Trill News

You miss 100% of the shots you don't take. — Wayne Gretzky
STEM

Hackers Can Open 3 Million Hotel Keycard Locks in Seconds

Hackers Can Open 3 Million Hotel Keycard Locks in Seconds
Vacancy (48780572076) by James Kerwin Photographic (www.jameskerwin.uk) (CC BY 2.0)
Security researchers developed a technique called "Unsaflok" that allows them to open millions of hotel room doors globally by exploiting vulnerabilities in Dormakaba’s Saflok brand RFID locks.

By using a pair of forged keycards, hackers can override the lock's encryption in seconds, a flaw that persists across three billion hotel rooms despite ongoing efforts to patch the systems.
Two forged keycards written with a $300 reader can open any door in a hotel running Dormakaba Saflok locks, a system on three million doors across 13,000 properties in 131 countries that shipped vulnerable beginning in 1988 Wired. Only 36 percent carried the fix at disclosure in March 2024 BleepingComputer; researchers later said most locks were upgraded, converted manually at roughly 500 properties a week in a process owners must fund. Hoteliers pay and guests carry the risk, and the deadbolt gives no cover because the compromised lock controls it too. When Onity refused to pay for fixes after its 2012 hack, many of its locks stayed vulnerable for years.

Read the original reporting at Wired.

Read Full Story at Wired →

FIND A BOOK ON BOOKSHOP.ORG