The New Hotel Key: Your Smartphone
online.wsj.com
online.wsj.com
This is a complete privacy and security nightmare both from the potential of cracking it and from installing an app that will probably grab every permission it can.
It's also going to be entertaining seeing people with dead batteries begging a charge from people in the lobby.
My guess is because none of they crypto is mentioned, its probably some self developed snakeoil, so you might not even need to own their phone. Could be as simple as "bluetooth address whatever, which happens to be in the central DB whitelist, says open sesame" and the door opens.
Amusingly I have a moto-X and my BT addrs is 1 less than my wifi MAC so if the security protocol is weak enough to depend on BT addrs, you could sniff the wireless for awhile and then just subtract 1 from each sniffed wifi MAC and have some fun with known good BT addrs. Or perhaps on other phones BT addrs = wifi + 1 instead of minus 1. Whatever.
Now this idea, I like.
http://krebsonsecurity.com/2011/08/beware-of-juice-jacking/
>My guess is because none of they crypto is mentioned, its probably some self developed snakeoil, so you might not even need to own their phone. Could be as simple as "bluetooth address whatever, which happens to be in the central DB whitelist, says open sesame" and the door opens.
I would seriously hope for this not to be true, but I've seen too many security fails to think it won't. Access is amazingly rubbish with security, especially when some RFID chip makers actually put a proprietary encryption algorithm as a selling point, when many of those (e.g. mifare) are provably broken.
Aren't hotel room locks already easily cracked? I remember seeing it on HN last year. As for permissions - if you don't like them don't install the app, they aren't going to deny you a key.
>> It's also going to be entertaining seeing people with dead batteries begging a charge from people in the lobby.
Presumably in this case they would give you a key.
They are, but this will only make them worse.
Moreover, the electronic mechanism pretty much never opens the lock: it activates a relay, which opens ... drum roll ... the physical lock. So the old, mechanical lock vulnerabilities are preserved, and new electronic ones added on top. What could posibly go wrong?
I've never been to a hotel that uses an ordinary key since those can be easily replicated, so that point is moot: all the electronic locks (most common these days) already have this "vulnerability" ("so why put a lock there in the first place?").
Second, since this system is being developed to use a smartphone, the security is easier to manage than a PIN code (such as 000000...). One can use centralised key-servers, etc.
Third, the company making these locks (the physical part) is ASSA Abloy, which is an extremely reputable lock company instead of the one in your link.
Fair enough, maybe they thought about the physical side then; Abloy make what is arguably the best mechanical lock in the world.
Still doesn't mean the authentication side is secure though.
It doesn't mean it cannot be made secure, either.
IIRC the post you're probably thinking about was the fact the reprogramming port for hotel use allowed an attacker to do gain control. This is an implementation problem with the hardware attached to the door, regardless of key technology.
Even with poorly-protected service access interfaces and magstripe keys the incidence of malicious attack doesn't provide economic incentive for hotels to do better. Bluetooth based locks may provide incentive to swap out all the existing poor security locks in a building, but there isn't anything preventing the computer security of the new locks from being even worse.
Unfortunately, many of the smart locks that use your phone as an unlock mechanism don't have a good solution for what to do when your phone battery runs out. Usually the answer is "use a key", but the new problem is that once enough of your locks are smart, you stop carrying keys.
In the home, keypads work well (and they can easily be set up for guests, etc), but that seems prone to memory error in hotel situations.
I'd rather have a keypad than the cascading inconvenience of having to swap those batteries more often.
The only z-wave smart locks I've seen carried in national retail stores also have keypads [1,2,3]. Isn't that the solution to the battery problem?
What lock do you use? I could never rely on z-wave to open mine; I only use that to automate locking up the house at night in case I forgot. It can take up to 30 seconds for my lock to respond to a z-wave command if it hasn't already been woken by some other event, which is a long time to stand outside your door waiting for it to open for you.
1: http://www.homedepot.com/p/Schlage-Camelot-Aged-Bronze-Touch...
2: http://www.homedepot.com/p/Schlage-Aged-Bronze-Home-Keypad-D...
3: http://www.lowes.com/pd_497751-350-910+TRL+ZW+15+SMT+CP_0__?...
The lock does have some lag in it, but I just try to keep it awake by pinging it, and rely on early detection of the beacon to get the request in early. Definitely not a great solution though, and I'd love to find something faster.
Are you using openzwave, RaZberry, MiCasaVerde, or something else?
[1] This sort of thing: http://proto-pic.co.uk/mifare-one-rfid-card-13-56mhz/?gclid=...
To anyone who is interested, enable NFC on your 'droid, then on Google Play, download "Card Test" and voila...
The app requests the key from a server and if it's correct it allows you to send the commands to the deadbolt. Now it's just time to start fuzzing for those commands. The only problem is that I can manipulate wifi pretty easy, but have no clue how to put bluetooth into monitor mode.
messing around with bluetooth sounds complicated
Entering a PIN code would be much less convenient.