The front desk will just give out keys based on trust since you don't have to register everyone staying in the room; they don't even have an audit trail if they wanted to use it.

Keyless entry cars are mostly crackable ... garage door systems are trivial, you can bump pin tumbler locks, many home security systems have no backup power. rfid skimmers are cheap and easy-to-use. almost every elock I've seen has the bus readily exposed on the outside (secured by a single screw at best).

There's at most 6 things I can think of that actually do not have trivial security issues.

If I knew I would become famous by informing the press that, for instance, a car model only has a handful of key patterns for millions of cars, I would have done it a long time ago, but I thought such things were just stupefyingly obvious.

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#68
post #8
post #4

I'm planning on doing a Reddit AMA for reversing in general -- as well as this work -- in the next hour or two, but if anyone has any questions I'll do my best to answer here. All I ask is no protocol details (paper and full code will be out tomorrow immediately following my talk) and no legal questions. Go wild. Edit: Since this thread has blown up a bit, we may as well just do it here for real. If you have any reve…

Random question: His former employer [..], sold the intellectual property behind Brocious’s hack to the locksmith training company the Locksmith Institute (LSI) for $20,000 last year. Are these guys "buying up" security flaws in locks similar to others who sell these kinds of things for software?

It's the Locksmith Institute. Locksmiths are who you call to get into a door to something own, but to which you lost the key. So presumably there's situations where a hotel can't get their keys working, and they'd like to have locksmiths in their city who are trained in this. Don't think it's any more complicated than that...

Re: HN's Daeken will expose security flaw in 4m hotel room keycard locks

#69
I think that making this public is not a very good example of responsible disclosure and I hope there will be a lawsuit before the presentation to prevent the details from being exposed.

I am all about exposing vulnerabilities but I honestly think there needs to be a dialog with the vendor first. Specially for exploits like this where there is a lot at stake.

I find the excuse of 'there is nothing they can do anyway' very poor. I have no doubt that this technique is known to locksmiths and law enforcement and maybe a smaller group of criminals. But making this public and exposing it to the world will allow any criminal with a soldering iron and an Arduino to start exploiting this.

Daeken, you have done an awesome job making this known. Maybe that it enough to get the ball rolling. Or do you just want to do damage for fame and profit?

Post reply on HN