Features Podcasts Family Video Comics Music Tech Science Books Film & TV Games ✚

Jill

Hotel break-ins blamed on flaw in keycard system

Cory Doctorow at 9:29 pm Mon, Nov 26, 2012

— FEATURED —

THE LATEST

Guatemala: Archive of documents from Rios Montt genocide trial, overturned 10 days after guilty verdict

Feature

Eurovision 2013: An American in London

Book Review

The Twelve-Fingered Boy - mesmerizing YA horror novel

Book Review

Black Code: how spies, cops and crims are making cyberspace unfit for human habitation

— FOLLOW US —

Boing Boing is on Twitter and Facebook. Subscribe to our RSS feed or daily email.

 

— POLICIES —

Except where indicated, Boing Boing is licensed under a Creative Commons License permitting non-commercial sharing with attribution

 

— FONTS —

Tweet
Kindle

Back in August, I blogged about a presentation at Black Hat, where a security researcher named Cody Brocious presented a paper on a vulnerability in hotel-door locks made by Onity, showing a method for opening many hotel-room locks with a simple, Arduino-based device.

Now comes the first reported case of a hotel-room break in using this technology "in the wild." A Hyatt in Houston's Galleria district was broken into using this method, according to the hotel, which had not replaced its locks even though it knew about the vulnerability.

In a statement sent to me, a White Lodging spokesperson says the company became aware of the vulnerability in its Onity locks in August, based on reading one of the stories I wrote about Brocious’s lock-hacking technique over the summer. But White Lodging says Onity only implemented a fix for that flaw in its locks after the September break-ins at the Houston Hyatt, around two months after I first alerted Onity to Brocious’s work.

Following those September incidents, White Lodging resorted to plugging the port at the bottom of its Onity locks with “epoxy putty,” according to the letter it sent to guests at its Houston location. The hotel company says it’s now working with Onity to put a more permanent solution in place, either plugging the locks’ ports or replacing their circuit board at every location it manages. “We sincerely regret that these thefts occurred, and hope that measures we have taken satisfy your concerns,” reads the letter to guests from White Lodging vice president Thomas Riegelman.

Security Flaw In Common Keycard Locks Exploited In String Of Hotel Room Break-Ins [Forbes/Andy Greenberg]

I write books. My latest is a YA science fiction novel called Homeland (it's the sequel to Little Brother). More books: Rapture of the Nerds (a novel, with Charlie Stross); With a Little Help (short stories); and The Great Big Beautiful Tomorrow (novella and nonfic). I speak all over the place and I tweet and tumble, too.

MORE:  crime • Gadgets • houston • security • tx

More at Boing Boing

Eurovision 2013: An American in London

The technology that links taxonomy and Star Trek

  • http://glitch.tl/ Michael Smith

    Maybe they should disable those ports with a 3mm drill bit prior to plugging them with putty.

  • Steve Allen

    So the difference between the past and present is that tension wrench and pick took skill, but this requires only being a geek?

    • http://imcravingpresidency.tumblr.com/ SedanChair

      Many geeks enjoy lockpicking and hacking equally well.

  • http://profile.yahoo.com/JW62NF6KZ6RXV3MQDTPNI7DY4M Ryan

    “………..No moleste..”

  • pupdog

    I thought part of the original report was that the ports were on the inside of the door/lock set, not externally available. Putting a programming port for a lock on the outside of the lock just seems like asking for trouble…