Showing posts with label keyless. Show all posts
Showing posts with label keyless. Show all posts

Wednesday, September 17, 2014

My smartphone is my key: Musings on the security of Smart-padlocks

Keys can be a bother. You forget them inside the apartment, they're stuck in a pocket or bag with your arms full, or you just lose them. When I was in high school, combination locks really appealed to me: no keys to misplace, just a simple three number combination to remember. Awesome, until the first time I forgot my combination after gym class. One pair of bolt cutters and I was able to change for my next class, but I was out one fancy combination lock. Potential memory lapses(my head is full of much more today than back in high school) rendered combination locks more of a hindrance than boon.

In previous years solutions to my problems with hotel keys and my house keys have arrived, but until the recent Noke(pronounced 'No Key') Kickstarter campaign I didn't have a reasonable way to replace the keys to my padlocks. Fortunately for me, the people at FŪZ Designs have thrown physical keys and combinations out to create a smart-padlock.

Smartphones? Now, smart-padlocks.

No more forgotten combinations?
Like a door from Star Trek, just walking up to your Noke lock with your smartphone unlocks it. For some of my more efficiency-minded friends that easily saves them seconds in their day. Given that the associated lock control apps let one control the unlock distance, I'm not too worried that attackers will steal things from my locker or ride off with my bike before I've gotten to them.

One can shorten the unlock distance via the control app.

The Noke lock actually shares more with the ignition lock in a modern car than with that old combination lock on my high school locker. Like the car without a new Transponder key, the Noke can be set so that it won't open without your smartphone. Of course that would just turn your smartphone into the key; lose your phone or let it run out of power and you've lost your key.  The designers have thought of that; they include a way to unlock the Noke with a 'Quick-Click' code. That code of course being the spiritual successor to my old nemesis the 'Combination'.
The Quick-Click code is a good backup opening method when you don't have your phone.

Truthfully the Quick-Click code, utilizing the shackle(that metal U-shaped part at the top) of the lock to enter the combination, is quite brilliant. While one could say it is a cousin of the original combination on a lock, its purpose is more like that spare key you keep under the doormat or that rock in your front yard.

Almost like Morse Code, one enters a series of short and long 'clicks' of the shackle. Entering the wrong code not only delays you but doing so 5 times disables this manual unlock method. Attackers trying to brute force the combination will get shut out.

Attacks against padlocks
I have friends who practice Locksport(recreationally playing with locks they own, looking for ways to bypass or 'lockpick' them). They're the sort to be first in line to buy a Noke once they hit the market. It's exactly the sort of puzzle they'd find amusing.

I'd already learned about the simplest physical attack from the teachers cutting my padlock off with the bolt cutters in school. The Noke has a hardened shackle to defeat this sort of attack. The physical security of the Noke could be bypassed with sufficient force, but it would lead to exposure of the attacker.

My Locksport friends have shown me more elegant means, such as the easy to make soda can shim. In a standard padlock the only thing holding the shackle locked is a spring loaded bar. The shim just pushes the bar out of the way releasing the shackle.  Shouldn't lockmakers have designed better ways to prevent attackers shimming their padlocks? Traditional lockmakers have and so have the Noke's makers.  They utilize a "double ball" mechanism to prevent 'shimming'. [More on 'double ball' padlocks from Deviant Ollam's fine book on lockpicking.]

Inside a Noke - Shackle at the top, 'Double ball' to counter shimming.

Attacks against smartphone apps
I'd be remiss if I didn't consider when an attacker would go after the low hanging fruit of the mobile app. The apps(one for each platform - Android, iOS, Windows Mobile) are the major interface to the padlocks. One can lock/unlock, set unlocking distance, and manage distribution of shared keys.  They also store a history of keys used.

I once described a possible threat scenario to a colleague regarding the ability of a particular piece of spyware to compromise the location and travel patterns of C-level executives. That last history feature of the app, while it doesn't leak the GPS data or location data can still provide an attacker with hints to location and specific time ranges when their victim is alone.

