Story image

Electronic lock vulnerabilities can lead attackers directly to your hotel room

30 Apr 2018

Next time you stay at a hotel as part of a business or personal trip, you may want to ask if the hotel’s locking systems are up-to-date.

Researchers at F-Secure discovered that hotels throughout the world use an electronic lock system that an attacker can exploit to gain access to any room in the building.

The vulnerabilities lie in the Vision by VingCard lock system software, which is used to secure millions of hotel rooms across the globe.

Researchers demonstrated that any ordinary key can be used to target the hotel – including keys that have been thrown away, expired, or ones to use spaces such as garages.

They were able to create a master key with privileges to open any room in the building, which can then be used to conduct a completely unnoticeable attack.

“You can imagine what a malicious person could do with the power to enter any hotel room, with a master key created basically out of thin air,” comments F-Secure Cyber Security Services practice leader Tomi Tuominen.

“We don’t know of anyone else performing this particular attack in the wild right now.”

The researchers decided to investigate the topic when a colleague’s laptop was stolen from a hotel room during a security conference 10 years ago.

Researchers say that when they reported the theft, hotel staff dismissed the complaint because they couldn’t find evidence of forced entry, or any evidence of unauthorised access in the room entry logs.

The researchers decided to investigate the issue further, and chose to target a brand of lock known for quality and security. These security oversights were not obvious holes, they add.

It took a thorough understanding of the whole system’s design to identify small flaws that, when combined, produced the attack. The research took several thousand hours and was done on an on-and-off basis, and involved considerable amounts of trial and error.

“We wanted to find out if it’s possible to bypass the electronic lock without leaving a trace,” comments F-Secure senior security consultant Timo Hirvonen.

“Building a secure access control system is very difficult because there are so many things you need to get right. Only after we thoroughly understood how it was designed were we able to identify seemingly innocuous shortcomings. We creatively combined these shortcomings to come up with a method for creating master keys.”

Assa Abloy, the world’s largest lock manufacturer, has issued software updates with security fixes to mitigate the vulnerabilities.

“I would like to personally thank the Assa Abloy R&D team for their excellent cooperation in rectifying these issues,” says Tuominen.

“Because of their diligence and willingness to address the problems identified by our research, the hospitality world is now a safer place. We urge any establishment using this software to apply the update as soon as possible.”

Opinion: BYOD can be secure with the right measures
Companies that embrace BYOD are giving employees more freedom to work remotely, resulting in increased productivity, cost savings, and talent retention.
Sonatype and HackerOne partner on open source vulnerability reporting
Without a standard for responsible disclosure, even those who want to disclose vulnerabilities responsibly can get frustrated with the process.
OutSystems and Boncode team up for better code analysis
The Boncode and OutSystems alliance aims to help organisations to build fast and feel comfortable that the work they're delivering is at peak quality levels.
Nozomi and RIoT to deliver advanced ICS security solutions to Australia
''As a specialised integrator of robust and resilient ICT and IoT solutions within Australia, we are delighted to be partnering with Nozomi Networks."
Nuance biometrics fight back against fraud
Nuance Communications has crunched the numbers and discovered that it has prevented more than US$1 billion worth of fraud from being passed on to users of its Nuance Security Suite.
SIS announces a partnership with Platform 4
“We are looking forward to a strong future in the New Zealand security industry with this global giant as our strategic partner."
Attacks targeting Cisco Webex extension explode in popularity - WatchGuard
WatchGuard's Internet Security Report for Q4 2018 also finds growing use of a new sextortion phishing malware customised to individual victims.
Developing APAC countries most vulnerable to malware - Microsoft
“As cyberattacks continue to increase in frequency and sophistication, understanding prevalent cyberthreats and how to limit their impact has become an imperative.”