Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Exclusive: High-security locks for government and banks hacked by researcher
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Exclusive: High-security locks for government and banks hacked by researcher

Exclusive: High-security locks for government and banks hacked by researcher

Reuters • August 7, 2019, 02:09:04 IST
Whatsapp Facebook Twitter

By Joseph Menn SAN FRANCISCO (Reuters) - Hackers could crack open high-security electronic locks by monitoring their power, allowing thieves to steal cash in automated teller machines, narcotics in pharmacies and government secrets, according to research to be presented Friday at the annual Def Con hacking conference in Las Vegas.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Exclusive: High-security locks for government and banks hacked by researcher

Exclusive: High-security locks for government and banks hacked by researcher

By Joseph Menn

SAN FRANCISCO (Reuters) - Hackers could crack open high-security electronic locks by monitoring their power, allowing thieves to steal cash in automated teller machines, narcotics in pharmacies and government secrets, according to research to be presented Friday at the annual Def Con hacking conference in Las Vegas.

Mike Davis, a researcher with security firm IOActive, discovered the vulnerability last year and alerted government officials and Swiss company DormaKaba Holding , the distributor of multiple brands of locks at issue.

STORY CONTINUES BELOW THIS AD

In an interview with Reuters, Davis said he used an oscilloscope worth about $5,000 to detect small changes in the power consumption, through what is known as a side-channel attack. The method worked best in older models.

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

The locks include their own power supply so they function even when an external source of electricity is cut off. Most versions do not consume extra or randomised power to hide what they are doing. That leaves them open to attack if a thief can get physically close enough and has the right tools, Davis said.

“I can download that analog signal and parse through the power trace to get ones and zeroes,” Davis said. “I know what the lock is doing internally.”

DormaKaba said it had looked into the matter itself and also retained an independent firm to probe IOActive’s findings regarding its Cencon and Auditcon locks.

“These investigations indicate that our current safe-lock product lines perform as intended in real life environment,” said company senior vice president Jim Mills.

Asked whether older models were also secure, a company spokesman said “there have been no reported events in the field to suggest that current or prior year models have presented security issues in real-world environments.”

STORY CONTINUES BELOW THIS AD

Inside ATMs, the company’s locks typically protect the cash in the more secure, lower compartment. An upper compartment includes the interface with customers and directs the lower compartment to send up money. The upper compartment often has less physical security, and breaking into it might provide access to the lower vault’s vulnerable lock.

Davis only tested his attack against the simplest mode of the device. When they are actually in the field, the locks typically interact with another device carried by drivers who supply or remove cash, and they may require one-time codes as well. Such measures provided some added security, Davis said.

A bigger concern is that another series of DormaKaba locks are used on military bases, U.S. presidential jet Air Force One and elsewhere in the government.

Davis said he found that several newer models but not the most recent iteration of that series, the X-10, leaked voltage information that could be used against them. The improvement was not due to IOActive’s research, said DormaKaba spokesman Joe Hudock.

STORY CONTINUES BELOW THIS AD

Eric Elkins, president of subsidiary and X-10 maker Kaba Mas, said he could not comment on the severity of the issue without seeing Davis’ presentation. Elkins said that if it works, the attack might put classified information at risk. He questioned why Davis was presenting his research at Def Con.

“The correct method would be to go the government rather than to go to a group of hobbyists or hackers or whatever you want to call them.”

A spokeswoman for the federal General Services Administration, Pamela Pennington, said government employees had been working to understand the side-channel attack and develop a work-around to foil real attacks.

“We are aware of this security issue as it relates to the U.S. government and have developed and deployed mitigation techniques in the federal environment,” Pennington said. “The federal government uses multiple layers of security.”

She declined to describe the steps taken.

(Reporting by Joseph Menn; editing by Greg Mitchell and David Gregorio)

STORY CONTINUES BELOW THIS AD

This story has not been edited by Firstpost staff and is generated by auto-feed.

Tags
Reuters
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV