Hotel ransomed by hackers as guests locked in rooms
thelocal.at
thelocal.at
For me it's :
A - It's the hacker that contacted RT with the story
B - It's part of a fearmongering campaign to ransom hotels
C - It's fake news written by an intern
[0] https://www.google.at/search?hl=de&gl=at&tbm=nws&authuser=0&...
http://kaernten.orf.at/news/stories/2821290/
Regarding the "locked in" issue; this article doesn't say anything like that:
"Die Gäste kamen nicht mehr in die Hotelzimmer, neue Schlüssel konnten nicht mehr programmiert werden."
"The guests could no longer enter their hotel rooms, new keys could no longer be programmed."
(Which doesn't work with any electronic hotel door lock I've seen so far anyway)
Though the laws are surely quite similar.
Both for evacuation in case of fire (a guest might be unconscious in a room) or in the case of a medical emergency (a guest might call down and complain about chest pain, and pass out before opening the door).
Can a malicious agent actually prevent previously working key cards from working (during the guest's stay - I know there is a time limit encoded on the key cards) or just prevent new cards from being programmed?
I have had that happen to me, and at least in that instance nobody had to come and reprogram the lock.
"We were hacked, but nobody was locked in or out," the
hotel's Managing Director Christopher Brandstaetter told
Bleeping Computer. "For one day we were not able to make
new keycards."Prosecute a CEO or 2 from tech companies for criminal negligence, and you will see companies actually investing in actual security. Put some business school graduates in a jail cell on criminal charges for their hiring and corporate practices, which would be criminal negligence if they were building bridges or doing any sort of work in any other industry.
Hiring the cheapest, least experienced engineers you can find, not even mentioning the word security on your job listing requirements for software or hardware design engineers, depriving the engineers of the time, tools, and environment they need to do competent work, putting business concerns ahead of engineering concerns when determining product development schedules, etc are things that executives should be judged in a court of law for. They are criminal acts that put not just money in jeopardy but frequently lives.
Document your thinking, sign off of it and upload it to some authority. It should be that easy, and when something bad happens take that document and let's review.
And if there is self-assessment questionnare and you went through the checkboxes and signed off of it and uploaded it, but you acutally did jack shit nothing at all, then you're liable.
It's not a hard ethical quagmire, it's best practices, it's 80-20, and we're currently at somewhere like 5-95.
Be careful what you wish for though. In many industries, releasing product requires getting explicit permission from government regulators based on trials/plans/etc. often assembled at considerable effort by licensed engineers and others.
This explosion of ransoms is getting nastier and nastier. It appears to have no end. Bitcoin's block chain has been stalled at 1mb blocks for a year now, it isn't adding users and their plans to make it scale aren't implemented. At what point do the political winds shift and the cost/benefit ratio of keeping Bitcoin around, at least in the USA, tips over to cost > benefit?
I don't want to see Bitcoin exchanging sent underground in the west, but it's clear that community has no intention of getting ransomware under control.
And yes, to a degree it's their responsibiltiy too to solve this, but the dominant share of the responsibiltiy is not really on them, it's on the various service providers that don't care about IT security, yet meddle with IT.
I don't think anyone should go to jail, like pretty much ever (let me pay a fine or kill me rather than lock me up), but I don't see a reason why whoever set this up, for example, shouldn't be held liable in the same way a doctor is liable with malpractice insurance to cover it.
It seems it'd fit the US laws very well, tech companies would buy insurance policies that'd pay out when their shit software or infrastructure is hacked.
Huge companies like Google or Apple could self insure.
That'd also give some incentive to the MBA's to take security seriously, as proving they take the extra steps would lower their premiums.
Usually, this isn't a problem because we deal with this through law enforcement, but law enforcement is very difficult and expensive on the internet, particularly now that you can accept payment in bitcoin.
The reason we have insecure systems is because we deal with systems that require constant vigilance to make sure we do not make mistakes in the face of adversaries. This doesn't scale for users and this doesn't scale for developers either.
There are certainly people who take security more and less seriously, and this would definitely move the needle on that, but I am not really sure it would move the needle on actual security, since actual security is hard.
Say good bye to startups if criminal negligence becomes a thing.
A guest at that hotel should be able to ask for a refund or sue the hotel for damages (to their time, their trip?), esp. if it was found the hotel didn't take basic steps to secure the card keys (like separating that system from the internet). The hotel should be able to sue the key manu system if they didnt keep their system safe.
I stayed in a hotel in Canada recently and their card key system was not on the internet - you had to type in the room number on a keypad. That seems fraught with potential for wrong number or time, but it also keeps that from getting infected from the internet.
Oops.
Our emergency exits were old-fashioned analog doors and still worked, at least.
That said, there should be exclusions to such rules for prisons or other areas that are designed to contain people. Some areas need secure doors.
I'm just pointing out the flaw in that statement taken literally.
