News

Researchers have discovered that secure electronic locks can be cracked by measuring their power consumption

Attackers can crack high-security electronic locks at ATMs, pharmacy display cases, government organizations, etc. by measuring their power consumption.

According to Reuters, last year IOActive researcher Mike Davis discovered a vulnerability in locks supplied by the Swiss company DormaKaba Holding. With an $ 5K oscilloscope Davis measured the minimal changes in electricity consumption of the devices and carried out an attack through third-party channels.

The locks studied by a specialist are equipped with a built-in battery, due to which they can work even when disconnected from the electricity supply. Most devices consume as much electricity as they need to work, and do not hide their activity behind power surges. This paves the way for attack through third-party channels, Davis explained.

“I can load an analog signal and convert power signals to units and zeros. I know what’s going on inside the castle”, – the researcher said.

Some DormaKaba-supplied lock models (not the most recent) of the X-10 series are used at US military bases, presidential jets, and government organizations. According to Davis, these models are vulnerable to attacks on third-party channels, allowing to crack devices using energy consumption data.

Read also: Avionics of small planes is vulnerable to attacks with the replacement of telemetry

Davis talked about his finding at the Def Con USA 2019 conference, which is now taking place in Las Vegas. The president of Kaba Mas, a subsidiary of DormaKaba and an X-10 manufacturing company, Eric Elkins declined to comment on this issue without seeing the researcher speaking. However, Elkins noted that if the attack works, then it could endanger classified information.

“It would be right to turn to the government, and not to a handful amateur hackers, or whatever you like to call them”, – Elkins added.

Davis notified DormaKaba of the problem and the company hired specialists to study the issue.

“As the results of the investigation showed, our current line of secure locks in a real environment works as expected”, – DormaKaba said.

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Qehu Virus Removal Guide (+Decrypt .qehu files)

Qehu - General Info Qehu is a destructive software functioning as typical ransomware. Michael Gillespie,…

11 hours ago

Qepi Virus Removal Guide (+Decrypt .qepi files)

Qepi Virus - Details Qepi is a destructive software functioning as typical ransomware. Michael Gillespie,…

11 hours ago

Remove Wifebaabuy.live pop-up ads (Virus Removal Guide)

Wifebaabuy.live is a domain that tries to trick you into clik to its browser notifications…

12 hours ago

Remove Relativeads.net pop-up ads (Virus Removal Guide)

Relativeads.net is a domain that tries to force you into clik to its browser notifications…

12 hours ago

Remove Vamtoa pop-up ads (Virus Removal Guide)

Vamtoacm.com is a domain that tries to force you into clik to its browser notifications…

12 hours ago

Remove Clicks2apk pop-up ads (Virus Removal Guide)

Clicks2apk.com is a site that tries to force you into subscribing to its browser notifications…

13 hours ago