Job Recruitment Website - Recruitment portal - What is the "little black box" that opens the smart lock in 3 seconds?
What is the "little black box" that opens the smart lock in 3 seconds?
However, in the store, there are often unlocking experts to "kick the pavilion".
According to insiders, this is almost a hidden rule in the industry. For example, Zhang Hongjun, known as the "Ghost Horse Master" in the locksmith circle, has been a frequent visitor to China International Import Expo(CIIE) over the years.
Because it is normal, on the first day in China International Import Expo(CIIE), a young woman named Wang Haili declared to the booth that "I can unlock your smart lock in 3 seconds", and no one cared.
Insiders said that people didn't care at first because of the past "kicking the pavilion", and both sides had tacit "Jianghu rules"-
There is no lock in the world that can't be opened. It's only a matter of time. It's not a mistake if you can't open it on the spot. Shake hands and make friends. If the lock is unfortunately broken, the locksmith will not embarrass you. Send you an improved method and charge you a "consulting fee". For merchants, this is not a bad thing, mutual promotion, common progress and mutual benefit.
But Wang Haili's next operation made many smart lock businesses feel chilly!
Wang Haili took out a small black plastic box from his bag.
A little smaller than a mobile phone, but twice as thick, with a copper coil exposed at the top of the box.
This is the little black box that appeared at the Expo.
There are only two buttons on the black box: the power button on the bottom and the trigger switch on the side.
Put the copper coil of the black box close to the smart lock, walk in different positions of the lock body, and press the trigger button once at the same time, with a swish. With the rotation of the motor in the lock body, the original smart lock of fingerprint and password is opened!
Everyone began to sit still. ...
Wang Haili, on the other hand, "killed someone", and the whole process was horribly relaxed: there was no time-consuming and laborious violent unlocking, not to mention complicated and high-end technical cracking. The black box was like an access card, and the door was wide open!
1、2、3、4……
Wang Haili opened eight brands of smart locks on the spot, and the fastest one really took only 3 seconds!
It is no exaggeration to say that smart locks have never been abused so much since the hidden rules of kicking the pavilion came into being.
More and more people are watching. Everyone takes out their mobile phones and focuses on Wang Haili and her little black box.
Next, the incident began to ferment in the lock circle, and videos of smart locks being opened by small black boxes appeared in the WeChat circle of friends of locksmiths and lock dealers-these smart locks that were opened in seconds were not only in the store, but also in the community. It was instantly captured.
At the same time, an article "That woman ruined the whole fingerprint lock industry" began to circulate on the Internet, and the industry circle was in an uproar.
What kind of broken lock is a little black box?
What's wrong with these smart locks? Encountered such a fiasco?
Who is Wang Haili accused of "destroying the smart lock industry"? Why would she do that?
On the morning of June 24th, Xuzhou, Jiangsu, the "Curious Lab" of Urban Express interviewed her.
Small black boxes are out of stock at present.
Dramatization has become a magic weapon for business self-examination, and some of it has flowed into the market.
"Curious Lab" has alerted the Ministry of Public Security.
"I have offended many people, but this industry really needs to be reshuffled."
Wang Haili said that she is the owner of a smart lock company in Hunan, and the black box was made together with a manufacturer of unlocking tools in Changzhou. Going to the Yongkang World Expo to "do things" is the real "kicking the pavilion". Why did you kick the gym?
Many of our locks have been sold abroad, so some people imitate us. If you just imitate our good technology, I can't help it. But they imitated my appearance and my advertisement, but they used the worst technology and accessories, and said it was my branch. I quit!
Do you know that this matter is a headache for many brands and distributors?
For example, a lock company in Hangzhou, often interviewed by Curious Lab, has represented several brands of smart locks and is also cooperating to develop a new type of smart locks. Now they're embarrassed and don't know what's wrong with the lock. Once they encounter the black box, is the agent's lock reliable? Can the newly developed lock hold up? I've been asking about our progress these days.
After the Expo, insiders asked me to buy a little black box. It used to be for you, but now I just started this business. I named the little black box "Professional Detection Tool for Intelligent Locks", and each 580 yuan was sold to 1200 yuan at the highest time.
The crazier those videos spread, the more malicious the voice that I ruined the whole industry, but the little black boxes are selling more and more, and they are almost out of stock. Originally an unlocking tool, it has now become a testing tool for brands and dealers to verify whether their smart locks are safe. The play itself illustrates many problems. How much did the little black box cost?
