Hackers found a way to open any of 3M hotel keycard locks
wired.com
wired.com
Many of the installed devices are not properly maintained, even if the manufacturers continue to support them, because you have to pay for maintenance. In addition, not all equipment can be updated remotely over the network or even have a network connection to do so remotely.
Even if your cards are encrypted, it still can't guarantee you protection, because in most cases card readers are connected to controllers (not in the case of all-in-one devices like this lock) via Wiegand protocol, which doesn't provide any data encryption, so the identifier ID is transmitted over two wires in the clear form.
How many browsers do you think support the TLS_NULL_WITH_NULL_NULL cipher?
A secure system would involve a PKI which increases complexity and management overhead significantly (you won't be able to just copy "passwords" from one system to another, etc).
This is just some faceless corp being cheap and ignoring the consequences, not their problem.
There should be. Also there should be liability for access control system customers for choosing low cost, insecure solutions. But just like in the InfoSec world, there are simply no consequences to companies that cheap out and fail at security. These companies just issue a press release saying “we take security very seriously” and continue on with their business.
Essentially every time I've stayed in a hotel with contactless keycards (usually in a group needing 3-5 rooms for 2-3 nights) at least one person has needed to get a keycard reissued.
What's up with that? My workplace's smartcards and my contactless bank cards keep working for years on end.
There are two types of magnetic stripe cards available: High-coercivity (HiCo) and low-coercivity (LoCo). The field-rewritable kind used in hotels is usually LoCo, to make the writers smaller and cheaper. But that also makes the cards much more prone to accidental corruption by magnets you might have on you, like earbuds, magnetic wallets etc.
Bank cards are usually only ever programmed once (these days), i.e. when they're issued, so they're usually HiCo, making them much more robust against that. In addition to that, magnetic stripe usage has been phased out for payment cards in most countries and is getting rare even in the US, so for all you know, and depending on where you live/shop, your magnetic stripes might have already been demagnetized without any adverse effects!
Bonus trivia question: Guess which kind NYC MTA Metrocards are :)
Edit: Oh, I just saw that you asked about contactless keycards! For these I actually have no idea, and I haven't had one fail on me yet.
I just know that they often use a similar scheme ("works for rooms x, y, z, until timestamp n"), sometimes with a bit of cryptography on top (often with a single shared key across all instances of the same lock and even across hotels...) but using non-networked locks, so there can definitely be synchronization/propagation issues too.
That is just bad management. The whole point of the interior deadbolt lock in a hotel room door is so no one can accidentally walk in on you thinking it is an empty room.
An emergency keycard that can open a hotel room locked from the inside is only supposed to be kept at the front desk for use during an emergency, mostly by police or firefighters so they do not break down the door and cause tens of thousands of dollars of damage. And its presence and use should be constantly accounted for.
> cause tens of thousands of dollars of damage
This is surely overstated. I am sure firefighters are trained to do the least amount of damage when forcing a hotel door open. I guess a handheld electric saw could do the trick in less than one minute.The cops or firefighters are not going to spend time cutting, they are going to bust it open with a battering ram which will ruin everything, requiring reframing, new door, new thresholds, new frames, new locks ($2k), and maybe flooring too.
And then add in opportunity cost from not being able to rent the room during repair, which would take weeks due to those materials not being available at Home Depot.
I would budget at least $10k, and I bet it would not exceed $20k, but either way, using a battering ram on a hotel door is very costly.
I don't see the connection. The Mandalay Bay incident was an emergency, and the door was forced. What needed to change?
In any case, I would classify a guest refusing to open the door for a room check as outline in the rental agreement as an emergency (which should simply state once every x days or per management’s discretion).
It could be up to hotel management to go in without police, but I would certainly not give any line level employee an emergency key card to carry around at all times for that scenario. And I would also expect a manager to take on that task themselves.
They told me couldn't whistle and spin the crowbar nonchalantly before casually popping open doors that had a dead battery in front of the guest waiting to stay in that same hotel.
