9 ms·
Hotel-room hacks: Picking the lock
- tzs 14y ago> The hacker did not explain the flaw to the company in advance of revealing it to the public, a decision he told Forbes was because he saw "no path to mitigate this from Onity's side." To fix the problem, the locks' entire circuitboard has to be replaced—and on millions of locks, that's a process that could take a long time. That seems like rather an asshole move on his part. I understand the argument for disclosing security flaws to force a reluctant vendor to deal with them, but in this case he didn't even give them a chance.
- dllthomas 14y agoRight, and mitigation doesn't necessarily have to take the form of fixing the electronics.
- jrockway 14y agoDon't shoot the messenger. The security hole was there for everyone to independently observe. Not telling the public just meant that the public couldn't take their own countermeasures. Blaming security researchers for finding holes is a very strange anti-pattern. We should be blaming vendors for shipping insecure products!
- deleted 14y ago[deleted]
- sopooneo 14y agoIt's going to happen. Even with full care and diligence there will still be some products shipped with security flaws. It is not ethical to give the company no heads up, not even anonymously.
- daeken 14y agoFor what it's worth, this isn't "some security flaws". The device itself allowed unauthenticated memory reads (as a matter of design -- it uses them), and the card crypto is done using a proprietary algorithm and a 32-bit key. It's not that there are security holes, it's that there are security Grand Canyons.
- jrockway 14y agoYou're assuming that the security researcher is the first person to discover the issue. That's rarely the case. Keeping quiet just gives users a false sense of security and ensures that they can't mitigate the security impact on their own (without the help of the vendor). Knowledge is power. We shouldn't censor ourselves because someone somewhere can be evil with some information. They have other ways of getting the information anyway.
- tzs 14y agoThe following is meant to be general, rather than about this particular case. Assuming the goal is to minimize harm, then when to disclose depends on an interplay of several factors. Here are some of them: 1. How many people will discover and exploit the flaw on their own if it is not publicly disclosed. 2. How many people will exploit it if they find out about it, but will not discover it on their own. 3. How fast knowledge of the flaw will spread to the people of #2 without public disclosure. E.g., through word of mouth in hacker or researcher circles. 4. How many users of the flawed system will be able to use knowledge of the flaw in order to protect themselves from the people of #1 and #2. 5. How long the flaw will remain available. 6. How lessons from this flaw will teach others to build more secure systems. Disclosure affects #2 (disclosure increases harm), #4 (disclosure decreases harm), sometimes #5 (disclosure might push a vendor to action), and #6 (disclosure decreases harm).
- huggah 14y agoWhat purpose does this serve? In general, I agree with you, because most vulnerabilities can be fixed by the vendor in some reasonable (<6 months) amount of time, and by telling the vendor about the vulnerability beforehand, you help reduce the window where the attack can be easily exploited. This is not such a case; the vendor had no reasonable way of fixing this. Others had probably already discovered (and used) this vulnerability, and in the long term fixing this vulnerability quickly requires motivating the company to do so. Disclosing it privately wouldn't have held much benefit, and might have been detrimental (the company may have tried to use legal means to prevent or penalize the public disclosure).
- daeken 14y agoI've covered this a number of times. Simply put, I felt that the best route for hotel owners and customers (who I care about, unlike J. Random Vendor) was to make them aware of the vulnerability and make them aware that they've had a horribly insecure product on their doors for nearly 20 years. Given how ridiculously simple the vulnerabilities are, I'd put money on many others having discovered them in the past, almost definitely using them for malicious purposes. In addition, there's absolutely no way that Onity did not know about this themselves -- it would not have required digging, but been immediately obvious from the design of the system. The route I took may not have been pretty, but it will get the issue fixed in a timely fashion, I believe, and hopefully alert people to the fact that we need real security processes in place around such things; not having your equipment audited in the case of a security product is simply not acceptable. Not now, and not in 1993.
- jaggederest 14y agoI appreciate your appearance here. One of the wonderful things about HN is that we often get the facts from the first party source. I also agree about disclosure - it might have been nice to drop them a note beforehand, but what could they honestly do about it? Nothing more than they are already doing.
- larrys 14y agoWell for one thing less people would know about the flaw and potentially be able to take advantage of it.
- saturdayplace 14y agoThat's called "security through obscurity," which isn't really security at all. It didn't prevent daeken from discovering the vulnerability, which means it's likely others with more malicious intent also know about it and are keeping the fact quiet. When the problem goes unpublished, unsuspecting customers will continue to trust the locks on their rooms. When published, customers can make more informed decisions about where to stay.
- K2h 14y agoReal engineered solution - without new hardware: If this thing is not reprogrammable, and only has an EPROM - do some real enginerering and calculate the ADDITION of bits to set to disable the exploit. Thats the one I would be working on if I worked for Onity. alternativly, take a mechanical approach to the problem - if you can live without the connector for servicing the lock. 1) De-solder the connector on the board and cut the traces/pads off the board - it won't stop everyone, but enough that have read of the exploit and try to follow through on it without applying any more critical thinking will be thwarted. 2) epoxy over the connector (they kind of did this with the security screw fix, but not really) 3) leave the connector, but add so much resistance between the connector and uP that you have to use a special interface cable to talk to the uP. no one will be able to tell until they pull the lock apart that its not stock.
