FutureIntelligence
No Result
View All Result
  • Login
  • Register
  • Home
  • Opinion
  • Radio & Podcasts
  • Events & Press
  • Tech Jobs
  • Reviews
  • About
FREE TO SUBSCRIBE
DONATE
  • Home
  • Opinion
  • Radio & Podcasts
  • Events & Press
  • Tech Jobs
  • Reviews
  • About
No Result
View All Result
FutureIntelligence
No Result
View All Result
Home Crime Computer Security

Trump hotels were wide open to hackers

peter by peter
in Computer Security, Crime, Defence, Latest News, Security agencies
Reading Time: 4 mins read
A A
0
Trump hotels were wide open to hackers
Share on FacebookShare on Twitter

Millions of electronic hotel door locks including those of US President Donald Trump’s hotel group and other chains around the world have been found to be vulnerable to hackers.

RELATED POSTS

Europe’s digital War of Independence

Space cold war warms up

Digital ID card row: to be, or not to be

Load More


Using a simple technique to trap the ‘unique’ data from the ID cards produced by the Swedish company Assa Abloy, formerly known as Vingcard, ethical hackers from the Finnish company were able to show that they could effortlessly open hotel rooms, often from some distance away.
The experiment, demonstrated at a hacker’s convention in Florida on the 27th of April at 2.15pm, will cause panic in the security industry because the digital locks are not only used for hotel locks but also for room safes and even more importantly for the access systems to the secure rooms used by banks and technology companies to store sensitive customer data and account information.
The weakness in the door locking system has been circulating within the hacking community for a number of years and was almost certainly known about by the intelligence communities. One of the most disturbing points about the research is that NFC systems have now been rolled out in so many different parts of our lives and are now used in smart cards, clothes shops to create smart tags and in mobile phones – all prime targets for criminals and a signal to them to concentrate on research into the systems looking for weaknesses just as the researchers did.

Intelligence agents have long used hotel room penetration as a stock in trade for targeting foreign travellers and visiting delegations – a point underlined in the recent Channel 4 TV series ‘Deutschland 83’ which showed an East German Stasi undercover agent entering the hotel room of a member of a NATO delegation to steal information.
F-Secure researchers found that global hotel chains and hotels worldwide use an electronic lock system that can be exploited by an attacker to gain access to any room in the facility. The design flaws discovered in the lock system’s software, which is known as Vision by VingCard and used to secure millions of hotel rooms worldwide, have forced the world’s largest lock manufacturer, Assa Abloy, to issue software updates with security fixes to mitigate the issue.

The attackers using any ordinary electronic key to the target facility – even one that’s long expired, discarded, or used to access spaces such as a garage or closet.
Using information on the key, the researchers can create a master key with privileges to open any room in the building. The attack can be performed without being noticed.

For Tuominen’s interview with the PassW0rd radio Podcast  click – PastW0rd – 

Researchers say flaws they found in the equipment’s software meant they could create “master keys” that opened the rooms without leaving an activity log“You can imagine what a malicious person could do with the power to enter any hotel room, with a master key created basically out of thin air,” said Tomi Tuominen, Practice Leader at F-Secure Cyber Security Services. “We don’t know of anyone else performing this particular attack in the wild right now.”

The hackers targeted the hotel locks a decade ago after a colleague’s laptop was stolen from a hotel room during a security conference. When the researchers reported the theft, hotel staff dismissed their complaint given that there was not a single sign of forced entry, and no evidence of unauthorised access in the room entry logs.
The researchers decided to investigate the issue further, and to prove a point focused on the Vingcard system due to its reputation for quality and security.

advertise
ADVERTISEMENT
Timo Hirvonen gives his version of the hack to PassW0rd’s PastWord podcast.

“We wanted to find out if it’s possible to bypass the electronic lock without leaving a trace,” said Timo Hirvonen, Senior Security Consultant at F-Secure.

“Building a secure access control system is very difficult because there are so many things you need to get right. Only after we thoroughly understood how it was designed were we able to identify seemingly innocuous shortcomings. We creatively combined these shortcomings to come up with a method for creating master keys.”

“These security oversights were not obvious holes. It took a thorough understanding of the whole system’s design to identify small flaws that, when combined, produced the attack. The research took several thousand hours and was done on an on-and-off basis and involved considerable amounts of trial and error.”
F-Secure has notified Assa Abloy of the findings and has collaborated with the lockmaker over the past year to implement software fixes. Updates have been made available to affected properties.

Previous Post

Tech companies must rebuild public trust

Next Post

Defence analysts dismiss cyber war fears

peter

peter

Related Posts

Europe fights to liberate data from the US
Artificial Intelligence

Europe’s digital War of Independence

The US president Donald Trump’s erratic behaviour on the world stage has provoked a massive European data sovereignty backlash as...

by George Ridley
16th April 2026
Space cold war warms up
cyber security

Space cold war warms up

Experts monitoring satellites in space warn of potential war as global tensions spin into orbit. Western space experts are accusing...

by Peter Warren
26th January 2026
Digital ID card row: to be, or not to be
Politics

Digital ID card row: to be, or not to be

The Government’s confused announcement of a Digital ID card scheme faces disaster, unless the Government sets out clear plans, according...

by Blue Buffery
12th November 2025
The M&S hack is a brand attack
Computer Security

The M&S hack is a brand attack

The M&S hack has battered not only the retailer’s computer systems and business it has also battered its brand. The...

by Georgie Warren
23rd May 2025
AI’s energy price
Artificial Intelligence

AI’s energy price

The UK must focus on data centre research to solve some of the massive infrastructure issues caused by the adoption...

by Peter Warren
21st May 2025
AI and creativity

Digital twins – creating our own image and making our mark in the metaverse

In this month’s PassW0rd, ‘Digitally Resonating’, we tackle living and working in the Artificial Intelligence world of the 21st century...

by Blue Buffery
12th October 2024
Next Post
Defence analysts dismiss cyber war fears

Defence analysts dismiss cyber war fears

Diva robot learns to sing and dance

Politicians need AI skills says tech expert

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Europe’s digital War of Independence
  • Space cold war warms up
  • Digital ID card row: to be, or not to be

Categories

© 2021 Future Intelligence - Website by Kukoo Creative

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms bellow to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Opinion
  • Radio & Podcasts
  • Events & Press
  • Tech Jobs
  • Reviews
  • About

© 2021 Future Intelligence - Website by Kukoo Creative

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?