The sharing/key management feature of the app is another interesting target. Stealing keys from the app or, better, generating a valid shared key would allow the attacker to simply walk by and access the victim's valuables.  Since a shared key must be generated by the app, an attacker compromising it or controlling it can craft a permanent 'skeleton key' to access/unlock the Noke.

Are we ready for Smart-padlocks?
My trouble with padlocks began decades ago. Smartphones have made my life easier, I no longer need to remember every single password to access my accounts. If my padlocks have gotten smart enough to work with my smartphone so I don't need to memorize a new combination or keep track of a physical key then I'm happy.  Of course if my padlocks get smart enough that they need an immune system(or at least Antivirus) I won't be disappointed.




Tuesday, May 21, 2013

"House Keys Under the Doormat? Nope, in Your Phone"

From McAfee blog:
One of my friends recently locked himself out of his apartment. I found this out when I called him because although he didn't have his keys, he did have his smartphone. This was one of those times he wished he lived in one of those hotels with the Assa Abloy NFC-enabled locks.

It turns out he doesn't need to go to a hotel to open his door with a phone. Kwikset will soon be selling Kevo, a new deadbolt that can be unlocked with a Bluetooth-enabled phone. You can replace your old door locks with one of these new models. 
The Kwikset/Unikey Kevo deadbolt is controlled via a Bluetooth-enabled smartphone app. 

The Kevo lock [see demo video] is based on technology from Unikey, a winning company on the ABC TV show Shark Tank. Unikey’s background is in developing biometrics-access controls. Those controls are the ones you see on TV or in movies when a character places a palm or finger on a pad to open a door. With these locks we can all have similar technology guarding our homes.

Security Concerns
Another thing that you would notice from those same shows and movies is that the bad guys are always trying to break these high-security locks and access controls. The difficulty facing the average computer crook when facing a government high-tech lock is that there are so few of these locks to test against. Contrast those to millions of Bluetooth locks that one can buy off the shelf. The bar is much lower with Bluetooth because if they damage one lock during testing, the criminals can easily buy another one and try again.

The biggest payoff for technical attackers against a lock like this is to duplicate your keys or introduce a new one of their own. With physical keys they would need to get possession of them to make copies; with digital keys they need to break encryption and/or bypass security on the device that holds the keys (smartphone or key fob).

The deadbolts come with a single key fob, similar to car keys with transponders in them, and more can be purchased. It’s not clear yet whether, as with transponder keys, one needs to go through a complex process to activate additional fobs. The security of the fobs makes the smartphone a relatively easier target to go after.

There is an iPhone app that lets you manage both your own door key plus those of other residents (e.g., friends, house sitters, etc.) and temporary keys. Android phones also support Bluetooth. So the choice to produce the iPhone app first may have to do with the relative ease of decompiling Android apps.

iPhones are not necessarily more secure, as a knowledgeable attacker can jailbreak a phone and gain access to a decrypted version of the Kevo key app. Using tools like disassemblers, they can then seek out the methods used to secure the keys within the app and potentially reverse-engineer the protection or discover a method of creating new keys. They may also be able to force the app to accept new keys, essentially adding a master key to every one of these Bluetooth-enabled locks. That is actually not as likely as the criminal’s finding a way to attack a single target’s locks.

Future of Physical Security?
Locks are not invincible, not even high-tech locks. The more such locks are installed, the greater the incentive for robbers to break in through technical means. Why steal one set of keys if they can attack a smartphone app and steal all the keys? Fortunately, as the crooks start to take notice of such devices, so will security researchers. Unlike the bad guys, security folks will test these locks and help them improve. I’m sure my smartphone-toting, key-forgetting friend will appreciate that.

Protecting the ‘Metaverse ecosystem’…: Openness is healthy

Meta’s Reality Labs has an opening for “Malware Reverse Engineer” . Not an uncommon role, but this particular one is a bit more specific whe...