* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, July 16, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Rough times for broadcast networks illustrate changing media landscape – New Haven Register

    Broadcast Networks Confront Turbulent Times in a Rapidly Changing Media Landscape

    Black River Entertainment Adds Traci Hite As Director Of Promotion, Southeast – MusicRow.com

    Black River Entertainment Welcomes Traci Hite as New Director of Southeast Promotion

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Victorville’s new gunfire-detecting technology already making strides, city says – NBC Los Angeles

    Victorville’s New Gunfire-Detecting Technology Is Already Making a Difference, City Officials Say

    Guest columnist: China cutting corners on technology – The State Journal

    China’s Rapid Tech Advances Spark Worries About Cutting Corners

    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Rough times for broadcast networks illustrate changing media landscape – New Haven Register

    Broadcast Networks Confront Turbulent Times in a Rapidly Changing Media Landscape

    Black River Entertainment Adds Traci Hite As Director Of Promotion, Southeast – MusicRow.com

    Black River Entertainment Welcomes Traci Hite as New Director of Southeast Promotion

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Victorville’s new gunfire-detecting technology already making strides, city says – NBC Los Angeles

    Victorville’s New Gunfire-Detecting Technology Is Already Making a Difference, City Officials Say

    Guest columnist: China cutting corners on technology – The State Journal

    China’s Rapid Tech Advances Spark Worries About Cutting Corners

    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

3 million doors open to uninvited guests in keycard exploit

March 24, 2024
in Technology
3 million doors open to uninvited guests in keycard exploit
Share on FacebookShare on Twitter

Around 3 million doors protected by popular keycard locks are thought to be vulnerable to security flaws that allow miscreants to quickly slip into locked rooms.

Security researchers developed an exploit that applies to various Saflok keycard locks made by Swiss security company dormakaba, ones that are prevalent in hotels around the world, as well as properties of multiple occupancy.

The researchers who worked on the exploit, dubbed “Unsaflok,” said more than 3 million hotel locks across 131 countries are affected.

Lennert Wouters, Ian Carroll, rqu, BusesCanFly, Sam Curry, sshell, and Will Caruana reported the vulnerabilities to dormakaba in September 2022 and disclosed them this week.

Saflok MT and Saflok RT Plus are the most common models people may have encountered on their travels, although all locks using the Saflok system are vulnerable – these include door locks, and the keycard readers used in elevators and parking garages.

A keycard from the property an intruder wants to break into is required to pull off the attack. This could be a valid card such as one issued to the intruder’s own hotel room, or even an expired one swiped from the express checkout deposit bin.

From there, two cards would need to be created – one to rewrite the data on the lock and another to open it, the researchers explained to Wired. This could all be done using commercially available equipment, including a Flipper Zero or even an NFC-capable Android phone, and a few MIFARE Classic cards.

It would also require the intruders to reverse engineer the software used by hotel front desk staff to reprogram keycards to locks. Hotels that use these locks, of which there are more than 13,000 around the world, typically use System 6000 or Ambience for the management of keycards, researchers said. 

El Reg asked dormakaba to comment, and we’ll add that in if we hear back. According to the researchers’ writeup on Unsaflok, the manufacturer started working on a fix in November 2023, more than a year after the vulnerabilities were discovered.

That fix has now been developed, but apparently the process of getting these locks updated, or in some cases replaced entirely, is a bit of a chore. That’s illustrated by the rate of upgrades so far, which stands at just 36 percent of all affected locks.

It’s not just the door locks that need upgrading – the hotel software also needs upgrading, as do the keycard encoders, and the keycards themselves. The researchers said the keycards may actually be a giveaway to anyone wanting to know if their lock is free from forgeries.

Hackers remotely start, unlock Honda Civics with $300 tech

Key to success: Tenants finally get physical keys after suing landlords for fitting Bluetooth smart-lock to front door

We don’t want to be Latch key-less kids: NYC tenants sue landlords for bunging IoT ‘smart’ lock on their front door

Hotel, motel, Holiday Inn? Doesn’t matter – they may need to update their room key software

“It is not possible to visually tell if a lock has been updated to fix these vulnerabilities,” they said. “You may be able to tell if a hotel has been through the upgrade process if the guest keycards are using MIFARE Ultralight C cards instead of MIFARE Classic.”

NFC reader apps available on Android and iOS can present this kind of data, and well-informed front desk staff may be able to let guests know too.

“Note that this information only applies to dormakaba Saflok systems; several other lock manufacturers use MIFARE Classic keycards and are not affected by the Unsaflok vulnerability. Nevertheless, the use of MIFARE Classic in a security-sensitive application is not recommended.”