In theory, in the event of a failure, the guards should still be able to open the cells to release people. I wasn't advocating for fail-impossible-to-open-doors.
I have a key, but I did not know the one deadlock has a different key for the inside and outside.
While this may be fine for high-security bank vaults, it is completely unacceptable for hotel room doors to operate in a fail-secure mode without a backup non-electrical unlocking mechanism as is the case here.
Locked in on their own volition, essentially. I've traveled a little bit, and I've yet to stay in a hotel that you needed anything electronic to exit.
According to the article this was not the first attempt to breach their security, yet they didn't put sane security practices in place, such as separating door lock controls from their internet connected network or not having door locks that can lock guests in in the first place, which, as pointed out in other comments, is likely not compliant with regulations.
> The manager said it was cheaper and faster for the hotel to just pay the Bitcoin.
Cheaper for him, but the cost will be beared by society as he has now encouraged the practice.
I understand that my comment can be seen as victim-blaming, but it seems to me that part of the service sold by an hotel is the security they procure to their guests.
Perhaps white (grey?) hats should run a series of ransom hacks and proceed not to release the code after payment.
(This will not just mean a network to VPN into, but physically separate, with no device-intermingling.)
I don't think it's about "best practices" or any sort of dogma, but more of a common-sense evaluation: do you really need your lock systems accessible from anywhere on the planet, which connecting to the Internet enables?
Building on TCP/IP is just fine (in-fact recommended) -- just keep that network physically isolated to the location it's implemented at.
> The manager said it was cheaper and faster for the hotel to just pay the Bitcoin.
Even better if the guy tries to hide it out of fear of being fired for incompetence - which is the general way these things go.
Any good parasite knows not to disturb the host system too much.
Especially with the standard policy of "we do not negotiate". That policy is really hard to justify when the amount is so small compared to the damage of delaying payment.
Now ... if only I could think of, say, some geopolitically significant hospitality enterprise, possibly with widespread or global operations, against which such a proven attack might be of interest.
Besides the argument of picking a sum that makes it relatively easy for a business to cough up, this is 1500 EUR tax-free. https://en.wikipedia.org/wiki/List_of_European_countries_by_... lists average net monthly income in Austria as 2000 EUR; pull something like this off twice a month and you're doing fine.
"I see numerous emerging synergies..."
https://plus.google.com/104092656004159577193/posts/PtsQrhF8...
Hopefully the local fire chief has shut the hotel down.
Anyway, at least in some countries, this is pretty common. Not that's it good. But, common? Yes.
> Yet according to the hotel, the hackers left a back door open in the system, and tried to attack the systems again.
I think that answers probably why the ransom was only a 1K EUR or so. It was turning to be into some kind of a rent or protection scheme.
The problem here is this is the kind of constant battle that may not be economically viable for most.
IOT is a deadend without better architecture, these devices cannot be in the open internet and vulnerable to hijacking. Those working on these systems may think otherwise but once businessess are disrupted and have to pay a price they will not use the technology. How many businesses can justify spending more and more resources on security, consultants and fighting off extortionists.
I feel sorry for those who were caught up in this through their stay, but I feel no sympathy for any company that ties their door locks to a vulnerable, non-isolated network.
I have to wonder if they considered breaking down the doors with a fire axe... if they were booked, would replacing the doors outweigh the cost of the ransom?
You realize it would have been a contractor who installed the systems? This is a single, family-run hotel. I suspect the incompetent contractor was unable to properly fix the systems after the first request, and the hotel didn't have the experience to confirm the fix.
[1] https://media.blackhat.com/bh-us-12/Briefings/Brocious/BH_US...
Hotel rooms that can't be opened from the inside should be strictly verboten!
Edit: That is, unless that part of the story is #clickbait, #fakenews.
So we go from a poorly secured internet connected security system to physical keys, any chance they could consider the common sense air gaped medium instead as the permanent solution?
"Cryptocurrency" is a large set of currencies, each of which work differently. Also, Bitcoin is a public log. It's much easier to trace bitcoin than to trace cash.
not true if the traders are cautious with their IPs and use bitcoin laundering services so others can't infer from the transaction graph.
That's true, which is why the sentence you quoted said "the way THE cryptocurrency works", not "the way cryptocurrency works". The "the" is a back-reference to the particular cryptocurrency that is being discussed here (Bitcoin). This differentiates it from a general statement about all cryptocurrencies.
"Hotel management said that they have now been hit three times by cybercriminals"
"we had no other choice. Neither police nor insurance help you in this case."
Do they not see the problem here? Perhaps they should have paid the thousands of euros to a security expert to fix their crappy system, rather than paying the hacker to do the same thing again.
(Of course, they're also a piggy bank every time the hackers need cash.)
(This assumes the hackers aren't, say, hotel management or employees skimming the operation themselves via hack threats, say, for money laundering purposes.)
Build your cities on
the slopes of Vesuvius.
--Nietzsche