Defcon Hacks Defeat Card-And-Code Locks In Seconds 144
Sparrowvsrevolution writes "At the Defcon security conference in Las Vegas, Marc Weber Tobias and Toby Bluzmanis plan to demonstrate simple hardware hacks that expose critical security problems in Swiss lock firm Kaba's E-plex 5800 and its older 5000. Kaba markets the 5800 lock, which Bluzmmanis says can cost as much as $1,300, as the first to integrate code-based access controls with a new Department of Homeland Security standard that goes into effect next year and requires identifying credentials be used in secure facilities to control access. One attack uses a mallet to 'rap' open the lock, another opens the lock by putting a pin through the LED display light to ground a contact on the circuit board, and a third uses a wire inserted in the lock's back panel to hit a switch that resets its software."
Attractive Nuisance (Score:5, Insightful)
Re: (Score:3)
I'd like to see the hacker that could defeat my home security system [remingtonle.com]!
Re: (Score:2, Funny)
Well, since you're probably american, the hacker can have a gun as well, if he shoot first, no one give a shit about YOUR gun.
Re: (Score:3)
Han? Is that you?
Re: (Score:3)
Re: (Score:2)
I'm surprised it's that high in the US. We have two, but they were my grandfather's, and almost nobody I know owns a gun. I wonder how the ownership is distributed socioeconomically and demographically.
Re: (Score:2)
It also doesn't take into account non-civilian ownership, which is going to push US numbers much higher. (Not that it matters ordinally, since it's at the top of the list already.)
Re: (Score:2)
Easy [wikipedia.org].
Re: (Score:3)
Even easier and not so exotic, I'll always bet on a thug who is used to violence against a regular guy with a gun. The thug wins because he has advantage in ruthlessness. I have a reasonably good command of a martial art, yet I got surprised this year in the street by a guy roughly twice my size who tried to mug me. I took one in the teeth just because I just refused to believe what was happening. In the end he wasn't really successful and is probably still productively employed in a brick prison factory, b
Re: (Score:2)
Exactly... Nice door lock there... Crowbar works just fine on the WINDOW too.
The difference it that real criminals have no problem leaving a broken mess...
Locks like these still miss the point that a big enough hammer is going to take the lock off the door.. Then a plain screwdriver can open it!
Re: (Score:2)
You want to see ruthless, that's a dog who thinks his owner is in mortal danger. Something flips in their brain, and they get as hard to put down as a wolf.
Re: (Score:2)
Re: (Score:2)
I have a reasonably good command of a martial art...
How come I never saw a headline in a paper which said something like: "Martial Arts master defeats gang of crooks!"
There's a decent percentage of the population practicing martial arts...where's the flaw?
Re: (Score:2)
I guess most people just don't bump into gangs of crooks, and those unlucky to do so do it under circumstances that are against them. In my case, this was my first "real" fight in 20 years, I do the martial art as a form of exercise. Also, I imagine if there were three or four of them that big and armed, I'd be in deeper shit if I tried to fight.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Won't work if you're not home.
Sounds like a job for Turret Monkey.
Re: (Score:1)
http://en.wikipedia.org/wiki/Sleep [wikipedia.org]
or
http://en.wikipedia.org/wiki/Vacation [wikipedia.org]
or even better reflexes +
http://www.remingtonle.com/shotguns/1187.htm [remingtonle.com]
Sounds like someone lost his Viagra prescription. (Score:2)
Re: (Score:2)
Re: (Score:2)
So the solution is to design things that are so obviously insecure no hacker will even bother to play with it? That's not the security I'd feel comfortable with.
made to government spec (Score:5, Interesting)
a new Department of Homeland Security standard that goes into effect next year
How many places will buy them because they meet this government spec without regard to these problems? Government planning at its finest!
Re: (Score:2, Interesting)
Re: (Score:3)
Zurich-based Kaba markets the 5800 lock... as the first to integrate code-based access controls with a new [DHS] standard
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
A-series papers all the same shape. A sheet of A(n) paper can be turned into two sheets of A(n+1) paper by dividing symmetrically. A(0) has an area of one square metre. That's it ; series defined for all possible values of "n". No mention of any mathematical constants (though they do pop out of the woodwork when you try to actually use the definitions).
And indeed, it's probably good that I don't make any attempt to rem
Re: (Score:1)
I couldn't find a link to this standard (though I didn't try that hard), so I'm not sure it's fair to criticize the standard without reading and understanding it.
