3 ms·
My main problem with publications like this is that they are often sensationalized. This type of technology has been around for years and years, same with Casin
by Rotdhizon 8y ago
My main problem with publications like this is that they are often sensationalized. This type of technology has been around for years and years, same with Casino machine hacks. People who figured this out and developed the devices for it often only use them lowkey, because that's the smart thing to do. Then you have someone who finds out and pushes a news story about it, spinning it to be some massive breakthrough in the hacking world and we're all no longer safe behind hotel keycard locks. There was a documentary I watched a few years ago, maybe it was on netflix but I don't think so, but it was about a guy who figured out how to hack certain Hotel door locks and he abused that to his advantage for upwards of a decade. Why was he able to do this for so long? Because he didn't go running to the press when he figured it out, and to a larger extent because its extremely costly to replace the technology in an entire hotel(same as why companies get hit with malware that exploit bugs that should've been patch months/years prior).
That's not to discredit this team, I'm sure they are full of great people doing honest work.
- gabriel34 8y agoSo you advocate for stealth exploitation instead of disclosure?
- gg5ever 8y agoI didn't get that all from GP's comment. What makes you think they advocate that?
- Rotdhizon 8y agoEntirely missed my point, but other comments here summarize it way better than I did. The point is that this is nothing new, these types of attack vectors have been actively exploited for a very long time. If you are a thief, undercover agent, assassin, etc, you aren't going to disclose your methods. The people who know how, and do hack security measures like this keep it under wraps. I'm all for responsible disclosure, but that term only exists in the realm of ethical security. People who use these methods for malicious reasons are under no obligation to disclose what they do. So in turn, while the article makes it out to seem like this one company has hit a groundbreaking discovery, it's really not. Props to the guys at F-secure, but they are late to the game compared to the unethical realm of physical security hacking.