DEF CON 24 - Jmaxxz - Backdooring the Frontdoor

  Переглядів 64,937

DEFCONConference

DEFCONConference

7 років тому

As our homes become smarter and more connected we come up with new ways of reasoning about our privacy and security. Vendors promise security, but provide little technical information to back up their claims. Further complicating the matter, many of these devices are closed systems which can be difficult to assess. This talk will explore the validity of claims made by one smart lock manufacturer about the security of their product. The entire solution will be deconstructed and examined all the way from web services to the lock itself. By exploiting multiple vulnerabilities Jmaxxz will demonstrate not only how to backdoor a front door, but also how to utilize these same techniques to protect your privacy.
Bio:
Jmaxxz works as a software engineer for a Fortune 100 company, and is a security researcher for pleasure. His FlashHacker program was featured in Lifehacker’s most popular free downloads of 2010. More recently he has contributed to the node_pcap project which allows interfacing with libpcap from node. His other interests include lock picking and taking things apart.

КОМЕНТАРІ: 33
@JamesBalazs
@JamesBalazs 7 років тому
And this is why you don't leave debug tools in production.
@pv2xeek
@pv2xeek 5 років тому
Are we all just going to ignore that fact that there is still an easily manipulated, traditional pin-tumbler lock cylinder on the outside of the door?
@abbdiego
@abbdiego 7 років тому
First time watching defcon, great talk about security locks... Made more aware of how consumer gadgets can be manipulated :)
@jerrya6840
@jerrya6840 7 років тому
Really enjoyed this talk. Great job Jmaxxz!
@Jmaxxz
@Jmaxxz 7 років тому
Thanks man!
@Radi0he4d1
@Radi0he4d1 7 років тому
The more DefCon I watch, the more mechanical things I want in my life.
@birchcakes
@birchcakes 5 років тому
Radi0he4d1 You haven’t seen the physical pen tester’s talks then have you? Haha. You’re never safe!
@sighthoundman
@sighthoundman 4 роки тому
@@birchcakes I have heard all my life, "The purpose of locks is not to keep thieves out, it's to keep honest people honest." The one advantage to keeping your valuables near you and behind a physical lock (or even an IoT one) rather than at the brokerage or in a safety deposit box is that you can tell when someone has broken in. Besides, it's really not worth anyone's time to come to my house looking for valuables because all I have is "personal items" that would cost a lot of money to replace but would bring nothing when trying to sell. (That's why I pay extra for replacement cost insurance rather than ACV.) By the way, Goodwill still takes black and white tvs (if they work). Cable installers can't figure out what's wrong with your black & white tv (it's not getting the colors). Also, you can't tell dark blue jerseys from black. At least baseball has stopped demanding that uniforms can be differentiated on b&w tv. No one has ever stolen food or clothing from me. If you have lots of things, or valuable things, I honestly don't know what to do. I was a victim of a random break-in and lost jewelry worth over $100. It made me mad (and it was a lot of money at the time), but since then I have not bought jewelry worth over $100. Not making the same mistake twice. TL;DR: You're safe by not having anything worth working to steal, and having locks (doors, windows, etc.) that withstand casual abuse.
@0xCAFEF00D
@0xCAFEF00D 7 років тому
10:00 Around here a boo or a cheer would be appropriate. This means that they could sell the information and then claim it's just poor security.
@projectdren806
@projectdren806 7 років тому
The dude at 31:00 really pisses me off. This isn't advertise time for your company. Jesus. Jmaxxz looked pissed while he was talking lol.
@DanHaiduc
@DanHaiduc 5 років тому
I didn't care, but after your comment I looked them up and saw their membership fee. Now he pisses me off also.