What were the improvements over "crowbar classic"?
If the reader had a decently secure channel to the central auth piece, then it shouldn't (in theory) matter how simple or complex the id would be. (?)
That’s very often not the case, though, especially in retrofitted installations.
Locks are sometimes offline and even battery powered (and I suspect they can even report a dying battery to the front desk by setting the appropriate flag on keycards as they’re being read).
None anymore! They're being phased out as we speak. They were supposed to be end of life last year, though they pushed back end of life EoY 2024, because the MTA is never on time, all the time.
The Metrocard is actually a quite elegant and resilient/decentralized system, given the technology that was available when it was introduced. OMNY depends on a network connection being (almost) always available.
It was programmed incorrectly and expired before it should have.
The stay was extended but the key was not updated with the new departure date.
A new key was erroneously issued for the room, someone used the new key to go into the room, saw someone was already staying in the room, and had to get keys for a different room. This would cause all old keys to stop working since every time a lock sees a new key used, it assumes a new hotel guest is staying.
Or it lost its data for whatever reason.
Given a need for multi-sentence items within a series, I go for bullet points. Hyphen character to start each point if no rich UL formatting is available.
It is true, seems like probably better to go back to keys and lock.
I'm much more worried about someone using to a clothes hanger looking tool [1] to break into my hotel room than someone exposing cables and reading data over the wire to unlock the door.
It took a journalist and a lot of e-mails and calls for my landlord to understand the problem, I suspect that Scantron were also downplaying the issue towards them. They finally budged and upgraded all the locks to use a better encryption scheme and re-issue keys.
My building have 197 apartments, each of them have at least 2 keys, I have to trust all of the tenants (and their friends), in order for my apartment not to get burgled, and if I were burgled my insurance wouldn't cover because there's likely no proof of entry.
I think landlords have to give you notice before entering your unit in most areas.
Swapping locks is maybe a ten minute job (probably less if you've done it a lot).
There's nothing to stop a tenant from swapping out the locks, then swapping the landlord's locks back in before a scheduled visit.
...And you might also get to pay for the water/fire damage to other appartments because it took longer to get into the appartment due to something you did.
1) the landlord didn't change the locks between tenants AND there's a great "key copying conspiracy."
Or
2) There's an emergency requiring your landlord/maintenance to enter the premise when you aren't home.
I know which one I find more likely, but you do you.
OTOH Probably most landlords won't mind you changing the locks as long as you give them a copy of the key.
I have changed the locks everywhere I have rented.
In my country, a landlord have zero right to access a rented property. Even keeping a copy of the key is forbidden. Emergencies are for firemen and police and they basically don’t care about your lock if you don’t answer.
The only way they would ever find out is if they were trying to enter your place unannounced.
People need to feel safe in their own homes.
So I had to put the old cylinder back in, because of condo rules about the property management company needing keys.
(Though I later learned that the property management company might not have been able to find my unit's key if they ever wanted to. One day, the fire department was at the building, trying to get into a different unit, which had an alarm sounding, but they found that the key box was empty. I was there, so I called the management company, but they refused to send a runner with the key. Even after I handed my phone to the firefighter in charge, and he identified himself and asked them again. :)
My fob copy still works there last I checked...
If setting out to find a vulnerability, how do you get started?
What is the “open ide, write print(“hello world”)” for this kind of work?
I would assume reading the cards with a reader would be a great start.
"Note that this information only applies to dormakaba Saflok systems; several other lock manufacturers use MIFARE Classic keycards and are not affected by the Unsaflok vulnerability"
So it is likely they way that Saflok implemented MIFARE Classic. Will start to read about this protocol more.
There are very fast card-only cloning attacks against even the newest "hardened" cards, and in many of these lock systems (no idea about Saflok in particular though), MIFARE is the only layer of cryptography, and the card only contains a bitmask of locks/doors that it should be able to open.
