Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

It Only Takes 8 Seconds for a Hacker to Open Your Garage Door


b2ap3_thumbnail_garage_hackers_400.jpgHackers have proven to be a crafty and suspicious lot, and can take advantage of even the most benign technology to infiltrate networks. However, we don’t often associate them with objects in the physical world. Now, even something as simple as a decade-old communications device can be used to open the right garage doors.

The device in question was built from a discontinued toy from 2007 called the IM ME. Manufactured by Mattel, it’s a device that was advertised as a secure wireless instant messaging system, sort of like an archaic mobile phone that allows for texting. It stores an address book of other users of the IM ME system, and allows for communications between devices so long as the device had an Internet connection. Looking at it now, you wouldn’t be surprised to hear that it’s no longer supported or even remotely useful these days, especially since smartphones are so much more dynamic and effective for communication.

Last year, it was discovered that this toy could be altered to hack into any garage door that’s equipped with an insecure fixed code transmitted from a remote, rather than one that uses a “rolling code” that’s constantly changing with every button press. The flaw was discovered and exploited by Samy Kamkar, who works as an independant developer and technology consultant. He reportedly built the device out of the IM ME, adding only an antennae and a simple open-source hardware attachment.

Kamkar explains that his device, which he dubs the OpenSesame, works in a different fashion from what are known as “code grabbers.” Ordinarily, code grabbers are devices that capture the code from the garage door button when it’s pressed, and can then reuse the code at a later time. This requires the presence of the hacker when the button is pressed. OpenSesame can accomplish this without being anywhere near the user, which makes it significantly more versatile and dangerous.

The most dangerous part of this hacking experiment is the fact that any hacker can walk up to a vulnerable garage door and have it open in around eight seconds. As reported by WIRED:

Using a straightforward cracking technique, it still would have taken Kamkar’s program 29 minutes to try every possible code. But Kamkar improved his attack by taking out wait periods between code guesses, removing redundant transmissions, and finally using a clever optimization that transmitted overlapped codes, what’s known as a De Bruijn sequence. With all those tweaks, he was able to reduce the attack time from 1,771 seconds to a mere eight seconds.

If you want to know how OpenSesame works, you can watch this video. If you’re unsure of whether or not your garage door is vulnerable to this particular issue, you can watch this video released by Kamkar:

This just goes to show how dangerous and unpredictable some of the things on the Internet of Things can be. With so many devices capable of communicating with each other through near-field and Bluetooth communications, in a worst-case scenario, it becomes a liability that can quickly spiral out of control. Concepts like these should make your business question if it’s prepared to handle the dangers that are approaching in the form of unregulated Internet of Things devices. Considering how much your business stands to lose, you shouldn’t be putting your organization at this kind of risk.

We can give your business’s network a quality assessment to ensure that it’s not vulnerable to other Internet of Things devices and emerging technologies. To learn more, give us a call at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 21 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices IT Services Hardware Disaster Recovery Android VoIP communications Business Continuity Communication IT Support Smartphones Miscellaneous Smartphone Mobile Device Network Browser Small Business Productivity Collaboration Cybersecurity Quick Tips Business Management Users Phishing Upgrade Managed IT Services Windows Outsourced IT Ransomware Data Backup Windows 10 Office Cloud Computing Server Save Money Data Recovery Passwords Windows 10 Saving Money Holiday Tech Term Social Media Chrome Gadgets Virtualization Managed Service Automation Microsoft Office Managed IT Services Facebook Operating System Cybercrime Artificial Intelligence Computers BYOD Mobile Device Management Networking IT Support Health Hacking Internet of Things Wi-Fi Telephone Systems Information Technology Remote Managed Service Provider Covid-19 Alert Spam Office 365 Information Bandwidth Router Recovery Employer-Employee Relationship Social Engineering Mobility BDR Application App History Encryption Applications Big Data Human Resources Data Breach Law Enforcement Remote Monitoring Mobile Computing Password Money Office Tips Training Data Storage Patch Management VPN Government Remote Computing Private Cloud Mobile Office Managed IT Blockchain Paperless Office How To Apps Wireless Infrastructure Voice over Internet Protocol Google Drive Vulnerability Gmail Windows 7 Word Settings Avoiding Downtime Two-factor Authentication Servers Mouse Flexibility HaaS Marketing Data Security Bring Your Own Device WiFi Data Management IT solutions Work/Life Balance Entertainment Website Budget Risk Management USB Hacker End of Support Education Physical Security The Internet of Things Safety Lithium-ion battery Conferencing HIPAA Sports Redundancy Scam Keyboard Firewall Data Protection Vendor Virtual Reality Vendor Management Apple Managed Services Display Social Save Time User Error Employee/Employer Relationship Meetings Telephone System Staff Software as a Service RMM Cleaning Machine Learning Remote Work Connectivity Biometrics Battery Virtual Desktop Google Docs Identity Theft Hiring/Firing Digital Signage Shadow IT IT Consultant Legal DDoS Internet Exlporer SharePoint Humor Procurement Augmented Reality Workplace Strategy Fraud Net Neutrality PDF Business Intelligence Help Desk Remote Worker Customer Service Environment Audit Printing Worker Proactive IT Cryptocurrency IT Management Best Practice Fax Server Botnet YouTube Black Market IT Plan Managed Services Provider SaaS Comparison Database CES Unsupported Software Remote Workers Document Management Virus Wireless Technology Network Congestion Charger Solid State Drive How to Unified Threat Management Downtime Business Technology eWaste Content Management Processor Compliance Computer Accessories Access Control OneNote Computer Care Data storage Virtual Assistant Current Events Hard Drive Automobile Authentication Telephony Samsung Wearable Technology Hard Drives Computing Printer Computing Infrastructure Retail Going Green Instant Messaging Bluetooth Value Robot Update Excel Spam Blocking Electronic Medical Records Laptop HVAC Google Apps Screen Mirroring Messaging Loyalty Cabling Techology Hypervisor Books Customers Analysis Frequently Asked Questions Policy Dark mode Windows 10s Trend Micro Audiobook Administrator Devices Mobile Touchpad Enterprise Content Management Cast SMS Default App Saving Time Emergency MSP Accountants Tip of the week Procedure Science webinar Professional Services dark theme Credit Cards Public Cloud Shopping Politics Employer Employee Relationship Google Search Advertising Microchip Thought Leadership Password Management Password Manager AI Assessment IT Infrastructure Bing Distributed Denial of Service Notifications Customer Relationship Management Windows Server 2008 FinTech Multi-Factor Security Tools Analyitcs Social Network Search Engine Twitter NIST Business Mangement Programming Television Investment Employee/Employer Relationships Consultant Relocation Smart Tech Employees Trending Windows 365 Amazon ISP Analytics Addiction Antivirus Recycling Video Conferencing Public Computer ROI Video Games Bitcoin Best Available Worker Commute Transportation Shortcuts Wiring Practices Regulations Sales Windows 8 IT service Point of Sale Amazon Web Services Computer Fan Personal WIndows 7 Experience Rootkit Cryptomining Cache Scalability Safe Mode Criminal Supply Chain Management Tablet Workers Batteries Business Owner Benefits GDPR Hosted Computing Monitoring NarrowBand Wireless Internet Domains Windows 8.1 Online Shopping FENG Digitize Search File Sharing IBM Windows Server 2008 R2 Specifications Smart Technology iPhone Camera IaaS Inventory Maintenance Flash Customer relationships Wire Email Best Practices Evernote Bloatware IT Assessment User Manufacturing PowerPoint Windows Media Player Software Tips Travel Supercomputer Millennials Tablets Emails Managed IT Service Security Cameras Files Printers Sync Computer Tips Chromecast Smart Office Virtual CIO Wireless Charging Entrepreneur OneDrive Managing Stress Biometric Security Peripheral Workforce Netflix Using Data Two Factor Authentication Cameras Colocation Virtual Private Network Uninterrupted Power Supply Shortcut Digital Security Cameras Cables Cost Management Root Cause Analysis Copiers 5G Music Monitor Social Networking HBO Quick Tip Knowledge Ergonomics Telecommuting Smartwatch Project Management Nanotechnology Skype Cortana Data loss Development OLED Virtual Machine Troubleshooting Reputation Running Cable Streaming Media Digital Signature Outlook PCI DSS Leadership 2FA Memory Fiber Optics Content Employee Printer Server Warranty Tech Support Start Menu

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code