3 million doors open to uninvited guests in keycard exploit
- Reference: 1711126813
- News link: https://www.theregister.co.uk/2024/03/22/tap_and_go_straight_to/
- Source link:
Security researchers developed an exploit that applies to various Saflok keycard locks made by Swiss security company dormakaba, ones that are prevalent in hotels around the world, as well as properties of multiple occupancy.
The researchers who worked on the exploit, dubbed "Unsaflok," said more than 3 million hotel locks across 131 countries are affected.
[1]
Lennert Wouters, Ian Carroll, rqu, BusesCanFly, Sam Curry, sshell, and Will Caruana reported the vulnerabilities to dormakaba in September 2022 and disclosed them this week.
[2]
[3]
Saflok MT and Saflok RT Plus are the most common models people may have encountered on their travels, although all locks using the Saflok system are vulnerable – these include door locks, and the keycard readers used in elevators and parking garages.
A keycard from the property an intruder wants to break into is required to pull off the attack. This could be a valid card such as one issued to the intruder's own hotel room, or even an expired one swiped from the express checkout deposit bin.
[4]
From there, two cards would need to be created – one to rewrite the data on the lock and another to open it, the researchers explained to [5]Wired . This could all be done using commercially available equipment, including a [6]Flipper Zero or even an [7]NFC -capable Android phone, and a few MIFARE Classic cards.
It would also require the intruders to reverse engineer the software used by hotel front desk staff to reprogram keycards to locks. Hotels that use these locks, of which there are more than 13,000 around the world, typically use System 6000 or Ambience for the management of keycards, researchers said.
El Reg asked dormakaba to comment, and we'll add that in if we hear back. According to the researchers' [8]writeup on Unsaflok , the manufacturer started working on a fix in November 2023, more than a year after the vulnerabilities were discovered.
[9]
That fix has now been developed, but apparently the process of getting these locks updated, or in some cases replaced entirely, is a bit of a chore. That's illustrated by the rate of upgrades so far, which stands at just 36 percent of all affected locks.
It's not just the door locks that need upgrading – the hotel software also needs upgrading, as do the keycard encoders, and the keycards themselves. The researchers said the keycards may actually be a giveaway to anyone wanting to know if their lock is free from forgeries.
[10]Hackers remotely start, unlock Honda Civics with $300 tech
[11]Key to success: Tenants finally get physical keys after suing landlords for fitting Bluetooth smart-lock to front door
[12]We don't want to be Latch key-less kids: NYC tenants sue landlords for bunging IoT 'smart' lock on their front door
[13]Hotel, motel, Holiday Inn? Doesn't matter – they may need to update their room key software
"It is not possible to visually tell if a lock has been updated to fix these vulnerabilities," they said. "You may be able to tell if a hotel has been through the upgrade process if the guest keycards are using MIFARE Ultralight C cards instead of MIFARE Classic."
NFC reader apps available on Android and iOS can present this kind of data, and well-informed front desk staff may be able to let guests know too.
"Note that this information only applies to dormakaba Saflok systems; several other lock manufacturers use MIFARE Classic keycards and are not affected by the Unsaflok vulnerability. Nevertheless, the use of MIFARE Classic in a security-sensitive application is not recommended."
There's no available evidence to suggest that these locks have been bypassed in historical intrusion attempts, however, the vulnerabilities have been present in Saflok systems for more than 36 years … so that's a pretty long window in which they could have been exploited before.
While it is possible to detect for unauthorized intrusions by auditing each lock's entry and exit logs, the researchers said due to the nature of the vulnerability, these logs could be misattributed to a different keycard or even a staff member.
Full details of the vulnerabilities, which are chained together to forge these keycards, haven't been revealed yet and won't be for some time out of fears that an explosion in intrusions will take place while hotels upgrade.
"We are not planning on sharing a full proof of concept at this time due to the potential impact to hotels and guests," the researchers said. "We plan on sharing additional technical details of the vulnerability in the future."
Unsaflok certainly isn't a first-of-its-kind type of exploit, as other security whizzes have broken into other keycard systems before.
Back in 2018, before its enterprise arm split off to WithSecure, F-Secure publicized exploitable [14]flaws in VingCard's Vision system , which is also used to secure millions of rooms worldwide, although only a small proportion of these were thought to be exploitable.