That's the model they already use for bank (credit and debit) cards too, so they need the backend to manage a deferred account-based system anyway. That's also what the MTA in New York does: They've never supported stored-value cards, and their new physical OMNY cards are effectively just a weird type of closed-loop EMV payment card.
Do you mean for MIFARE Classic or for all RFID cards? I was not aware of any cloning attacks for types such as HID Seos.
The only question is whether they do some hacker shit, or whether they just go to reception and say "My keycard isn't working, I'm in room 123" and reception gives them a new keycard for room 123, with no ID check and no questions asked.
Luckily thieves are relatively rare and 97% of hotel rooms just contain a suitcase of second-hand clothes.
In my experience, keycards fail so often that the hotel workers don't bat an eyelid when you say your card has failed, they just make you a new one.
While I'm sure some hotels (maybe more upscale ones?) do verification, it is far from universal in the USA.
Thanks for doing this. Hopefully, you guys expose all other lock companies.
That’s a pretty serious vulnerability, pretty much all it takes is to be a guest at a hotel
Did Dormakaba not make this a first-priority, all-out effort?
Or have 2/3 of the installations been offered a timely free fix, but are dragging their feet for some reason?
> “Our customers and partners all take security very seriously, and we are confident all reasonable steps will be taken to address this matter in a responsible way.”
That "reasonable" in a PR response is suspicious.
Wikipedia:
> dormakaba Holding AG is a global security group based in Rümlang, Switzerland. It employs more than 15,000 people in over 50 countries.
Sounds like they probably have the resources, if they have the will to solve this before potential very bad things happen to some hotel customers.
> publicly traded on the SIX Swiss Exchange.
https://www.google.com/finance/quote/DOKA:SWX?comparison=IND...
https://www.google.com/finance/quote/DOKA:SWX?comparison=IND...
However you can only flipper doors that are held closed by the latch bolt. If the lock deadbolt is engaged, you cannot flipper it, because the deadbolt will not budge when manipulated by a card or piece of plastic.
Technically a lock without an engaged deadbolt is not really "locked" but "closed". That being said, an unbelievable amount of people believe their doors are locked when in fact they are closed.
This is a bit harder when said window is only reachable from the outside, and is 78m above ground level (and all the walls are brick, so they're stronger than the wooden door).
They're about making it inconvenient enough / loud enough to gain unauthorized access that someone is going to notice and complain to the manager.
When you try to open a door, it compares your card's ID to the room database to see if the door should open.
Is that... not how it works? Because that seems simpler than anything that involves encryption, or actually writing shit to the card.
There are network-connected systems but they can be considerably more expensive to install.
Encrypting this information on the card itself is essier
Someone with the intent and know-how to crack RFID readers could put together a hardware tool to do so. Does the Flipper Zero provide such a tool? Yeah. Does the responsibility of following ethics fall with the user? Debatable, but I think absolutely yes.
If one carries around a lockpicking set and learns how to use it, they can go right ahead, correct? We accept the fact that people exist that can pick locks and yet 80% of states allow possession and use of lockpicking tools in a legal manner.
Saying "RFID is insecure, use NFC" is like saying "radio is insecure, use WiFi." NFC is a subset of the concept of RFID, much the same way WiFi is a subset of digital radio protocols.
RFID, while versatile and utilized across a range of applications from inventory management to access control, does not inherently prioritize security to the same extent. Its broader application spectrum means that specific security measures can vary significantly based on the use case and the design of the RFID system. For example, passive RFID tags, which are widely used due to their cost-effectiveness and simplicity, can be read from distances up to several meters, potentially exposing them to unauthorized scans. Active RFID tags offer longer read ranges and can incorporate additional security features, but their cost and complexity limit their use to specific applications.
Therefore, when comparing the security aspects directly, NFC's design principles inherently prioritize secure exchanges, leveraging close proximity communication and encryption standards that are well-suited for transactions and sensitive data exchanges. This focus on security, combined with the technology's adaptability for consumer use (e.g., smartphones for payments), underscores NFC's advantage in scenarios where security is paramount.
