Hackers gathered in Las Vegas on Saturday showed ways to crack electronic key-card systems and deadbolt locks used at security-sensitive places including the White House and the Pentagon.
"If you can't physically protect your computer, you are screwed," said Zac Franken, a British hacker who engineered a way to outwit door locks relying on key cards.
"Most people think that computers inside buildings are secure. How many computers do you see left logged on at night?" he said.
PHOTO: AP
Franken's creation was among the real-world lock-cracking revelations made at the DefCon hackers conference, where a room is devoted to the "sport" of lock picking.
Medeco deadbolt locks relied on worldwide at embassies, banks and other tempting targets for thieves, spies or terrorists can be opened in seconds with a strip of metal and a thin screw driver, Marc Tobias of Security.org demonstrated.
"This is incredible; it's unreal," Tobias said while showing the ease with which the locks can breached.
"Medeco has one of the best designed locks in the world, but with this kind of attack it's all irrelevant," he said.
US-based Medeco is owned by ASSA ABLOY Group, a Swedish manufacturer and supplier of locks.
"This is not the only company," Tobias said. "There are lot of them; lots of deadbolts with similar weakness."
Tobias said he refuses to publish details of "defeating" the locks because they are used in places ranging from homes and banks to the White House and the Pentagon.
"This can cause a lot of trouble," he said. "They need to fix this. If you have one of these on your house or wherever you'd better be concerned."
Franken is equally protective of the simple electronics he uses in a device that can be spliced into wires connecting key card readers to computer systems that control door locks on many businesses.
"The access control system is inherently insecure," Franken said. "I just walk up, pop off a cover held on by two screws, put my device in and we're away."
Easy targets for the "physical hack," involving manipulating hardware instead of computer software, are electronic key scanner pads at doors where workers step outside for cigarette breaks, Franken said.
Once the device is spliced into place, encoded cards can be used to command it to replay the last valid entry code or have the system deny access to people with legitimate cards, he showed.
"Basically, I can now lock all the valid users out while I can still get in," Franken said. "There is no patch for this."
Tobias wants to see a "Hogwarts School for Reality," which like the school of magic made famous in the Harry Potter novels would aim to inspire children to act creatively -- in this case by applying technology to security needs on and offline.
"It's no difference breaking into a lock or a computer," he said. "If you can get past locks you get to the computers. This is the real world; we need the real world Hogwarts."
UPDATED (3:40pm): A suspected gas explosion at a shopping mall in Taichung this morning has killed four people and injured 20 others, as emergency responders continue to investigate. The explosion occurred on the 12th floor of the Shin Kong Mitsukoshi in Situn District (西屯) at 11:33am. One person was declared dead at the scene, while three people were declared deceased later after receiving emergency treatment. Another 20 people sustained major or minor injuries. The Taichung Fire Bureau said it received a report of the explosion at 11:33am and sent rescuers to respond. The cause of the explosion is still under investigation, it said. The National Fire
ALL-IN-ONE: A company in Tainan and another in New Taipei City offer tours to China during which Taiwanese can apply for a Chinese ID card, the source said The National Immigration Agency and national security authorities have identified at least five companies that help Taiwanese apply for Chinese identification cards while traveling in China, a source said yesterday. The issue has garnered attention in the past few months after YouTuber “Pa Chiung” (八炯) said that there are companies in Taiwan that help Taiwanese apply for Chinese documents. Minister of the Interior Liu Shyh-fang (劉世芳) last week said that three to five public relations firms in southern and northern Taiwan have allegedly assisted Taiwanese in applying for Chinese ID cards and were under investigation for potential contraventions of the Act Governing
‘INVESTMENT’: Rubio and Arevalo said they discussed the value of democracy, and Rubio thanked the president for Guatemala’s strong diplomatic relationship with Taiwan Guatemalan President Bernardo Arevalo met with US Secretary of State Marco Rubio in Guatemala City on Wednesday where they signed a deal for Guatemala to accept migrants deported from the US, while Rubio commended Guatemala for its support for Taiwan and said the US would do all it can to facilitate greater Taiwanese investment in Guatemala. Under the migrant agreement announced by Arevalo, the deportees would be returned to their home countries at US expense. It is the second deportation deal that Rubio has reached during a Central America trip that has been focused mainly on immigration. Arevalo said his
‘SOVEREIGN AI’: As of Nov. 19 last year, Taiwan was globally ranked No. 11 for having computing power of 103 petaflops. The governments wants to achieve 1,200 by 2029 The government would intensify efforts to bolster its “Sovereign Artificial Intelligence [AI]” program by setting a goal of elevating the nation’s collective computing power in the public and private sectors to 1,200 peta floating points per second (petaflops) by 2029, the Executive Yuan said yesterday. The goal was set to fulfill President William Lai’s (賴清德) vision of turning Taiwan into an “AI island.” Sovereign AI refers to a nation’s capabilities to produce AI using its own infrastructure, data, workforce and business networks. One petaflop allows 1 trillion calculations per second. As of Nov. 19 last year, Taiwan was globally ranked No. 11 for