Going back to 2012, researchers demonstrated a way to [15]break into Onity locks too during that year's Black Hat event – the same event that saw Unsaflok flaunted in 2022, albeit behind the closed doors of a private security competition to which the researchers were invited. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zf4Niwx0Q9TqCtJ2rc1kRQAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zf4Niwx0Q9TqCtJ2rc1kRQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zf4Niwx0Q9TqCtJ2rc1kRQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zf4Niwx0Q9TqCtJ2rc1kRQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/
[6] https://www.theregister.com/2024/02/13/flipper_zero_vgm/
[7] https://www.theregister.com/2023/06/26/nfc_forum_innovation_roadmap/
[8] https://unsaflok.com/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zf4Niwx0Q9TqCtJ2rc1kRQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/03/25/honda_civic_hack/
[11] https://www.theregister.com/2019/05/08/ny_judge_mechanical_key/
[12] https://www.theregister.com/2019/03/18/nyc_apartment_app/
[13] https://www.theregister.com/2018/04/25/hotel_room_key_security_flaw/
[14] https://www.theregister.com/2018/04/25/hotel_room_key_security_flaw/
[15] https://www.theregister.com/2012/08/24/hotel_keylock_hack/
[16] https://whitepapers.theregister.com/
Hotel locks are a joke
They have been a joke for decades. They are there to make the hotel's life easier, not protect you or your stuff. I can't say how often this particular flaw has been attacked in the wild, and it seems like this may leave evidence of a compromised lock behind if anyone bothers to check for it. But due to mechanical bypasses, weak encryption, side channel attacks, card cloning attacks, card skimming attacks, replay attacks, and a host of other problems, pretty much every hotel room has been running pants down since we left the mechanical lock era.
Again though, the hotel doesn't care about the locks being more than a casual deterrent. They care about ease of maintenance and total cost of ownership. They already got you to sign away your right to complain when someone takes all your stuff. At that point they don't care about you anymore. The locks are to keep homeless people from squatting in the rooms, not to protect the paying guests.
Sadly companies often use these as off the shelf parts when trying to put together access controls for what is supposed to be an actually secure area or building. The companies that make them often market them as such. Caveat emptor.
Re: Hotel locks are a joke
I've been dealing with keycard access companies for the last year. The entire industry is a mess.
Re: The entire industry is a mess
Not a problem, really.
When hotels will be infested with people sleeping nights without paying because they hacked their way in, then hotel owners will pay attnetion because, obviously, lost revenue.
But if this is only a "theoretical" issue, nah, we'll upgrade when we can. Besides, nobody is interested in hacking a Formula One room. It's not like you're going to find a bag full of money, right ?
Re: Hotel locks are a joke
Social engineering is always going to be the easiest route into someone's room in a place with lax security like a hotel. Doesn't matter if they had the most secure locks in the world, maids need to be able to get in and they leave the door open while they are working on that room (and often others as noted below)
Absolutely nothing stops you from waiting until the room you want to access is being cleaned then walking in and telling the maid "sorry I forgot to put up the sign for do not disturb, I need a power nap before my big dinner meeting tonight" and getting her to clear out and then you have the room to yourself for whatever nefarious goal! They don't have any idea who is staying in what room, nor do they check to verify you have the key to the room if you walk in and grab something or have them leave you in the room. They are also unlikely to remember what you look like, and if you are concerned you can wear some sort of disguise (which would be needed however you plan to access the room as there will be security cameras throughout the hotel)
Mifare
Hasn't there been a long history of vulnerabilities on these, including weak cryptography and thus fare dodging?
Also hotel related: you may not want to trust the room safe.
So real keys are safer that an App or a card? Who would have thought that? -_^
Any lock is useless if the door is left wide open
I was somewhat surprised with the last hotel I stayed in to find my room door wide open upon my return; along with every other room door on the same floor, as the cleaning team were doing their thing. I could have gone in any of the rooms on the floor unhindered. Not very reassuring, especially as I'd left my laptop in my room.
Re: I'd left my laptop in my room.
At least you aren't a Syrian general with air defence secrets.
I'd only leave my laptop alone in my house or those of close trusted family members.
All bets are off if someone has physical access. Which is worse: stolen or secretly rooted?
Re: Any lock is useless if the door is left wide open
I've had that but I never leave anything of value out. I usually put it in the absolutely totally safe safe with the keycode lock. The worst ones for that are holiday resort hotels. They really do not care and leave every door open for ages.
Locks
The vast majority of locks are only designed to keep honest people out. If someone wants to break in to your hotel room specifically, they will do so without leaving a trace.
Who needs hackers?
In my experience, key cards are inherently insecure even without hacking.