Slashdot Mirror


Defcon Hacks Defeat Card-And-Code Locks In Seconds

Sparrowvsrevolution writes "At the Defcon security conference in Las Vegas, Marc Weber Tobias and Toby Bluzmanis plan to demonstrate simple hardware hacks that expose critical security problems in Swiss lock firm Kaba's E-plex 5800 and its older 5000. Kaba markets the 5800 lock, which Bluzmmanis says can cost as much as $1,300, as the first to integrate code-based access controls with a new Department of Homeland Security standard that goes into effect next year and requires identifying credentials be used in secure facilities to control access. One attack uses a mallet to 'rap' open the lock, another opens the lock by putting a pin through the LED display light to ground a contact on the circuit board, and a third uses a wire inserted in the lock's back panel to hit a switch that resets its software."

4 of 144 comments (clear)

  1. Attractive Nuisance by retroworks · · Score: 5, Insightful

    Legally speaking, an "unhackable" security system is starting to resemble an attractive nuisance. Design utmost security, you are inviting hackers, thereby defeating your trespass claims...

    --
    Gently reply
  2. made to government spec by magarity · · Score: 5, Interesting

    a new Department of Homeland Security standard that goes into effect next year
     
    How many places will buy them because they meet this government spec without regard to these problems? Government planning at its finest!

  3. Re:I guess all those cheesy movies/TV shows are ri by mea_culpa · · Score: 5, Interesting

    I got locked in my self-storage lot after staying past closing time (11 PM). There were no staff to let me out and I was trapped inside with only a keypad to open the gate which happily told me the lot was closed. After inspecting the gate I saw a what amounted to a key switch on a pole high enough for someone on a fire truck to access from the outside. I followed the conduit from that key switch to an electrical box near the gate motor. This small box was secured with one flat head screw, Armed with a paperclip I removed the screw and shorted the two wires coming from the key switch and the gate opened.

    I don't know if I would have thought to do that if I wasn't inspired by the movies. It sure beat camping there for the night,

  4. Uber locks by DragonHawk · · Score: 5, Informative

    You are going to roll out a $1000 lock it need to at least give you the same kind of security you'd get from one of those. They may not be perfect, but you can't stick a wire in them to get by them at least.

    What's interesting is that Kaba Mas also makes the X-09, which is the current DoD uber-lock used for classified stuff. It is, by all reports, extremely hard to subvert.

    • * Self-powered. No battery or external power supply needed.
    • * The exposed side has an LCD and a dial. Everything else is inside the security boundary. If you break the dial off you just make entry harder.
    • * The LCD is designed to only be viewable by someone standing right at the lock. Someone standing next to you can't snoop the numbers.
    • * The rate at which the dial causes numbers to change varies randomly with each step of the combination. Someone standing next to you can't derive the numbers from the rate at which you turn the dial.
    • * If the dial is turned too at regular a pace, the lock assumes you're an auto-dialer and shuts down.
    • * Repeated wrong combinations result in progressively longer lockout delays.
    • * You can view how many unsuccessful attempts have been made (allows you to audit to see if someone's tried to get in).

    Neat stuff.

    --

    dragonhawk@iname.microsoft.com
    I do not like Microsoft. Remove them from my email address.