{"id":21504,"date":"2018-05-23T15:39:44","date_gmt":"2018-05-23T14:39:44","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=21504"},"modified":"2018-05-23T15:39:44","modified_gmt":"2018-05-23T14:39:44","slug":"master-keys-to-hotels-can-be-created-out-of-thin-air","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/05\/23\/master-keys-to-hotels-can-be-created-out-of-thin-air\/","title":{"rendered":"Master keys to hotels can be created &#8216;out of thin air&#8217;"},"content":{"rendered":"<p>F-Secure researchers have found that global hotel chains and hotels worldwide are using an electronic lock system that could be exploited by an attacker to gain access to any room in the facility. The design flaws discovered in the lock system\u2019s software, which is known as Vision by VingCard and used to secure millions of hotel rooms worldwide, have prompted the world\u2019s largest lock manufacturer, Assa Abloy, to issue software updates with security fixes to mitigate the issue.<\/p>\n<p>The researchers\u2019 attack involves using any ordinary electronic key to the target facility \u2013 even one that\u2019s long expired, discarded, or used to access spaces such as a garage or closet. Using information on the key, the researchers are able to create a master key with privileges to open any room in the building. The attack can be performed unnoticed. <\/p>\n<p>\u201cYou can imagine what a malicious person could do with the power to enter any hotel room, with a master key created basically out of thin air,\u201d said Tomi Tuominen, Practice Leader at F-Secure Cyber Security Services. \u201cWe don\u2019t know of anyone else performing this particular attack in the wild right now.\u201d<\/p>\n<p>The researchers\u2019 interest in hacking hotel locks was sparked a decade ago when a colleague\u2019s laptop was stolen from a hotel room during a security conference. When the researchers reported the theft, hotel staff dismissed their complaint given that there was not a single sign of forced entry and no evidence of unauthorised access in the room entry logs. The researchers decided to investigate the issue further and chose to target a brand of lock known for quality and security. These security oversights were not obvious holes. It took a thorough understanding of the whole system\u2019s design to identify small flaws that, when combined, produced the attack. The research took several thousand hours and was done on an on-and-off basis and involved considerable amounts of trial and error.<\/p>\n<p>\u201cWe wanted to find out if it\u2019s possible to bypass the electronic lock without leaving a trace,\u201d said Timo Hirvonen, Senior Security Consultant at F-Secure. \u201cBuilding a secure access control system is very difficult because there are so many things you need to get right. Only after we thoroughly understood how it was designed were we able to identify seemingly innocuous shortcomings. We creatively combined these shortcomings to come up with a method for creating master keys.\u201d<\/p>\n<p>F-Secure notified Assa Abloy of the findings and has collaborated with the lockmaker over the past year to implement software fixes. Updates have been made available to affected properties.<\/p>\n<p>\u201cI would like to personally thank the Assa Abloy R&amp;D team for their excellent cooperation in rectifying these issues,\u201d said Tuominen. \u201cBecause of their diligence and willingness to address the problems identified by our research, the hospitality world is now a safer place. We urge any establishment using this software to apply the update as soon as possible.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>F-Secure researchers have found that global hotel chains and hotels worldwide are using an electronic lock system that could be exploited by an attacker to gain access to any room in the facility. The design flaws discovered in the lock system\u2019s software, which is known as Vision by VingCard and used to secure millions of [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":21505,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,999,14,29],"tags":[7084,3407,7085,7083],"class_list":["post-21504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-hospitality","category-more-news","category-software","tag-assa-abloy","tag-f-secure","tag-master-keys","tag-vision-by-vingcard"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=21504"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21504\/revisions"}],"predecessor-version":[{"id":21506,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/21504\/revisions\/21506"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/21505"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=21504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=21504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=21504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}