Welcome, Guest |   Sign In   |   Register  
 
Print Email Page RSS Feeds

Posted Date: 11/28/2012

Locking Hack Draws Fire for Both Hotel and Vendor

A recent article by Andy Greenberg in Forbes details a string of break-ins that hit a Houston-based Hyatt in September of 2012, the result of hackers using a digital tool to trigger the opening mechanism on the hotel’s Onity locks.
 
This security flaw was first publicly demonstrated by Cody Brocious, a 24-year-old software developer for Mozilla, at the Black Hat hacker conference in July. Brocious reverse-engineered Onity’s locks and discovered he could spoof the “portable programmer” device meant to be used for designating master keys and opening locks whose batteries had died.
   
White Lodging, the Hyatt franchisee that manages the Houston hotel, believes that the rooms were opened using this device. At the Black Hat conference, Brocious showed it was possible to insert the plug of a small device he built with less than $50 in parts into the port at the bottom of any Onity keycard lock, read the digital key that provides access to the opening mechanism of the lock, and open it instantaneously.
 
White Lodging contends that Onity only implemented a fix for that flaw in its locks after the September break-ins at the Houston Hyatt, around two months after Andy Greenberg, the Forbes reporter, first alerted Onity to Brocious’s work.
 
Following those September incidents, White Lodging resorted to plugging the port at the bottom of its Onity locks with “epoxy putty,” according to the letter it sent to guests at its Houston location. The hotel company says it’s now working with Onity to put a more permanent solution in place, either plugging the locks’ ports or replacing their circuit board at every location it manages.  
 
But even Onity’s official response, has drawn ire because rather than paying for the full fix itself, which requires a new circuit board for every affected lock, Onity has asked its hotel customers to cover the cost of those hardware replacements. The free alternative involves merely blocking the port on the bottom of the lock instead with a plastic plug and changing the screws on the locks to a more obscure model to make it harder to open the locks’ cases and remove the plugs.
 
Read the full story here.

Rate this Content (5 Being the Best)
12345
Current rating: 0 (0 ratings)
 


Profiling the Restaurant of the Future Profiling the Restaurant of the Future
4/24/2013
The restaurant industry is rapidly changing as consumers have unprecedented abilities to drive their engagement with quick service and casual restaurants. Find out what technologies will give restaurants a competitive advantage in this future-looking whitepaper.



Download Now

2013 Security Showcase 2013 Security Showcase
5/8/2013
With the ever-changing payment landscape, security is a top concern for hospitality operators. In an increasingly mobile culture there are more touchpoints than ever that need protection from data breaches. This report highlights several of the latest additions to the security landscape that run the gamut from wireless networks, tokenization, encryption, and PCI requirements.
Download Now

Wi-Fi & the Bottom Line: Forrester Measures Impact of Connectivity on Hotel Guest Satisfaction & Staff Productivity
6/6/2013 2:00:00 PM (EST)
Moderator:
Abigail Lorden, Editor-in-Chief, Hospitality Technology
Panelists:

Andre Kindness, Principal Analyst - Infrastructure & Operations Professionals, Forrester Research, Inc.
Tom Moore, Director of Hospitality Industry Solutions, Motorola Solutions
Register Now


MEDIA KIT | EDITORIAL CALENDAR | PRIVACY STATEMENT | TERMS & CONDITIONS | CONTACT US
All materials on this site Copyright Edgell Communications. All rights reserved.