5 ms·
Bypassing Door Passwords
- sockpuppets 5y agoSource Code: https://github.com/aydinnyunus/gateCracker https://github.com/aydinnyunus/gateCracker https://github.com/aydinnyunus/gateCracker-REST https://github.com/aydinnyunus/gateCracker-REST
- htgb 5y agoI the blog post is preferable, as the linked page doesn't provide any context: https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995 https://sockpuppets.medium.com/bypassing-door-passwords-4004...
- sockpuppets 5y agothank you for response
- VeninVidiaVicii 5y agoSame. I clicked the link and thought I must’ve opened a wrong window.
- sockpuppets 5y agoI added source code and blog post links on the demo page.
- dang 5y agoOk, we've changed to that from https://share.streamlit.io/actuallytest/test2/main/main.py https://share.streamlit.io/actuallytest/test2/main/main.py. Thanks!
- zinekeller 5y agoActually an interesting article (for context: https://news.ycombinator.com/item?id=29850750 https://news.ycombinator.com/item?id=29850750), and demonstrates that locks are indeed only keeping honest people honest. Unfortunately, it seems that locks suffer from the dilemma of being low-cost enough while looking that it provides security.
- sockpuppets 5y agoBlog Post For the Research : https://sockpuppets.medium.com/bypassing-door-passwords-4004b8d7995 https://sockpuppets.medium.com/bypassing-door-passwords-4004...
- Nextgrid 5y agoA long time ago I was looking at security of contactless-related security systems such as door access control. The security is absolutely terrible for the most part; there was very little cryptography and the cryptography there was is often broken (by others that is - I don't have the skills to break it myself, I just looked at existing open-source tools), so seeing undocumented backdoor passwords is not surprising. The general feeling that I got is that outside of IT there's a lot of people who think "it's on a computer so it must be secure". Maybe that's technically true in the sense that it's secure because they have no clue how to use a computer and think that their idea of the difficulty of using one is enough security but obviously that's not the case. Many systems were (and are even today - the industry is very slow and physical security companies that are responsible for selling/installing these systems rarely have the skills to evaluate them) just based on an ID the keycard broadcasts unencrypted - there is no challenge response nor encryption, even when the keycard itself supported at least some crypto (Mifare Classic for example - that is broken but at least it would be an attempt at making it secure). Systems that use Mifare Classic would make you think that you'd need to break the crypto and copy the secret data from the card (which is possible and there are open-source toolkits to do it) but in reality you don't even need to bother as copying the UID (which is unencrypted and broadcast in the clear) is enough. Systems that use HID (which seems like it would be secure, if I remember right those use at least some form of cryptography) that I interacted with as a user (at a well-known tech company) used USB readers in what looked like keyboard emulation mode which "typed" the public UID of the card during provisioning. I am not sure if the actual readers on the doors did anything more (maybe the provisioning step just looks up a UID in a DB and doesn't technically need to be secure, as the readers will only use that UID to lookup a public key in the DB and then do proper authentication?) but there could be potential for a flaw too.
- meibo 5y agoA lot of RFID door openers also just use mechanical relays to power the locking mechanism, which can be triggered from outside with a strong magnet. In the end it probably depends on what your threat model is. To keep out thieves, most of them are probably unsuited.
- 5y ago
- egberts1 5y agoAs an alternative, I find Lockly to be an awesome asset for my household. I regularly hack my Lockly locks via Bluetooth and wireless. It’s holding up pretty good. https://lockly.com/ https://lockly.com/
- netizen-936824 5y agoHow secure is their fingerprint reader? More secure than the ones on mobile decides I hope?
- egberts1 5y agoeveryone that walked through the front door has been asked at least once to try the fingerprint mechanisms (as an unregistered finger) and failed (zero false positive). Unfortunately, my wife’s fingerprint is scrubbed shallow from excessive hand washing and gets a false negative quite often. Otherwise, one has to remember the orientation and angle of finger consistently to get near 100% of the time. And experience gets you there. The part that I like best is the number pad gets scrambled each time you pressed a key while entering in your digits (4 to 8 digits): the glass plate would then offer no clue as to what are the most frequent positions are. Furthermore, any shoulder surfer would be thoroughly stymied by a set of three digits to each of the keypad positions (of which one of the 3 digits has the correct digit, other two got randonly chosen).
- vizzah 5y agoyou regularly attempt to hack? and they're holding up? or you regularly manage to actually hack them? In such case how this asset can be awesome? =)
- egberts1 5y agoI hack without a key and i get rebuffed in all my attempts. I hack with my KNOWN keys (which gets scrambled) to get in.
- ThePowerOfFuet 5y agoThe weak spot on those is the shitty pin-tumbler cylinder, which you can bypass in seconds.
- yeldarb 5y agoThis makes me nostalgic. The first homebrew app I ever released[1] helped you pick combination locks with the help of your Playstation Portable. Looks like the original site that described the algorithm is long dead, but the gist was that once you have the first number from a Masterlock (which you can listen for) the search space of the second two can be reduced with a pretty simple algorithm and so there are only a few dozen combinations to try. [1] http://forums.qj.net/psp-development-forum/7427-release-psp-ick-v-2-a.html http://forums.qj.net/psp-development-forum/7427-release-psp-...
- Fatnino 5y agoIt's actually the last number. It's found by pulling the shackle and noting where the dial sticks. There will be several places but one stands out from the rest and is the last number. Then the last number mod 4 is equal to the first number mod 4 while the middle number mod 4 is ± 2 from the others. This reduces the search space to 100 possibilities to be brute forced in a few minutes.
- oolonthegreat 5y agoneato. must be noted that these locks are used in almost all apartment entrances in Turkey.
- ipiz0618 5y agoNever knew streamlit now has a cloud sharing platform. The UI has improved so much as well
- Mountain_Skies 5y agoAm I the only one who thought about BBSes when seeing the headline?
- cardiffspaceman 5y agoYou are not