HN Theater @HNTheaterMonth

The best talks and videos of Hacker News.

Hacker News Comments on
DEF CON 30 - Miana E Windall, Micsen - Digital Skeleton Keys

DEFCONConference · Youtube · 14 HN points · 0 HN comments
HN Theater has aggregated all Hacker News stories and comments that mention DEFCONConference's video "DEF CON 30 - Miana E Windall, Micsen - Digital Skeleton Keys".
Youtube Summary
Offline RFID systems rely on data stored within the key to control access and configuration. But what if a key lies? What if we can make the system trust those lies? Well then we can do some real spooky things…
This is the story of how a strange repeating data pattern turned into a skeleton key that can open an entire range of RFID access control products in seconds.
HN Theater Rankings

Hacker News Stories and Comments

All the comments and stories posted to Hacker News that reference this video.
Nov 09, 2022 · 14 points, 2 comments · submitted by muffe
muffe
It turns out, offline access control systems with no central server are a very bad idea. Not only does this attack open any SmartAir lock in literally seconds, it leaves very little information behind on the lock. For instance, if you try to retrieve the log, it won't even show that the door was opened at the time of the attack, as the attack uses an invalid user ID that the lock happily accepts but the log blocks. Fantastic!
nullish_signal
Wew, good thing the log is secured from invalid user IDs
HN Theater is an independent project and is not operated by Y Combinator or any of the video hosting platforms linked to on this site.
~ yaj@
;laksdfhjdhksalkfj more things
yahnd.com ~ Privacy Policy ~
Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.