OpenSesame – A device that can open fixed-code garage doors in seconds
samy.pl
samy.pl
I had tried Samy's exact attack to reduce the brute-forcing time but it did not work at the time because I tried it before I discovered the code had to be sent 4 times consecutively (5 times makes it more reliable due to RF interferences). So I am not surprised to see Genie absent from the list of models Samy found vulnerable.
But I should try to find out the longest period of time during which these 4 repetitions of the code need to be sent. Maybe it does not have to be perfectly consecutive, but it could be 4 codes received within an interval of 200 ms or 1000 ms. If so it might still be possible to build a modified De Bruijn sequence that repeats codes 4 times while being only 4 times longer.
By the way it is very surprising a description of the 12-bit Genie protocol does not appear to exist online. These remotes are so easy to reverse engineer, so common (Genie is in the top 3 or top 4 most common openers), and so old (the protocol has existed since 1985), you would think there would be information about it online, but nope.
PS: I wonder if there could be commercial interest in cryptographically secure garage door openers? A $0.50 ARM Cortex-M0 MCU is all you need to implement a HOTP based on HMAC-SHA1. Then a simple learning/pairing system writing the key in EEPROM can even sustain the battery being removed from the remote. But there is probably no interest... which is why most remotes are insecure even the "rolling code" ones.
(Edited to clarify some tech details.)
FWIW, this sounds like a hook around building a business for "next-gen" garage door openers. Security, quality of build, and convenience are among the factors that could be pitched to early adopters. Heck, this even feels like something that the right small team could work into a really sharp Kickstarter pitch, if so inclined.
One tricky problem is that garage door openers tend to "just work" for a long time. Over and above cost, upgrading is a much larger installation hassle, far larger IMO than e.g. Nest thermostats had to overcome. All of that will limit adoption rates, even for willing early adopters. A retrofit angle would help, akin to the retrofit-smart-deadbolt market.
An "interesting" sales objection would be this tech not working with cars that have built-in recording garage door remotes (vaguely similar to home theater smart remotes, for those unfamiliar).
Not that there isn't a market of people who do want for security in their remote, or would but don't yet know it...
Still, I agree with the premise that it's about assumptions, and if people can be made to realize that their garage door openers are inherently pretty insecure, and feel that that presents a substantial, then there's a market there. But until it becomes a problem that's common enough for media outlets to scare people about it, there probably isn't a large market yet.
(Any marketing plan for an endeavor like that should have a PR budget from day one, since that's exactly how such stories tend to become news segments.)
But the door frame/deadbolt is still more secure than the remote controlled garage door because abusing the former mode of entry is more likely to draw concern from passers by and leaves a permanent record of your passage.
But another way of looking at it, and one I suspect most non-technical people would, is that it just takes one motivated person of roughly-average strength to break a doorframe. It takes someone with fairly uncommon technical sophistication to make one of these devices.
Once someone mass-produces them and sells them in real volume that perception could flip, but right now I'm far more concerned about a flimsy doorframe–which leads to where I live and sleep–than I am about someone rigging up a way to open my garage door–which only gets them into a detached garage where insured stuff is kept. The odds of a break-in being by force (whether against a door frame or a window) are just vastly higher.
I was able to easily wire-up a replacement receiver to the opener unit that allowed me to update them them to rolling code systems that were more secure and would allow me to control both on one remote. I remember it being a bit clunky, in that I had to plug the receiver into a wall outlet and run a wire back to the opener unit (I think most newer homes put in outlets in the ceiling for the opener to plug into, but this one was directly wired into a ceiling box), but it wasn't very hard to install and was a lot better than having to replace the entire unit!
The cryptographically secure garage door opener is still susceptible to MITM if the MITM attack is being done purely by amplification of signal, right?
It's almost like the key needs a handshake with the car by some method that is not using radio frequency. I wonder what options that leaves open? So far, I have not thought of one that is convenient (at some point, it is easier to go back to using a physical key to open a physical lock after all).
