Smart locks: dumb security, dumber API

No ratings

Presented at BSidesAthens 2019 by

The rise of cheap, low powered communication technology has been most prominent in the fields of locks, where the traditional model of a key, rfid reader or magnetic stripe does not work for many use cases. This talk will be demonstrating how many smart locks fail to fully think out security and in many ways make the smart locks weaker than its low-tech equivalent.Some of these methods will be destructive, as much as can be done in an unventilated room at least. We will be going through several smart locks, all designed for convenience and showing where the security flaws are and the different vectors to attack. Some locks will be focused on, specifically the Nokelock series of products, the slok lock and ultraloq. Including demonstration of how the protocols were reversed and how they can be used to unlock a padlock from a python script or Android device. Just for Bsides Athens, we will be focusing on the API that supports most of these devices and their weaknesses, which often make it possible to not only compromise a lock, but prevent the lock’s owner from using their own lock.