@damejelyas
@damejelyas 5 років тому
I did not care at first but now he sounds like a broker
@FennecTECH
@FennecTECH 7 років тому
be right back need to change my locks
@jackbazileuski8726
@jackbazileuski8726 7 років тому
The biggest problem I see with those locks is that 99% of the time your house/door that need to be secured is gonna be defeated not by a madskillz haxxor (there's not that many of them) but an asshole with an angle grinder. And the more high-tech the lock looks the more potential value is presumed to be beyond the door. But yeah amazing talk, and really well researched in terms of software. Really wanna see some more research into how a real world attack would be conducted.
@rmast
@rmast 7 років тому
It looks like the August just replaces the interior portion of your deadbolt lock so the high-tech appearance would only be visible for someone who is already inside your house, right? Unless you have glass windows in the door, but then the angle grinder isn't needed.
@Radi0he4d1
@Radi0he4d1 7 років тому
Then again, if it bluetooth-enabled, you can just walk around the block and find August devices. Now all you have to do is befriend the lock owner and ask him to add you as a guest to his lock. Easy peasy.
@zolartan4442
@zolartan4442 6 років тому
Boot Kick. Quieter and faster than Angle Grinder.
@hollymarshall2825
@hollymarshall2825 7 років тому
Wow...kudos, brownie points, and a gold star for you!!! One question: how do you keep a straight face while manipulating the in-store "demo" locks and watching the BB employees freak out? :)
@jasonjase8661
@jasonjase8661 4 роки тому
Safest lock. A big ass mean dog a big wood board across the inside of the door
@Arkos__
@Arkos__ 7 років тому
8:35 starts to sound like watch_dogs..... scary
@HEMNAT91
@HEMNAT91 2 роки тому
What is August lock processor size ?
@SirRapTureGames
@SirRapTureGames 7 років тому
This dude didn't actually put his phone number in Defcon slides did he?
@Jmaxxz
@Jmaxxz 7 років тому
Jeremiah Llewellyn it was a burner number.
@SirRapTureGames
@SirRapTureGames 7 років тому
Jmaxxz ah. I knew no one was that silly lol. Great talk and solid research my dude. I hope to be in your position once I finish my schooling.
@7zwergealleinimwald
@7zwergealleinimwald 7 років тому
Jmaxxz, Why is it always 9:41am on the phone? Great talk, thank you!! :-)
@gegdim9307
@gegdim9307 7 років тому
MI_DROID when you connect your iPhone to your iMac, you can record the screen using QuickTime. When you do that, the iPhone recording shows 9:41, a Easter egg by apple since that's the time they always show at their key events
@gegdim9307
@gegdim9307 7 років тому
MI_DROID when you connect your iPhone to your iMac, you can record the screen using QuickTime. When you do that, the iPhone recording shows 9:41, a Easter egg by apple since that's the time they always show at their key events
@Kennnn264
@Kennnn264 7 років тому
What program does he use at 10:26?
@jerrya6840
@jerrya6840 7 років тому
Postman.
@Some_Beach
@Some_Beach 5 років тому
Gotta say. I've never heard that called a hamburger
@Mosibfu1
@Mosibfu1 5 років тому
lol at 21:30 he showed his phone number, on defcon lol, i wonder how many people called him rofl
@karlnul
@karlnul 5 років тому
yeah lol, I was assuming it was a Google Voice number or the likes
@Jmaxxz
@Jmaxxz 10 місяців тому
@@karlnul Indeed, it was a burner phone I got just for this talk.
Не пей газировку у мамы в машине
00:28
Даша Боровик
Переглядів 723 тис.
DEF CON 24 - Weston Hecker - Hacking Hotel Keys and Point of Sale Systems
44:20
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Переглядів 635 тис.
Defcon 21 - Stalking a City for Fun and Frivolity
45:20
HackersOnBoard
Переглядів 246 тис.
The Search for the Perfect Door - Deviant Ollam
50:50
Shakacon LLC
Переглядів 1,3 млн
DEF CON 24 - LosT - Hacker Fundamentals and Cutting Through Abstraction
38:38
Defcon 21 - The Secret Life of SIM Cards
42:36
HackersOnBoard
Переглядів 693 тис.