HackInTheBox Amsterdam
Blue Picking: Hacking Bluetooth Smart Locks (2h workshop)
Recently it seems our home/car/bicycle locks have started to follow a new trend: to include a BLE chip inside to make them “smart”. Unlike smart toothbrushes, socks or kettles, locks guard our safety, and their security should be much more of a concern. Vendors promise “military-grade level of security”, “128-bit encryption” and “cryptographic key exchange protocol” using “latest PKI technology”. However, recent disclosures of multiple vulnerabilities in smart locks clearly contradict the assurances on the actual security provided, and raise the question of whether these devices have passed any independent security assessments at all!