There’s no available evidence to suggest that these locks have been bypassed in historical intrusion attempts, however, the vulnerabilities have been present in Saflok systems for more than 36 years … so that’s a pretty long window in which they could have been exploited before.

While it is possible to detect for unauthorized intrusions by auditing each lock’s entry and exit logs, the researchers said due to the nature of the vulnerability, these logs could be misattributed to a different keycard or even a staff member.

Full details of the vulnerabilities, which are chained together to forge these keycards, haven’t been revealed yet and won’t be for some time out of fears that an explosion in intrusions will take place while hotels upgrade.

“We are not planning on sharing a full proof of concept at this time due to the potential impact to hotels and guests,” the researchers said. “We plan on sharing additional technical details of the vulnerability in the future.”

Unsaflok certainly isn’t a first-of-its-kind type of exploit, as other security whizzes have broken into other keycard systems before.

Back in 2018, before its enterprise arm split off to WithSecure, F-Secure publicized exploitable flaws in VingCard’s Vision system, which is also used to secure millions of rooms worldwide, although only a small proportion of these were thought to be exploitable.

Going back to 2012, researchers demonstrated a way to break into Onity locks too during that year’s Black Hat event – the same event that saw Unsaflok flaunted in 2022, albeit behind the closed doors of a private security competition to which the researchers were invited. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/03/22/tap_and_go_straight_to/

Tags: DOORSMilliontechnology
Previous Post

‘Kavya Maran Moye Moye Moment’, Social Media Reacts On SRH Owner’s Roller-Coaster Of Emotions After Team’s Defeat In IPL 2024

Next Post

Uncle Sam wants to know how big airlines use passenger data

AC Milan and PUMA Golf Tee Off with a Lifestyle-Driven Capsule Collection – stupidDOPE

AC Milan and PUMA Golf Tee Off with a Lifestyle-Driven Capsule Collection – stupidDOPE

July 16, 2025
Donald Trump reaps $50bn tariff haul as world ‘chickens out’ – Financial Times

Donald Trump reaps $50bn tariff haul as world ‘chickens out’ – Financial Times

July 16, 2025
China GDP: Economic growth beats expectations as Trump tariffs loom – BBC

China’s Economy Soars Past Expectations Despite Threat of Trump Tariffs

July 16, 2025
Iconic ’90s Singer’s Latest Announcement Is an Early Invite to ‘Rock Around the Christmas Tree’ – Yahoo

Iconic ’90s Singer Scores Early Invite to Rock Around the Christmas Tree Celebration

July 16, 2025
Subcommittee on Health Holds Hearing on Preserving Access to Timely and Affordable Care – House.gov

Subcommittee on Health Holds Hearing to Protect Timely and Affordable Care Access

July 16, 2025
MAGA supporter: Self-deportations are not scary, they get $1K and a free plane ticket – CNN

MAGA supporter: Self-deportations are not scary, they get $1K and a free plane ticket – CNN

July 16, 2025
Victorville’s new gunfire-detecting technology already making strides, city says – NBC Los Angeles

Victorville’s New Gunfire-Detecting Technology Is Already Making a Difference, City Officials Say

July 16, 2025
Sinclair Continues Expansion of AMP Media Podcast Slate with New Local Sports Podcasts – Sinclair, Inc

Sinclair Continues Expansion of AMP Media Podcast Slate with New Local Sports Podcasts – Sinclair, Inc

July 16, 2025
Birds documenting the Anthropocene: Stratigraphy of plastic in urban bird nests – Hiemstra – 2025 – Ecology – ESA Journals

Birds documenting the Anthropocene: Stratigraphy of plastic in urban bird nests – Hiemstra – 2025 – Ecology – ESA Journals

July 16, 2025
The 100-year journey from quantum science to quantum technology – Phys.org

The 100-year journey from quantum science to quantum technology – Phys.org

July 16, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (723)
  • Economy (747)
  • Entertainment (21,633)
  • General (15,932)
  • Health (9,785)
  • Lifestyle (755)
  • News (22,149)
  • People (748)
  • Politics (758)
  • Science (15,965)
  • Sports (21,245)
  • Technology (15,730)
  • World (731)

Recent News

AC Milan and PUMA Golf Tee Off with a Lifestyle-Driven Capsule Collection – stupidDOPE

AC Milan and PUMA Golf Tee Off with a Lifestyle-Driven Capsule Collection – stupidDOPE

July 16, 2025
Donald Trump reaps $50bn tariff haul as world ‘chickens out’ – Financial Times

Donald Trump reaps $50bn tariff haul as world ‘chickens out’ – Financial Times

July 16, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version