Arduino, Resistor, And Barrel Plug Lay Waste To Millions Of Hotel Locks

The security flaws on this common hotel keycard lock are nothing short of face-palmingly stupid. Look closely at the picture above. This is a hotel room door swinging open. The device he holds in his hand is an Arduino connected to the OUTSIDE portion of the door lock. It takes approximately 200 milliseconds from the time an attacker plugs the device in, until the door can be opened. Yes, in less than 1/4 of one second an Arduino can open any of the millions of these locks in service.

The exploit in Onity programmable keycard locks was revealed by [Cody Brocious] at the Blackhat conference. Apparently the DC barrel jack on the outside of the lock serves as a one-wire protocol interface. Once communications are established a 32-bit sitecode can be read from any of the locks and immediately used to open the door. There is no authentication or encryption used to obfuscate this kind of attack. To make matters worse, you can even read out master key and skeleton key codes. These codes facilitate ‘magic’ keys used to open a variety of different doors through the system.

We’re no strangers to easy hotel beak-ins. But how can a digital lock possibly be sold with this type of vulnerability present? Really!?

Here’s the white paper on the exploit as well as the slides from his talk (PDF).

[via Reddit]

Kansas City MakerFaire: Greentechweekly’s Coverage

We hadn’t been at the MakerFaire long when we ran into a couple hackaday fans lugging around camera equipment and microphones. I agreed to a quick interview for their show greentechweekly.tv which was fairly painless, then we all went our separate ways. [EcoGeeco] later sent me the footage and I couldn’t help but think… these guys did a better job than I did!  They asked some great questions, got some great footage, somehow managed to get decent audio too!

Continue reading “Kansas City MakerFaire: Greentechweekly’s Coverage”

MakerFaire K.C.: Power Wheels Racing

[vimeo=44644726]

This section of the MakerFaire almost deserves an entire event of its own. I know I would happily attend a monthly match of the power racing series in my home town. To compete, you must have a modded Power Wheel. Yes, those electric kids vehicles that go really slowly across your lawn, those power wheels. You tear it apart, soup it up, and race it.

Continue reading “MakerFaire K.C.: Power Wheels Racing”

NC Maker Faire 2012: Other Projects

Maker Faire NC 2012 Splat Space

Although I didn’t get to see everything I wanted to at the Faire, there was a ton of stuff that was interesting enough for a mention. Many of these could probably merit their own separate article, and I didn’t get to talk about everything, so feel free to comment, or better yet write in to the tip line if you feel like you deserve more “air time.”

In the video after the break there’s everything from a [steampunk] display, to a model railroad club, and lots of projects in between.  For a list of makers at this Faire, check out this page. Continue reading “NC Maker Faire 2012: Other Projects”

Maker Faire NC 2012: Electrical Vehicles

lab306-fox

Although I had no idea what to expect at the NC Maker Faire, I was pleasantly surprised to see several well made electrical vehicles. One of note was [Lab306]‘s Fox body electric Mustang. Although it would have been impressive by itself, it was made by a high school class and has been featured in several publications. Be sure to check out their excellent website, or the short video of it after the break! Don’t you wish you went to that high school?

Also of note were a few really cool cars seen after the break, including one built from a kit by [Green Cycle Design Group]. The other two were extremely small by traditional car standards and featured very unique designs. Continue reading “Maker Faire NC 2012: Electrical Vehicles”

MakerFaire K.C. Kansas City Hackerspace Delivers


The Kansas City Hammerspace crowd really brought an amazing amount of stuff this year. Some stuff you’ve already seen, some stuff that is totally new. I’ll be sharing details on some of them individually as they really deserve the attention.  Their booth, or booths were huge, taking up roughly 1/3 of the main hall. It was packed with a plethora of individual projects that really were all over the place. There were enthusiastic people at every turn happy to show off what they had built.Their presence really boosted the awesome level of the MakerFaire through the stratosphere.

Not only did they bring tons of awesome to the MakerFaire, they were gracious enough to invite people back to the hackerspace after the show for an after party. They stuffed food in my entire family and made us feel at home. It was really cool seeing everyone gathered discussing various projects. The ArcAttack crew was even troubleshooting a small tesla coil cit that wasn’t working right.

Watch the Hackerspace tour and check out some pictures after the break. Posts highlighting some of the individual projects will be coming soon.

Continue reading “MakerFaire K.C. Kansas City Hackerspace Delivers”

MakerFaire K.C. Sneak Peak At ArcAttack’s New Toy

I’ve been seeing videos of ArcAttack all over the web for several years now and hoped one day I’d be able to cross paths with them. When I heard they were going to be at MakerFaire K. C., I was determined to grab them and ask a few questions. As it turns out, they’re fans of Hackaday and were happy to talk. Not only that, but when I was asking what fun things they were building, their eyes lit up. “You’re going to love this” one of them said as he ran off behind the stage.  He returned with a device which was strapped to his body and spitting 5 foot long lightning bolts. He was right, I did love it!  They demonstrated this proton pack looking portable tesla coil for a while, shocking each other and random bits of metal, all the wile grinning like the fools we all are.

I know we’ve covered a portable tesla coil or two before, but seeing this thing in person,heading right for you,strapped to someone who might actually even be able to run faster than you, is pretty cool.

There is video (sorry, shaky) and a ton of pictures after the break. Enjoy.

Continue reading “MakerFaire K.C. Sneak Peak At ArcAttack’s New Toy”