https://www.schneier.com/blog/archives/2024/03/security-vulnerability-in-safloks-rfid-based-keycard-locks.html

„A team of […] security researchers are revealing a #hotel #keycard hacking technique they call #Unsaflok. The technique is a collection of #security vulnerabilities that would allow a hacker to almost instantly open several models of #Saflok-brand #RFID-based keycard locks sold by the Swiss lock maker Dormakaba. The Saflok systems are installed on 3 million doors worldwide, inside 13,000 properties in 131 countries.“

Security Vulnerability in Saflok’s RFID-Based Keycard Locks - Schneier on Security

Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds

exploiting weaknesses in encryption and the underlying RFID system, hackers obtain any keycard from a target hotel, read the code from the card and write two keycards of their own - then they merely tap those two cards on a lock

#BlackHat #DefCon #LasVegas #Dormakaba #Saflok #RFID #travel #hotels #security #cybersecurity #hacking #hackers

https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/

Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.

WIRED
Millions of Dormakaba Saflok RFID Locks Vulnerable to Security Breach

A Vulnerability Exposes Hotels and Homes Across 131 Countries to Unauthorized Entry

Review Space
Unsaflok flaws allow to open millions of doors using Dormakaba Saflok electronic locks

A flaw in Dormakaba Saflok electronic locks, dubbed Unsaflok, can allow threat actors to open millions of doors worldwide.

Security Affairs

[en] Serious security vulnerabilities in electronic RFID locks from dormakaba

"... identified weaknesses allow an attacker to unlock all rooms in a hotel using a single pair of forged keycards. Over [3m] hotel locks in 131 countries are affected."

"As of 03/2024, ... 36% of the impacted locks have been updated or replaced."

https://unsaflok.com/

#ResearchHighlights #dormakaba #kaba #saflok #unsaflok #privacy #rfid #rfidlock #cybersecurity #ictsecurity #itsecurity #infosec #security

Unsaflok

Unsaflok is a series of serious security vulnerabilities in the Saflok brand of hotel locks.

Unsaflok
The use of MIFARE Classic already made it possible to clone the #Saflok keys at will, assuming you had even passing access to the key to clone. This was possible since you've been able to obtain UID programmable cards/fobs from china for over a decade, and thus produce 100% clones of MIFARE Classic cards/fobs. The actual key #Unsaflok finding is the generation of Skeleton keys that open all doors.
“Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds - The company behind Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels” https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/ #locks #research #security #physicalsecurity #physsec #saflok #defcon
Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.

WIRED
Classic example of #securitybyobscurity ending badly: "To clone the cards, they had to crack #dormakaba's key derivation function. ... Forged keycards can be created using any #MIFAREClassic card."
https://www.bleepingcomputer.com/news/security/unsaflok-flaw-can-let-hackers-unlock-millions-of-hotel-doors/ #Unsaflok #vulnerability #infosec #cybersecurity #Saflok
Unsaflok flaw can let hackers unlock millions of hotel doors

Security vulnerabilities in over 3 million Saflok electronic RFID locks deployed in 13,000 hotels and homes worldwide allowed researchers to easily unlock any door in a hotel by forging a pair of keycards.

BleepingComputer

WIRED: Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds. The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels. 🔗 https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/

#keycard #Saflok #physicalsecurity

Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.

WIRED

#Hackers Found a Way to Open Any of 3 Million #Hotel #Keycard Locks in Seconds

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.
#saflok #security #privacy

https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/

Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.

WIRED