DEF CON 33 - Hacking Hotel Locks: The Saflok Vulnerabilities Expanded -Noah Holland, Josh Stiebel

DEF CON 33 - Hacking Hotel Locks: The Saflok Vulnerabilities Expanded -Noah Holland, Josh Stiebel

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The Safelock hotel lock vulnerability, previously thought patched, remains exploitable with new methods that bypass security measures 1:06-1:12.

Key Takeaways:
• All Safelock data was encrypted with the same weak algorithm across all properties, creating a systemic vulnerability 11:46-12:13
• The HH6 programmer can interrogate any lock regardless of property ID, making exploitation easier than previously believed 18:56-19:35
• Even "patched" systems using Ultralight C cards remain vulnerable if not implementing enhanced security features 23:31-24:00
• Upgrading to Ultralight C alone provides minimal security benefit against determined attackers 28:17-29:06

Hotels must fully implement enhanced security measures rather than just upgrading card types to protect against these vulnerabilities.

Sources:

  • 1:06-1:12 Overview of original unsafe lock vulnerability
  • 11:46-12:13 Explanation of weak encryption algorithm
  • 18:56-19:35 HH6 programmer capabilities
  • 23:31-24:00 Demonstration of Ultralight C vulnerability
  • 28:17-29:06 Explanation of insufficient patch implementation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay, so hacking hotel locks. Okay, thank you. Uh yeah, so we did our talk on uh expanding on the safe lock vulnerabilities that were discussed last year at DevCon. Uh there was a number of things excluded in the talk and there were some different uh areas they didn't investigate. So we wanted to kind of elaborate on those. We also are hosting a demonstration on some of this at the physical security village. So if you're interested, stop by after the talk. Uh we'll mention this again. Uh so about us. Um my name is Noah Holland. I'm an undergrad at Michigan Tech. I'm the president of the Red Team and Linux users group uh clubs. Uh and I host the access control village at various conventions and am a co-founder of Badac LLC with Josh. >> Um I'm Josh. I'm a Michigan Tech alumni. Um I co-host …