{"id":172736,"date":"2016-07-24T18:28:34","date_gmt":"2016-07-24T16:28:34","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=172736"},"modified":"2016-07-24T18:29:58","modified_gmt":"2016-07-24T16:29:58","slug":"how-easy-it-is-to-hack-your-homes-gate-remote","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/172736-how-easy-it-is-to-hack-your-homes-gate-remote.html","title":{"rendered":"How easy it is to hack your home&#8217;s gate remote"},"content":{"rendered":"<p>It is easy for criminals to attack fixed-code garage and gate remote systems, according to security researchers.<\/p>\n<p>Using a technique known as a replay attack, someone could listen to the remote&#8217;s code you send to your gate or garage door motor.<\/p>\n<p>As\u00a0this code doesn\u2019t change in fixed-key systems, an attacker can record it and replay it to open your gate.<\/p>\n<p>Information security enthusiast Andrew MacPherson has written about the <strong><a href=\"https:\/\/andrewmohawk.com\/2015\/08\/31\/hacking-fixed-key-remotes-with-only-rfcat\/\" target=\"_blank\">technical implementation of fixed-key replay attacks<\/a><\/strong>.<\/p>\n<p>MacPherson said there are also other ways to attack fixed-code systems, citing\u00a0research from Samy Kamkar regarding\u00a0a device he calls <strong><a href=\"http:\/\/samy.pl\/opensesame\/\" target=\"_blank\">OpenSesame<\/a><\/strong>.<\/p>\n<h3 class=\"my-4\">Guessing the key of a fixed-code system<\/h3>\n<p>Kamkar said fixed-code remote systems suffer from a limited number of unique codes.<\/p>\n<p>Even remotes considered to support a high number of possible combinations only have 12 DIP switches, which translates to 4,096\u00a0unique keys.<\/p>\n<p>An attack who\u00a0searches all the combinations in the 8-bit, 9-bit, 10-bit, 11-bit, and 12-bit keyspaces would take just under 30 minutes.<\/p>\n<p>Trying different frequencies and baud rates results in you having to search through the keyspaces a few times.<\/p>\n<p>This means an attacker can\u00a0guess your key, even without listening to your gate remote.<\/p>\n<h3 class=\"my-4\">Hack a gate remote with bit-shifting<\/h3>\n<p>Kamkar then discovered a vulnerability in several fixed-code systems that let him cut the time it takes to guess a key by 99.5%<\/p>\n<p>He found that automated opening systems don\u2019t discard attempted codes that were incorrect, but use a bit-shift operation to test if a key matches.<\/p>\n<p>It is therefore possible to send 13 bits of data to test two 12-bit codes, instead of having to send 24 bits.<\/p>\n<p>With this technique, a 12-bit code also tests five 8-bit codes, four 9-bit codes, three 10-bit codes, and two 11-bit codes while testing the 12-bit code.<\/p>\n<p>Kamkar also found\u00a0an algorithm to get the shortest possible sequence of bits to exploit the shift register.<\/p>\n<p>Dutch mathematician Nicolaas Govert de Bruijn developed the\u00a0concept, called the De Bruijn sequence.<\/p>\n<p>Using the sequence, Kamkar was able to build a device from a Mattel toy that tests every key for a 12-bit remote in 8.214 seconds.<\/p>\n<p>Not all remote vendors are affected by this vulnerability, and many have fixed this issue in newer products.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-172774 size-new-size\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1-640x817.jpg\" alt=\"How the Gate Remote Bit-Shifting Exploit Works\" width=\"640\" height=\"817\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1-640x817.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1-768x980.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1-337x430.jpg 337w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2016\/07\/How-the-Gate-Remote-Bit-Shifting-Exploit-Works-1.jpg 1280w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/iSSRaIU9_Vc\" width=\"640\" height=\"360\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<h3 class=\"my-4\">Defending against remote hacking<\/h3>\n<p>Kamkar advised\u00a0consumers\u00a0to\u00a0upgrade to a remote system that uses rolling or hopping codes\u00a0to prevent being attacked.<\/p>\n<p>These systems are not impervious, but are more difficult to hack.<\/p>\n<p>MacPherson has <strong><a href=\"http:\/\/andrewmohawk.com\/2016\/02\/05\/bypassing-rolling-code-systems\/\" target=\"_blank\">researched attacks into rolling-code remotes<\/a><\/strong>, which are often used in car remotes, and said they are more resistant to replay attacks.<\/p>\n<p>Together with Mike Davis, they presented a talk at <strong><a href=\"http:\/\/zacon.org.za\/\" target=\"_blank\">ZaCon 2015<\/a><\/strong> on the topic.<\/p>\n<p>People should be as concerned about the security of their gate remotes as they are anything else,\u00a0said MacPherson.<\/p>\n<p>\u201cI\u2019d definitely move away from fixed key since it&#8217;s the equivalent of having a password you cant change and having to shout it at the top of your lungs to your garage to get it to work.\u201d<\/p>\n<h3 id=\"related\">More on security<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/banking\/171275-how-your-chip-and-pin-bank-card-gets-skimmed-and-your-money-stolen.html\"><strong>How your chip-and-PIN bank card gets skimmed and your money stolen<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/171807-arsmcor-getting-cyber-experts-to-investigate-anonymous-hack.html\"><strong>Armscor getting \u201ccyber experts\u201d to investigate Anonymous hack<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/171267-online-dating-scam-bust-in-south-africa-6-arrested.html\"><strong>Online dating scam bust in South Africa: 6 arrested<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/170401-how-to-spot-a-card-skimmer-at-a-restaurant.html\"><strong>How to spot a card skimmer at a restaurant<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/169313-the-best-defence-against-house-robberies-in-south-africa.html\"><strong>The best defence against house robberies in South Africa<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many garage and gate remote systems are not very secure.<\/p>\n","protected":false},"author":15,"featured_media":172738,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[38132,35,38138,38136,38134,38142,31978,31942,38140],"class_list":["post-172736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-andrew-macpherson","tag-headline","tag-mike-davis","tag-nicolaas-govert-de-bruijn","tag-opensesame","tag-remote-hacking","tag-remote-jamming","tag-samy-kamkar","tag-zacon"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/172736"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=172736"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/172736\/revisions"}],"predecessor-version":[{"id":173080,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/172736\/revisions\/173080"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/172738"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=172736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=172736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=172736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}