Most hotels use non-NFC RFID and on top of that most use passive tags. So it is certainly an inherent security flaw of hotel door locks. Unfortunately non-meatspace security is also drastically in need of choosing more effective already existing measures.
Base NFC has almost no security and relies on protocols on top to be secure. For example, Amibos use NFC and are trivially duplicated with cheap writable NFC tags. Contactless credit cards aren't secure because they do NFC, they're secure because NFC allows for an EMV transaction, it's the EMV handshake that handles all the security.
Once again, suggesting NFC just has a lot of security by default is acting like WiFi is always secure. But even worse, because at least WiFi standards have encryption and what not built in and optional, NFC doesn't even provide that.
And then you point out passive tags as if that's a thing that makes RFID less secure (ignoring NFC used for identification is RFID) but then I guess don't realize NFC allows for passive tags as well. I don't need to change batteries on my Amibos or the NFC stickers I put on the Wi-Fi info around the house.
You could build a key card system with NFC that has the same or worse system as older key card platforms. It being NFC gives you absolutely no additional benefit.
I actually will also correct myself about saying that NFC is shorter range than RFID. Both HF and LF have about the same range. UHF has a range on the order of 10m but is almost never if at all used for high volume applications like hotel door locks. I do however disagree with your rejection of the colloquial usage of RFID to exclude NFC. In everyday conversation, I believe it is understood that NFC is a subset.
> NFC's design principles inherently prioritize secure exchanges
NFC's design principles inherently has absolutely zero security. It doesn't prioritize secure exchanges, at all. The fact secure exchanges can happen over NFC in incidental to NFC existing. Any secure exchange that happens over NFC happens because the higher-level application brought its own security.
It's like UDP. Sure, you can do a secure exchange of data using it like QUIC or encrypted RTP, but UDP doesn't give you anything other than a way to send that data along.
Which then compared to just an overall massively wide topic like "RFID", which encompasses dozens (hundreds?) of other technologies, some of which do actually prioritize secure (or at least attempted to secure) handshakes throughout the entire stack.
And range of an RF thing is largely just based around typical hardware. If you wanted to you could build an antenna array to pick up an NFC tag from dozens of meters away. WiFi might only be designed to work around the house, but with a clear line of sight, decent RF conditions, and the right antennas you can send it miles.
Generally speaking, you shouldn't expect any kind of security doing things with NFC. Because, NFC has no security inherent to the protocol.
But a lockpicking kit has one purpose, it's picking locks. A Flipper Zero type device has plenty of legitimate, legal, personal uses in an IoT equipped home.
The Flipper Zero being banned will lead to a flood of copies, not to mention black market OEM versions.
Banning things doesn't make them impossible to get hold of but it does make it harder/more costly, which is all that any anti-crime measure can hope to achieve. Why do you say the opposite effect? This isn't like alcohol (or even, to an extent, weed) where a majority of ordinary decent people use it occasionally and want it to be available. Most people have never owned or used lockpicks and don't see any reason to have them if you're not a criminal. (And, sadly, that's probably also true of a flipper zero).
In general it's probably okay to bring your picks somewhere in most parts of the country if you're a hobbyist.
In general it's a bad idea to carry picks if you're doing anything that a prosecutor could construe as breaking into a building to steal things. This is an area to be particularly aware of for urban exploration, where trespassing is bad but burglary with burglarious tools is like felony bad.
However, that is a fairly extreme case, and most countries don't have such laws on the books (or if they do, what's illegal is "possession with intent").
In the United States, postal services have access to clusters of mailboxes and some common areas where mailman can leave mail and parcels, which can be entryways or some kind of storage rooms in them, for example, so that the owners can pick them up when they get home. These rooms are locked with padlocks made by several local companies. Once a key is inserted and turned in the lock, it can only be retrieved by turning it in the opposite direction to the default position, but even then they manage to forget them in the locks.