- daeken 14y agoEven if you fix the vulnerability present in the lock firmware (which you can't do without replacing the Portable Programmer as well), the encryption on the cards is still completely broken. I've written at length about how this can be fixed; Onity has not yet responded with an effective solution. (I'm the original researcher) Edit: Link to my post is here: http://daeken.com/onitys-plan-to-mitigate-hotel-lock-hack http://daeken.com/onitys-plan-to-mitigate-hotel-lock-hack Note that their statement about how they would fix it was pulled after Forbes quoted my post.
- markpercival 14y agoYeah, this is what I found fascinating in your paper(http://demoseen.com/bhpaper.html http://demoseen.com/bhpaper.html). I had always wondered how they invalidated the old keys automatically.
- daeken 14y agoOut of curiosity, was that part clear? Writing the section on key rotation and lookaheads took me something like 4 days of editing, and I was never actually happy with it.
- waterlesscloud 14y agoPrevious discussion here: http://news.ycombinator.com/item?id=4281722 http://news.ycombinator.com/item?id=4281722
- jgannonjr 14y agothe code and paper: https://github.com/daeken/LockResearch https://github.com/daeken/LockResearch
- daeken 14y agoMind changing it over to http://daeken.com/blackhat-paper http://daeken.com/blackhat-paper please? I keep failing to keep the git repo up to date (been way too busy).
- ams6110 14y agoAre hotel room locks really that big a target? If you're in the room, set the deadbolt. When you leave, take your valuables. The easiest way into a hotel room is social engineering via the housekeeping staff.
- daeken 14y agoThe deadbolt doesn't do anything with this, for what it's worth. The deadbolt on Onity locks is software-controlled; that is, there's a privacy switch that's triggered when you throw the deadbolt, and it checks the value of that when you put in a card. If you use a card with the 'privacy override' flag, or you use the Portable Programmer (or my opening device), the lock opens regardless of whether or not you use the deadbolt, as it's disengaged by the lock mechanism when you turn the handle.
- montecarl 14y agoI think he is referring to a manually operated dead bolt or those latches at the top of the door. The locks that can only be set and unset from inside of the room.
- daeken 14y agoLatches will work, but 99.9% of doors with Onity locks will only have the deadbolt inside the Onity lock, which is vulnerable to the problem I detailed above. Just something to keep in mind.
- jusben1369 14y agoNo no you're missing the point I think. Nearly every hotel room has a big old manual separate bolt set up higher and away from key based locking system. Slides open maybe 2 inches etc. Twice in my life the hotel person has given my room to someone else by mistake (I travel a lot for work). That is, I'll be in there, twice late at night, and someone else puts in a key and it works. After the first time I always set that manual bolt no matter what - just in case. Not that I think there's any real merit to the original point that kicked off this particular thread.
- kanzure 14y agoI once worked with Cody (daeken) when he was reverse engineering the Emotiv EPOC headset, he's definitely top notch. It turns out he does other things: http://demoseen.com/portfolio/ http://demoseen.com/portfolio/
- jliechti1 14y ago>"I would like to point out that the '$30 microprocessor' in 2012 would have needed a refrigerator size computer 20 years ago when the Onity system was designed. Twenty years from now all of our current 'state of the art' security will be hackable with nothing more powerful than a 2032 edition pocket calculator." Just read this comment on the site - perhaps a bit exaggerated, but I think a valid point nonetheless. Of course, Onity should have done something about the flaw.
- daeken 14y agoHah, I didn't see that comment on the story. It's funny, but it's completely untrue. The chip may have cost you $5 (rather than the $0.05 it costs now), but a PIC from 1993 -- when Onity released the HT locks, and they actually used for the locks themselves -- would've opened them just as well as a modern PIC/AVR/Propeller. If someone didn't know about and exploit this flaw in 1998 (5 years later), I'd be downright flabbergasted. It's just way, way, way too simple.
- Freestyler_3 14y agoWhat can people do about it? barricade their hotel door? No, this is much more of help to people looking to get to other people and now they just got an extra option. This really opened a market. If you really care about hotel customers you would be on the company side that made all these locks, because they really need help. Yes they screwed up, they deserve punishment but do the customers have to be the victim?
- DigitalSea 14y agoNothing is secure. I don't see how the electronic lock is any less secure than the glass used on most house windows. It's like saying glass manufacturers aren't making glass secure enough to protect home owners from intruders when someone can throw a piece of brick and smash it.
- cheald 14y agoCrappy comparison. Glass is installed for aesthetics, not security. Locks are installed specifically to keep people out. Windows are a known and accepted security hole that often have additional security measures attached to them.
- DigitalSea 14y agoHow about glass in general? Glass in police vehicles, glass in a police station, court house... Glass isn't a purely aesthetic material, it has many uses.