The "attacks" mentioned in the summary don't seem to be against the standard itself, but are physical attacks against one particular
Let me write the spec... (Score:2)
1) Submit production samples of your candidate locks to several Defcon conferees, particularly those who have defeated lock mechanisms in the past.
2) A decision on whether your locks meets the specification will be rendered after next year's Defcon.
Re: (Score:2)
What I don't understand is, why spend $1300 on an untested design?
What I'd do is put an RFID tag on the user's key, then take a high quality conventional lock and add an RFID reader to it and a pawl which prevents the lock cylinder from turning unless an RFID on the allow list is present.
The point would be the lock would fail to a safe, or relatively safe condition. If the electronic system were defeated you'd still have a functioning lock.
Re: (Score:2)
Something you have plus something you know required. If both authentication mechanisms are integrated all you have is a more secure key.
Re: (Score:2)
How many places will buy them because they meet this government spec without regard to these problems? Government planning at its finest!
That's pretty common with (non-classified) government security standards. A bunch of guys, often ones whose last industry experience occurred twenty years ago, get together and, after 2-3 years of often acrimonious committee meetings, throw together enough random features to call it a standard. Far too frequently what gets certified for govt.standards is whatever's possible to itemise in a checkbox rather than what would actually add security (I've seen stuff that's little removed from EU banana-bentness r
Re: (Score:2)
Re: (Score:2)
You left out the part where the biggest player in that industry produces a product that doesn't technically meet the standards, but is accepted anyway for your choice of reasons.
Oh, you can do much better than that: If you're the largest vendor, create a broken implementation of the spec, declare yourself to be fully compliant in your sales literature, and then threaten to prosecute any competitors who download your product in order to figure out what the fsck it's doing under the DMCA. This actually happened - your tax dollars at work.
Re: (Score:2)
Sneak and peek
Re: (Score:2)
WTF is one of that?
[googles] http://www.knoxbox.com/ [knoxbox.com]
Ah, that's WTF is one of that.
What a ... pointless idea. Above a certain size of premises, you have a "night watchman" ; below that size, a policeman, fireman or emergency medic who needs entry uses an appropriate tool on an appropriate window, after using a megaphone and sirens for an appropriate number of seconds on the approach to the building. Far, far quicker than wondering where the fuck this "key box" is.
One day one
good security (Score:2)
It's nice to know that those in charge of building the United States' very own Gestapo are also security experts. Too bad they're so good at the first task and so lousy at the second.
Also... (Score:1)
Re: (Score:2)
Security in depth... (Score:2)
Your post reminded me of something I haven't seen mentioned here -
In pretty much any system you're going to have numerous vulnerabilities, which you will mitigate with controls(being generic here).
Take a house or building. Incomplete list, of course:
Depending on attack, all of these are vulnerabilities:
Now, there's also covert and non-covert entry. Picking a lock is covert, busting a window isn't. It's a sliding scale really; busti
I guess all those cheesy movies/TV shows are right (Score:3)
You know, the ones where the character (usually a young, bright geek) rips the cover off the card swipe/keypad unit, shorts a few wires, and opens the door? ..bruce..
Re:I guess all those cheesy movies/TV shows are ri (Score:5, Interesting)
I got locked in my self-storage lot after staying past closing time (11 PM). There were no staff to let me out and I was trapped inside with only a keypad to open the gate which happily told me the lot was closed. After inspecting the gate I saw a what amounted to a key switch on a pole high enough for someone on a fire truck to access from the outside. I followed the conduit from that key switch to an electrical box near the gate motor. This small box was secured with one flat head screw, Armed with a paperclip I removed the screw and shorted the two wires coming from the key switch and the gate opened.
I don't know if I would have thought to do that if I wasn't inspired by the movies. It sure beat camping there for the night,
Re: (Score:2)
Necessity really IS the mother of invention.
Re: (Score:2)
Re: (Score:2)
An external verification controller isn't completely necessary to increase security. Just make the actuator more complicated to control.