A customer from the USA came to us and asked us to combine this padlock with an intercom system we are developing to signal the administrator that the letter carrier came, opened/closed the lock or forgot the key in it. Nobody wants to switch to RFID, of course, or else the employees of the lock manufacturing company will have nothing to eat, so we had to enlarge the intercom vertically in order to build into it a lock whose transom will close a group of contacts on the panel, letting us know that something is going on. On the edge, lmao.
In the UK, mailmen are treated very differently - the intercoms have a special button on the intercom which, when pressed, will open the door so that the mailman can enter and drop off the mail without having to carry keys or RFID identifiers. Normally this button is set for some working hours, for example from 9 to 5 and of course anyone can press it and get into the premises.
Most hotel door locks I’ve seen are designed to be opened from the outside.
A door jammer wedges the door shut. With it, I sleep better at night.
People think that they are mysterious things that are secure because they aren't able to see what they mean. But in reality, they are all still just a machine-readable number.
(even if a rolling key, challenge-response or pubkey authentication is supported, we're often still just using a single number, but my point is more about the perceived obscurity for the public)
I have a contactless card that runs GPG as a Java Card applet and creates 4096-bit RSA signatures. That's pretty secure!
Ok, my eyebrows are up. Authentication has grown so much as a field since then that I'm having trouble with the idea that this flaw has always been present. In fact, Saflok predates MIFARE Classic by at least five years. Perhaps all will become clear if a full technical disclosure is ever made available, but it seems like the authors are making an overstatement here.
Buy this strap for your door lock while you're inside.
That is the biggest surprise to me. I had assumed getting around the deadbolt would require a locksmith or breaking the door. (What's the point of it otherwise?)
How else would the hotel staff enter the room when the current occupant is locked in the room, but dead or some lesser medical emergency condition?
A medical emergency would justify breaking the door.
The same applies to my apartment door.
Look into what happens when someone pulls a fire alarm. Some building-wide lock systems will actively unlock doors during a fire scenario.
How can I use an Android phone as a room keycard? Is there an app for reading a card and acting as a tag?
How can I use an iPhone as a room keycard? Why can't I easily add it to Wallet? Is there another app for that?
And Android, and EBay, and Proxmark...
https://corporatefinanceinstitute.com/resources/fixed-income...
AFAIK, even accountants are slowly moving away from it for ... Obvious reasons.
* other brands of very sticky strong tape are available.
Do likewise at the bottom edge, adding a seal to the floor / carpet. Don't be frugal (these are drunk roadies in full prank mode)... use your imagination ;)
See page 64: https://www.austinpowder.com/wp-content/uploads/2019/01/The-...
Not explosive in and of themselves, but a component in modern industrial explosives. As a sensitizer and a density modifier.
Also perhaps consider expanding the headline character limit above 80, or maybe not count numbers in the total.
i do agree that the "don't editorialize" and strict char count are very contradictory, but suggesting that the site changes because of it is also naive at best.
I was definitely NOT thinking of unlimited.
I was thinking of 80chars, but excluding numerals (123, etc) and number text ("thousand", "million" etc.) and maybe a few other items excluded from the count, with a maximum of 100, or whatever number actually will not break the layout.
I've found it frustrating trying to fit in 80chars, and e.g., finding that ampersand gets expanded so it actually counts more than "and", so it is not a single-rule 80 chars; perhaps a few more sophisticated rules might help. Just a suggestion.
million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million million>>"with a maximum of 100,"
Of course lowercase "mm" is most recognizable as millimeter, so that would be confusing in a different way.
Seems the 3M branding has worked quite well...
[0] https://www.springfieldspringfield.co.uk/view_episode_script...
jeasus christ:
https://corporatefinanceinstitute.com/resources/fixed-income...
Seems like you engineers have been behind code and not having to defend your project budgets to CFOs and stakeholders often.
Using K and MM in finance reduces the odds of an incorrect interpretation of a single M.