Categories: Security

Hack Lets Burglars Enter Locked Hotel Rooms Without Leaving A Trace

Finnish security experts have successfully hacked a line of electronic door locks used in several major hotel chains, saying the exploit could be used to enter a hotel room without leaving a trace in computer logs.

The attack works on the Vision by VingCard system made by Assa Abloy, whose locks are used by hotel chains including Intercontinental, Hyatt, Radisson and Sheraton.

But the lock maker said F-Secure’s exploit only works on an older version of the Vision lock. It didn’t disclose which hotels used the compromised locks.

F-Secure said its method could allow a hacker to create counterfeit “master keys” that could open hotel room doors as well as other doors on hotel premises. The false key could also be used to send an elevator to restricted VIP areas of a hotel.

Assa Abloy’s locks are used by major hotel chains

No record

The firm began looking for ways to exploit the locks after a colleague’s laptop was stolen from a hotel room without any record being left behind of the burglar’s entry.

“We wanted to find out if it’s possible to bypass the electronic lock without leaving a trace,” said F-Secure senior security consultant Timo Hirvonen of the Ghost In The Locks attack.

Hackers could produce the master key from an electronic RFID or magstripe key that had been used at the hotel to open room doors, or even a storage closet or garage.  The hack works even if the key’s privileges have long expired.

A portable programmer is then used to overwrite the key’s data and create the master, F-Secure said. But the hack only works with custom software developed by the security firm. F-Secure said it isn’t planning to make its software public.

Assa Abloy downplayed the implications of F-Secure’s discovery, saying it had taken the security firm’s team of two people 12 years and thousands of hours of intensive work to create the hack. It would take a large team of specialists years to repeat F-Secure’s achievement, the firm said.

The company also noted that the Vision software involved is 20 years old and is being rapidly replaced with new technology.

F-Secure said it contacted Assa Abloy a year ago to collaborate on a fix, which has been available since February.

Do you know all about security? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

1 hour ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

2 hours ago

Australian PM Hits Out At Elon Musk Over Knife Attack Video

Censorship row brewing down under, after the Australian Prime Minister calls Elon Musk an 'arrogant…

3 hours ago

US SEC Seeks $5.3 Billion Fine From Terra’s Do Kwon

Financial regulator asks New York judge to impose $5.3 billion in fines against Terraform Labs…

4 hours ago

Microsoft Launches Smallest AI Model, Phi-3-mini

Lightweight artificial intelligence model launched this week by Microsoft, offering more cost-effective option for Azure…

8 hours ago

US Senate Passes TikTok Ban Or Divestment Bill

ByteDance protest falls on deaf ears, as Senate passes TikTok ban or divest bill, with…

9 hours ago