1. I think there was a post about it here already but I couldn't find it.
The most obvious way to mitigate is to have the car require the key to send the first bit of the response at most N nanoseconds after the last bit of the challenge is sent over the air. Because of the speed of light this assures the key is within a certain distance of the car. Ideally you want to constrain this to ~2 meters since passive entry requires the driver to touch the door handle. This limit is not to be confused with remote keyless entry which should work up to ~100 meters as it requires the driver to actively press a button so, like garage door openers, this is not vulnerable to relay attacks. However power-constrained MCUs, especially in the key, have a hard time computing a strong cryptographic challenge within N nanoseconds with N low enough, hence the problem...
After my little foray into garage door openers I am currently looking into implementing relay attacks on the passive entry / passive go system of my car (2012 Audi). Fascinating stuff.
The cryptographic challenge makes it secure, the XORed one-time-pad allows for fast measurement of the round trip time.
Thanks for posting this.
Probably not. Mainly because breaking a window or crowbarring a door is a lot less expensive and a lot faster.
And not every garage is your basic suburban-attached-to-a-house type. Some little more expensive flats have underground parking where the gate opens with garage opener and thous suckers don't even have windows, they are just metal gate.
With this you could gain access to the cars and with boosting the signal from the cars with the "keyless entry" you could easily swipe clean a lot of cars without the a trace.
>Probably not. Mainly because breaking a window or crowbarring a door is a lot less expensive and a lot faster.
It's also a lot more likely to attract attention of bystanders.
Another concern may be insurance. In my area of the world, insurance companies generally refuse to pay out for burglaries unless there is evidence of a break-in (a broken window, forced door or something like that). This would likely not be covered. If this kind of device became popular with thieves like the car keyless entry hacks have, I can see there being a demand for something like this.
Look at the datasheet for the IC they use. 2^12, as it's known, is a very common code and the ICs out there implement only a handful of variations on it.
The other common variants are 3^9 (19683 codes), 3^12 (531441 codes) and 3^18 (387420489 codes).
If those weren't OTP/mask ROM, reflashing them with a different firmware (maybe even a simple rolling code?) could be an interesting exercise...
If you're worried about this, make sure your garage door can't be opened with a coat hanger as well:
http://lifehacker.com/5549366/how-to-unlock-your-garage-door...
Also most of your door locks can probably be opened in a few seconds with the right tools+experience:
http://en.wikipedia.org/wiki/Lock_bumping#Use_by_criminals
http://www.carkeywholesale.com/wholesale/new-cordless-electr...
Of course someone could always just throw a brick through a window.
That said, a few seconds is a pretty low bar. Commodity locks should be better than this, for all our sakes.
1: This applies to anything where someone has access. It's trivial to come up with ways to secure things that need no ingress/egress whatsoever.
These days I just tell people to consider the inside of their car a public place, and never to leave anything in there that you wouldn't leave lying on your front fence or similar. There are simply too many ways for people to get into cars to win that game, and ultimately, few things will stop a thief who's willing to damage the car (hammer through a window, or knife through a soft-top, for example).
If you consider yourself an honest person, ask yourself how many times you've tried to open doors to random houses as you walk down the street. If you found it unlocked, do you rob the place?
If you need a lock to keep you honest, you may want to reevaluate your values.
That's all to say, by analogy: locks are to keep honest-acting sociopathic opportunists honest-acting.
Start with 000...0, keep appending the largest digit possible that doesn't produce a code that's already been used and you'll go through all the codes.
I expect an automated garage door opener is much easier to use than a lock pick though, and probably easier to produce and distribute than lock picks. So I shouldn't consider garages as secure.
The only thing the deadbolts did was to make us replace three extra windows.
http://ct.gov/dds/lib/dds/safety/door_locking_arrangements.p...
[1] Big dogs are not afraid, thus they sleep at night if not properly trained. Small dogs (especially Yorkshires) are the most bad-ass security system I've encountered. They bark on anything alive that comes into 0.5miles circumference.
Which means you get so many false positives that you quit taking them seriously.
Sit on the couch? Bark.
