Monday, 2016-11-07

* Bitweasil yawns14:40
BitweasilMorning, all.14:40
warthog9'morning Bitweasil17:44
warthog9i won't claim it's "good" on account of it being Monday, and being exhausted ;-)17:44
ecdhewarthog9, did you get an extra hour of sleep this weekend? Or are you in a anti-dst state?18:09
warthog9ecdhe: I got the extra hour18:32
warthog9but sadly, not of sleep18:32
warthog9Personally I'd be happy to be in one of the anti-dst states18:33
ecdheMe too, I'd be glad to see DST removed nation wide.  Nobody has asked me, though.19:15
warthog9ecdhe: that's 'cause they don't ask sane/normal/folks like us ;-)19:35
warthog9(noting that 'sane' is probably used very relatively, at least in my case)19:35
ecdhewarthog9, have you looked into badgereader setups any more?19:54
ecdheI hear the yubikey neo has an NFC interface, could be great for access controls.  I'm familiar with the HID Millenium system now, but it seems like anyone with some basic arduino skills could build a spoofer for that.19:55
warthog9ecdhe: I haven't dug back into them recently19:55
ecdheA bluetooth-managed deadbolt is secure against key forgery... until it isn't.19:56
warthog9ecdhe: yup19:56
warthog9that being said, keys on doors are laughable from a security perspective19:57
warthog9since most key locks are not nearly as secure as everyone would like to think19:57
BitweasilOh, come on.  It takes at /least/ a few seconds to bump pick one.20:11
ecdheIt's just nice when your lock is based on strong cryptographic primitives...20:12
BitweasilYeah, the side channels in implementation that leak the key don't matter. ;)20:12
ecdheThe badge solutions from billion dollar vendors are vulnerable to replay attacks...  access is controlled on the basis of a badge's ability to repeat a number in the clear.20:13
ecdheAnyone with an RTLSDR and an upconverter can get every access code used all day, whether through skimming or a hi gain antenna20:14
ecdheBy simply replaying those codes you could gain access as any account which you overhear authenticating.20:15
BitweasilI'm quite aware.20:16
warthog9I'm actually surprised that there aren't more rfid type cards that do a challenge response OTP type negotiation out there21:56
