TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

IoT Smart Lock Vulnerability Spotlights Bigger Issues

52 pointsby axsharmaalmost 5 years ago

8 comments

neomalmost 5 years ago
While not IoT - Lock Picking Lawyer has a bunch of &quot;smart&quot; locks that he owns with very little effort. [1] My favourites are these RFID locks [2][3] and this fingerprint lock.[4]<p>[1] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;c&#x2F;lockpickinglawyer&#x2F;search?query=smart" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;c&#x2F;lockpickinglawyer&#x2F;search?query=sma...</a><p>[2] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=z4lVylO7y5U" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=z4lVylO7y5U</a><p>[3] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=XXW27KKHtc8" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=XXW27KKHtc8</a><p>[4] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pTys_WYBOLE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pTys_WYBOLE</a>
nullcalmost 5 years ago
It&#x27;s really a shame that &quot;IoT&quot; locks are destroying the reputation of electronic locks.<p>A well constructed electronic lock can be considerably more secure against non-destructive attack than any mechanical lock. Yet IoT locks continually have gross vulnerabilities that allow undetectable bypass-- and issue that even moderately good mechanicals locks don&#x27;t really have (even picking usually leaves evidence).
评论 #24104490 未加载
评论 #24105082 未加载
cortesoftalmost 5 years ago
No lock keeps out a determined attacker. I bet fewer people could carry out this attack than people who can pick a normal lock.
评论 #24105020 未加载
评论 #24104365 未加载
评论 #24104605 未加载
评论 #24104363 未加载
jmroblesalmost 5 years ago
This is the funny part:<p>&quot;the [cloud] server does have strong security” --&gt; oh, good<p>&quot;and that users’ data have been encrypted by the MD5 algorithm --&gt; WTF???
评论 #24107726 未加载
tehlikealmost 5 years ago
Homeassistant + yale zigbee&#x2F;leave lock. No need for cloud at all. If you care, you can vpn to your house.
axegon_almost 5 years ago
I&#x27;ve fiddled with IoT very little, yet with the little experience I have, I must say, I&#x27;m not surprised at all. And I think the main reasons are the ecosystems around IoT: they are a mess - no standards, no common communication protocols, none of that. So it is a bit of a &quot;every man for himself&quot; kind of thing. I have a few smart devices at home and it really boggles my mind how much they differ from one another when they connect to the wifi. Some fire up a tiny http server which I would assume is used as a rest api, some use udp connections, each one uses the most random port you can imagine, the developer documentation for all of them is nothing short of crap. I think the security vulnerabilities will start going down once:<p>1. Everything goes open source.<p>2. Everyone settles on a standard way of communicating between those devices.<p>Sure, vulnerabilities won&#x27;t disappear completely but they will go down. At this stage, I feel like they aren&#x27;t exploited due to lack of interest rather than good will or lack of opportunities.
评论 #24107205 未加载
exabrialalmost 5 years ago
&gt; and that users’ data “have been encrypted by the MD5 algorithm”<p>Literal head-desk. They ought to be sued. There is so much wrong with that one statement.
axsharmaalmost 5 years ago
Got an IoT smart lock? Watch out for hackers unlocking it from anywhere!<p>A security vulnerability discovered and responsibly reported by Craig Young of Tripwire exposes flaws in U-Tec UltraLoq locks, among other devices.