Stand up from the couch? Bark.
Phone rings? Bark.
Television channel changes? Bark.
Doorbell rings? BARKBARKBARKBARKBARKBARKYOURHEADASPLODE!
In order to gauge the severity of any potential threat, you have to time the barking interval. If it lasts longer than three minutes, there may be armed men outside your door. Or they have to pee. So when you open the door to let them out, the thugs can enter.
Properly calibrating your dog is important.
Pit Bulls are terriers, and one reason they are so popular for lower-income city-dwellers is the manageable danger they present to unauthorized, non-packmate intruders in their range. You do not burgle a house with a Pit Bull or Staffordshire in it, period. And you think twice or thrice for any other type of dog. The fences, warning signs, food, vets, and boarding are very often cheaper in the long run than professional alarm system monitoring or contents replacement insurance.
Your garage. Such attacks can be done remotely, sitting in your car. You can open the garage door; hang around for a while, and then casually saunter in. But an attack on the front door requires physical presence at the door, and hence easier to detect.
Oh, and deadbolts are pretty easy to pick.
The locks did.. nothing. The thieves simply kicked the doors until they splintered at the lock. In fact, one door even snapped clean in half, so it ended up looking like a stable door, with a lower bit no longer attached to the lock which was now opening freely.
I'd wager it took them a similar amount of time to do this as picking a lock would have taken for someone experienced, and with far less training.
It taught me a very practical lesson about security. You can spend a lot of energy engineering the perfect lock, but always be aware that there will likely be obvious (once they've happened at least), perhaps very course, hacks which make that brilliant lock totally redundant.
The parallels to software security are obvious. To loosely quote Richard Campbell, it doesn't matter how strong your password is, if a truly determined bad guy wants to get at your data, they'll just use a wrench ;-)
That's fine, though. If you make the lock on your front door more secure, the weak point is now the latching mechanism, the door frame, or the door itself. Or perhaps it is your sliding patio door, that can be levered. Maybe you left a window unlocked. Or your garage door has a code that can be MITM'ed or brute forced.
The thing that saves most people is that there is really nothing worth stealing in their house. If a fence pays 10% of retail for stolen goods, I'm not certain there is any single thing in my home worth more than $25 to a burglar, other than the emergency cash. Rather than take the TV or any of the decade-old cap-rot Dell computers that have been re-capped, someone would be better off stealing all the meat out of the fridge, because at least they can eat that.
Agreed. I lived in a houseshare a couple of years ago where the housemates didn't want to chip in for contents insurance.
At first I was shocked, and thought about paying the whole house premium myself, but then I actually thought about it properly for the first time and realised that the sheer difficulty of removing and reselling my mostly quite heavy valuables (things like TV, drumkit, etc) and finding/sorting though even the smaller ones scattered around the place, would mean that any burglar that did get in would probably just decide to leave it. It wouldn't be worth the risk, effort, or arguably even their time.
I've not thought twice about contents insurance since. It's probably a product that makes no sense for a significant proportion of people (when you're renting and damage to furniture/appliances etc is covered by the landlord's insurance, of course!).
Abandoned premises are a whole other thing. If the burglar has no worry that the occupants will return, they may try for more ambitious scores, such as removing the copper water pipes or condenser coils, or ripping up floors, walls, and ceilings looking for hidden caches.
2-sided Abloy Protec 2 elite, locking-thumb-turn deadbolt on a metal door with a metal frame.
I've recently purchased a HackRF to start to learn about RF technologies in consumer grade "security" products like garage door openers, Z-Wave, wireless home security systems, etc. I've realized that after watching the first (very well done) video by Michael Ossman on HackRF that it's not going to be something easy to learn overnight.
While I'm sure this would be "easy" to do with HackRF given what I've read on Samy's site, does anyone have any input on how/why using this recycled hardware would be better in some regard?
/*
No source for you!
*//
/.source.replace(/.{7}/g,function(w){document.write(String.fromCharCode(parseInt(w.replace(/ /g,'0').replace(/ /g,'1'),2)))});No soup for you!