If you use e.g. a BLDC motor (see http://en.wikipedia.org/wiki/Brushless_DC_electric_motor [wikipedia.org]) at the door, just sending some power done the control lines is at most going to burn the coils. controls have to be activated and deactivated in correct fashion (and current measured) for the motor to turn. Obviously people skilled enough can reverse engineer this. But connecting al
Re: (Score:2)
But think about the cost of that also not forgetting that if the control mechanism messes up, those motors if simply powered up can remain stationary and are virtually impossible to move. Most security is just to keep a simple thief out. An intelligent, dedicated, targeted attacker will always succeed if you give it enough resources. If nothing else I'll just get a plasma cutter and cut out your door.
Truth in television (Score:2)
"You know, the ones where the character (usually a young, bright geek) rips the cover off the card swipe/keypad unit, shorts a few wires, and opens the door?"
I swear to FSM I've done this.
I was meeting a friend of mine at a place. Door is protected by a keypad lock. When we get there he then realizes they just issued all new codes for the year, he can't remember his yet, and the paper with the new code is back at his place. I look at the box the keypad is mounted in, and notice it has two exposed screws.
I whip out my Leatherman and take the keypad off. There are four wires running to the keypad. I try randomly shorting two of the pins on the connector.
*clic
Re: (Score:2)
OK, I'm at my laptop, laughing out loud. Well done. ..bruce..
Attacks too easy? (Score:5, Interesting)
Isn't this pretty much an old trick, similar to 'bumping'?
This one's a lot more fun as you have to know where, approximately, that contact is - but then again, why is that contact accessible?
oh for pity's sake.
The first has already been solved by lockmakers, the second is solved by making the PCB reasonably inaccessible (an individual cover plate will do) which would also deal with the third, but then the third shouldn't be a switch anyway - it should be two distinct female header points on the PCB that can be bridged only with a length of wire; this is not a crappy home wireless router that actually needs a user-accessible reset button.
Whoever designed these $1k locks, electronically and mechanically, really need to go back to the drawing board... or school.
Re: (Score:2)
Re: (Score:2)
And a Dremel in the correct place (once you know where the contact needs to be) would've fixed that. Also, it makes the unit practically unfixable if necessary for whatever reason, you don't want to be throwing out $1k worth of product every time it fails.
Re: (Score:1)
I thought of this when I saw the summary:
http://www.youtube.com/watch?v=yp4LFuFCon0 [youtube.com]
Come on guys, don't you watch any movies?
From the movie Sneakers
Sun Microsystems knows this well (Score:2)
"It is important to realize that any lock can be picked with a big enough hammer." -- Sun System & Network Admin Manual
Re: (Score:2)
Isn't this pretty much an old trick, similar to 'bumping'?
Sadly, this is like bumping only with less finesse and no need to make a special bump key. For a $1300 lock, it's a damned sad showing. A $20 lock is actually a bitharder to crack.
No kidding for that price (Score:2)
I mean when you deal with physical security, you accept that there is no 100%. There is no unbreakable lock, no invincible door, and so on. However that doesn't mean everything is shit and money should get quality.
Compare that shit to a high security Medeco or Assa lock or the like. They can't be bumped, are hard to get keys copied for, can take a hell of a lot of physical abuse and so on, yet only cost about $200-300.
You are going to roll out a $1000 lock it need to at least give you the same kind of secur
Uber locks (Score:5, Informative)
You are going to roll out a $1000 lock it need to at least give you the same kind of security you'd get from one of those. They may not be perfect, but you can't stick a wire in them to get by them at least.
What's interesting is that Kaba Mas also makes the X-09, which is the current DoD uber-lock used for classified stuff. It is, by all reports, extremely hard to subvert.
Neat stuff.
Re: (Score:1)
The X-09 is just amazing - a bit of a pain in the ass, because the turning of the dial and the rate of numbers changing is never quite the same.
The self - powered thing is cool too - you spin the knob hard 3 or 4 times - the lcd display will appear - and it is good to go.
You are allowed to go past the number you want to n+3 where you can turn the dial 'backwards' and still pick-up the right number, at n+4 you have to start again.
The earlier model X-08 is largely the same - Led display and not quite as fancy
Re: (Score:2)
FWIW - the numbers for the combination are almost always remembered using a dictionary word - next to almost all locks you will see a drawing of a 12 button phone number / letter pad.
How sad that this piece of well-engineered technology can be subverted by something so simple... This drastically reduces the keyspace. It's not quite as bad as leaving the combination on a post-it, but it's still considerably degraded from what it should be.
Re: (Score:1)
They can't be bumped, are hard to get keys copied for, can take a hell of a lot of physical abuse and so on, yet only cost about $200-300.
