Tech Trends

Unsaflok Flaw on Android Puts Over 3 Million Hotel Rooms at Risk

Highlights

  • Unsaflok flaw affects Saflok RFID locks in hotels globally.
  • Hack involves duplicating keycard data to unlock doors.
  • Android NFC capability can mimic keycards for door unlocking.
  • Team adopts cautious disclosure to prevent misuse and ensure remediation.

A group of cybersecurity experts has disclosed a significant flaw in hotel keycard systems, dubbed “Unsaflok,” which poses a threat to the security of over three million hotel rooms worldwide.

This vulnerability, identified in the RFID locks manufactured by Dormakaba, known as Saflok, spans across more than 13,000 hotel properties in 161 countries.

The security loophole stems from shortcomings in the encryption and RFID technology utilized by Dormakaba.

Exploiting a Vulnerability

Exploiting a Vulnerability

The method for exploiting this vulnerability involves initially acquiring a keycard from the hotel in question, achievable through booking a room or finding a discarded card.

With the aid of an RFID writer-reader, priced around $300, the data on the keycard is duplicated onto two new cards.

These cards, when used sequentially on a hotel room’s lock, manipulate the lock’s data, ultimately unlocking the door.

Interestingly, this hack can also be executed using an Android smartphone equipped with Near-Field Communication (NFC) capability.

By downloading a specific app that emits the necessary signal, the smartphone can replicate the function of the two physical keycards, enabling door unlocking without them.

Breaching Hotel Privacy

Breaching Hotel Privacy

This revelation follows a previous security breach presented at the 2012 Black Hat conference in Las Vegas, where a vulnerability in Onity’s lock systems, affecting 10 million locks, was exposed.

Onity’s refusal to fund the necessary updates forced hotels to manage the rectifications independently, a decision that led to the exploit being used for criminal activities, including theft from hotel rooms.

In contrast to the previous incident, the team behind Unsaflok has opted for a more reserved approach in disclosing the full details of their discovery.

Hacker Ian Carroll stated their intention to strike a balance between facilitating Dormakaba’s swift response to the issue and raising awareness among hotel guests.

The team’s concern is that premature full disclosure could enable malefactors to exploit the vulnerability before a widespread understanding and remediation effort is in place.

FAQs

What is the Unsaflok vulnerability?

The Unsaflok vulnerability is a security flaw in the Saflok RFID lock systems produced by Dormakaba. It affects over three million hotel rooms across more than 13,000 properties in 161 countries. The issue lies in the encryption and RFID technology, making it possible to unlock doors unauthorizedly.

How can the Unsaflok vulnerability be exploited?

Exploiting the Unsaflok flaw requires obtaining a hotel’s keycard, then using an RFID writer-reader to duplicate its data onto two new cards. Using these cards in sequence on a door’s lock can unlock it. Alternatively, an Android phone with NFC and a specific app can mimic the keycards’ function.

Are there any precautions hotel guests can take?

While the technicalities of the Unsaflok exploit are complex, guests are advised to safeguard their keycards and report any lost or stolen cards immediately. Awareness and vigilance, such as ensuring doors are securely locked and using additional security measures like door stoppers, can offer extra protection.

What is being done to fix the Unsaflok vulnerability?

The cybersecurity team behind the discovery of the Unsaflok flaw is working with Dormakaba to address the issue. By not fully disclosing the hack, they aim to prevent its exploitation and ensure a solution is found before the vulnerability becomes widely known and misused.

Also Read: WhatsApp found using mic when the phone isn’t in use; company says it’s an Android bug; Elon Musk Says WhatsApp is not trustworthy

Also Read: Android 14 Storage Bug in Several Pixel Devices Causing User Lockout

Share
Published by
Team My Mobile

Recent Posts

Nothing Phone (4a) Goes on Sale in India on March 13; Phone (4a) Pro Sale Starts March 27

Highlights Nothing Phone (4a) goes on sale in India on March 13, while the higher-end…

17 minutes ago

Poco X8 Pro Series India Price Tipped Ahead of Launch; Key Specs Leaked via Micorsite and Iron Man Edition Officially Teased

Highlights Poco X8 Pro Iron Man Edition teased shows logo, Stark branding and themed packaging.…

13 hours ago

Apple Rolls Out iOS 16.7.15 and iOS 15.8.7 Updates for Older iPhones and iPads With Security Fixes

Highlights Apple rolled out iOS 16.7.15/iPadOS 16.7.15 and iOS 15.8.7/iPadOS 15.8.7 for older iPhones and…

16 hours ago

Vivo Y11 5G and Vivo Y21 5G Debut in Singapore with Dimensity 6300 Chip, 6.74-inch 120Hz Display and 6,500mAh Battery

Highlights Vivo introduced the Vivo Y11 5G and Vivo Y21 5G in Singapore, both positioned…

17 hours ago

Apple’s Foldable iPhone May Feature iPad-Like Interface and Split-Screen Apps: Gurman

Highlights Foldable iPhone may feature an iPad-like UI with split-screen multitasking, app sidebars, and developer…

18 hours ago

OPPO A6s 5G India Launch Tipped for March; Key Specifications, Colours and Design Details Leaked

Highlights OPPO A6s 5G is tipped to debut in India on or before March 20,…

19 hours ago

This website uses cookies.