You are going to roll out a $1000 lock it need to at least give you the same kind of security you'd get from one of those. They may not be perfect, but you can't stick a wire in them to get by them at least.
Oh come one, do you know just how EXPENSIVE the cost of living is in Switzerland compared to the USA? The Swiss get in trouble if the pop over the border to Germany and buy cheaper petrol and groceries!
Re: (Score:2)
What's bumping? Is that like on NCIS when DiNozzo says something stupid while standing with his back to Gibbs?
Re: (Score:2)
Coin-operated self-destruct - not one of my better ideas...
Re: (Score:2)
Exact change only.... duh!
Still a major defect (Score:3)
Unfortunately these locks still happily open the door when fired on by a blaster.
Re: (Score:1)
Unfortunately these locks still happily open the door when fired on by a blaster.
Gimme a light saber any day. This is the weapon of a Jedi Knight. Not as clumsy or random as a blaster; an elegant weapon for a more civilized age.
(In addition you can use it to cut through the door directly, even if the lock is blaster-proof).
Re: (Score:2)
"Unfortunately these locks still happily open the door when fired on by a blaster."
A standard cutting torch can be run off a medical oxygen cylinder and a disposable propane cylinder. Merely a matter of using standard fittings (and is a great back-saver, which is why it's done). Not much can stop a cutting torch, and for those obstacles you can spend more money for an exothermic rescue outfit.
Locks are intended to raise the barrier and require such messy means of entry.
Re: (Score:2)
Nice videos (Score:1)
In other news, people who attend Defcon are too cheap to use a Mac, upload bizarrely interlaced videos to YouTube because mencoder's command line cannot be understood by humans.
Disklocks are awesome... (Score:2)
If you could just implement a identifying credentials into these locks...
toool.nl/images/f/f3/Abloypart2.pdf (PDF)
Re: (Score:2)
Re: (Score:2)
And if that don't work... Try 4 pounds?
Although I learned from Mythbusters that different explosives have different purposes. For locks Thermite might be a better choice because it "cuts" meaning you'll still have a room on the other side of that door to rob!!!
The Swiss can make good rolexes but high priced lo (Score:2)
The Swiss can make good rolexes but high priced locks where you can get to bypass wire real easy.
any ways slots machines used to be easy to short out by doing some thing like this and they fixed them.
Exposed grounds/resets? (Score:4)
how about hardwired so there less need battery (Score:2)
how about hardwired so there less need for a some what easy to get to battery door / panel. Still can use a backup battery that is more sealed up.
But make so the lock can be in place where some one will see messing with it to bypass it and make take a little bit of time to bypass it as well.
It's tough to get security *right*s (Score:2)
It's pretty easy to put together a basic security system. Require an identity token of some sort, and require proof of knowledge of a secret, and you have the makings of a security system!
Security is not a boolean. Security is a variable, ranging from non at all to mild, moderate, to extremely secure.
Little things can greatly add greatly to real security (such as free permits for concealed weapons and password strength requirements), and big, obvious, "secure" things can easily be nothing more than theater.
Re: (Score:2)
Obviously, one has to be realistic in one's demands of devices built of pitifully limited matter; but even realistic demands won't save this design...
um... (Score:1)
My guess is that no matter how hack-proof they make this lock, with a 6l
Re: (Score:1)
NOPE. The point of "terror" is to be known, not to remain undetected. Breaching the damn lock is almost as good as getting to, busting, etc. whatever the lock is supposed to keep safe, inaccessible to the unauthorized, etc....
Re: (Score:2)
Most of this is to protect isolated control rooms... Think the water testing valve for a city wellhead. Once you are in and deal damage, you'll have plenty of time to flee, damage will actually happen up to miles away from here.
The USA is dotted with power, telco, gas, water lines that cross miles of country. Hell, most of my local utility offices are "unattended" now. Just plain brick buildings.
Re: (Score:1)
If what's being "protected" is a part of the Dept of Homeland Security I'd say my few nickles worth of pop culture is far more valueable. Of course I have a more tamper-resistent lock, from Ace hardware....
Re: (Score:1)
My father locked certain power tools in a steel 'sea chest' because he didn't want me using them. I quickly sanded down one end of the hinge pins on the two hinges on the chest. Thus I could easily slip the hinges and get access to the tools when needed. I didn't tamper with the lock in any obvious way, and from then on always had access to those tools.
These don't leave any visible damage (Score:2)
Did you watch the videos? The first two don't leave any visible damage and the third one is hard to detect.
Re: (Score:2)
um yea if your liquor lock issue had a big squishy silicone window to a "opps reset to unlock mode" that you could trip with a key-chain swiss army knife, cost a grand doing it, while being marketed to our dumb government, then you would have a point.
Re: (Score:3)
A 6lb maul? You joking? I have an 8lb demolition hammer, and I wished I had something bigger when doing a rather "simple" remodel of a room and demolition of a deck. 8lb was barely enough to get a slightly curvy 6.5' 2x10 header in place...
I've seen plenty of doors where even a 24lb demolition hammer would perhaps dent them and scratch the paint, and not much else. Since I had to replace the front doors on my house, I did try the 8lb hammer on them. By my estimate, it'd take me half a day of pounding and sw
Re: (Score:2)
There's a quicker, quieter way (Smith linked because they are very well made in the USA):
http://store.cyberweld.com/porwelkit.html?utm_medium=shoppingengine&utm_source=googlebase&cvsfa=2530&cvsfe=2&cvsfhu=706f7277656c6b6974 [cyberweld.com]
Re: (Score:2)
Very nice. Thanks for the link.
Hammer method might not work? (Score:4, Insightful)
Pretty Sneaky Sis (Score:2)
Still prefer the "Sneakers" solution to a locked, secured room sporting a very hard to crack keypad combination lock on the door.
It was not only one of the best scenes in the movie but should cause anyone faced with an impossible problem to stop for a moment and think outside the box. If your problem is in the box, then move the box. You will eventually find a way to crush it.
For those who have not seen the film or won't bother, the secret solution to the ultra secure keypad lock is to.... kick the door i
Re: (Score:2)
One of my old BJJ instructors always carries a knife to make emergency exits through drywall. Kept his ads from being jumped by a gang of guys in Brazil, once.
Re: (Score:2)
Even if the wall is made of cement blocks, it should only take a good chisel and a 4lb hammer to get through. Perhaps if you're in shape a 6lb hammer will make the job quicker, but I don't recommend it if you don't use it regularly. Once you get two blocks out, the rest will be like eating cheesecake: smooth and easy goin'. Brick walls are easier once you start, but may be harder to break through the first brick or two. If there's two of you -- to start let one hold the chisel, while the other one uses an 8
Re: (Score:2)
Our front door is steel, in a concrete wall and opens out. Before you break your leg or get the jack hammer out, though, I'd recommend jumping onto our balcony and breaking the glass in the sliding doors.
Re: (Score:2)
Re: (Score:2)
With proper security, you shouldn't be left unattended with that axe very long.
But in this case the intention is to protect utility control rooms and such... What protects a cell phone tower from hackers just going inside and plugging in? Or just turning the thing OFF? That's what these are marketed for, the HUGE amount of infrastructure in the USA that is basically kept in "doghouses".
Re: (Score:2)
For those who have not seen the film or won't bother, the secret solution to the ultra secure keypad lock is to.... kick the door in.
Sometimes it can be almost as useful to know that a lock has been compromised as it is to have it remain secure.
Kicking in the door (and variations on that theme) certainly provides access to the locked space, but it provides undetected, unaudited access only until the security guard or cleaning staff make their next trip down the hall. Depending on what's on the other side of that door, a few minutes of readily-detected, one-time access may be quite a bit less harmful than months of covert access.
I would have liked to seen the demo done properly (Score:3)
1300$ (Score:2)
The IT Crowd (Score:2)
Turning it off and on again, usually helps :)
Re: (Score:1)
Above comment MINE get so PO'd about the whole war on terrorism - perhaps not as bad as the war on drugs at least there is a problem in there somewhere and maybe an enemy somewhere as well...that I FORGOT I was not logged in, thought I had that on auto, guess not lol
Re: (Score:1)
Exactly. No such thing as security, although there are such things as making "violations" more difficult or maybe even trying to do somehing to reduce, punish, or otherwise affect the number doing "violations" ("violations" = whatever the F a "breach of "Security" is for the matter at hand, if any)
Re: (Score:2)
Instead of metal, the main material in a modern vault door is a proprietary concrete mix that has more than ten times the strength of a similar thickness of standard reinforced concrete. Even a thermal lance is impractical, hours needed to make a small hole