Over the past month, I have been traveling in several cities, and set up warehouses in Ningbo, Yongkang and Changsha, with sales exceeding 3,000 units.
Because there is only one production line, the production capacity can't keep up, and all the delivery warehouses are supplied by quota, so some orders have to be postponed. At present, two similar black boxes have appeared on the market, which are made in Taizhou and are cheaper.
Wechat now receives feedback from users every day, and more and more smart locks are cracked by black boxes.
Aren't you worried that this thing will fall into the wrong hands?
I'm also worried about accidents. Any unlocking tool is a double-edged sword.
We sell carefully, mainly for brands, dealers and locksmiths.
Brands need to have logos, and some brands are also worried that we will not deliver goods, and they also offer business licenses and home photos.
Dealers are friends, most of them know each other, and the crowd is relatively uncomplicated.
Locksmiths need to provide a national unified professional qualification certificate.
They are all registered one by one, and the destination is very clear. This is also the unlocking tool required by the public security department.
Because the video of the smart lock being opened in seconds was forwarded in large quantities, someone did contact us to get the goods, but they all refused.
However, we hope that the relevant departments will manage the loopholes in smart locks, and don't hide them. Now everyone in this business knows. The black box is actually a Tesla coil, which has been sold on Taobao.
Workers in the production workshop are assembling small black boxes.
The structure of the black box is not complicated, just a Tesla coil-a device that boosts the ordinary voltage with a transformer and then discharges from the discharge terminal through a two-stage coil; Generally speaking, artificial lightning has many fans all over the world.
Tesla coil will produce strong electromagnetic pulse. If you put it near a fluorescent tube, it will glow. This kind of high-frequency and high-intensity electromagnetic pulse can destroy the surrounding electronic equipment.
Although Wang Haili didn't elaborate on which loophole of the smart lock Tesla coil attacked, what she was worried about finally happened.
In the early morning of June 26, Curious Lab found that this "double-edged sword" has been publicly transferred from WeChat friends circle to Taobao online sales. There are more than 0 stores 10, and the delivery locations are Chongqing, Dongguan and Xuzhou. The price is cheaper. As long as each set is in 320 yuan, the highest sales volume has been sold 160 sets.
"There are a lot of orders recently, and they will be delivered tomorrow." Unexpectedly, as an unlocking tool, the seller did not ask the reporter for any identification.
In this regard, Curious Lab reported to the Cybercrime Alarm Platform of the Ministry of Public Security and the Ali Illegal Commodity Alarm Platform yesterday.
Measured by Curious Lab:
Unlock it with a small black box
What is the success rate?
Is this fiasco of smart locks really caused by some smart lock manufacturers cutting corners?
After Yongkang opened, Curious Lab contacted Zhejiang Lock Product Quality Inspection Center.
The testing center reported that they also got the black box at the first time and took the 10 smart lock from the warehouse for testing. As a result, 1 was opened, but the vulnerability and cracking principle are still unclear.
The lock breaking rate of10:1doesn't seem to be very serious, but some insiders remind that the locks sent to the quality inspection center are often different from those after mass production.
"What is needed in front is to pass, and what is considered later is the cost."
On the other hand, many merchants quickly broadcast the video "Tested by Tesla coil, not cracked" after the incident of Yongkang Pavilion kicking, in order to cope with the current storm.
If you type the keyword "Tesla coil, strong electromagnetic pulse" in the search engine, you will see almost the same content, especially in the principle of cracking-
The explanation of the insiders is that after the strong electromagnetic pulse generated by Tesla coil attacks the smart lock chip, it will cause the chip to crash and restart, and some smart locks will automatically unlock after restarting by default, so Tesla coil can open the smart lock in seconds.
Although this incident cannot represent the whole industry, it has caused a sensation and panic in the whole industry, indicating that everyone is very concerned about the stability and safety of smart lock products ... As users, when buying smart locks, we should not only look at the price, but also look at the quality of the products.
There is no evidence in the mouth, and the experiment is evidence. Curious lab measured it for everyone to see. It takes less than 3 minutes to open three locks in the small black box delivery warehouse, and the fastest one takes only 5 seconds.
On June 22nd, in the workshop of zhenhai district, Ningbo, Li Dehui, a colleague and technician of Wang Haili, was busy packing black boxes. Each box is equipped with a paper manual and a test light bulb, and the list is filled out and sent over.
The pulse generated by the black box can make the light bulb glow without power supply.
"It has been sent to all parts of the country. Just the warehouse in Ningbo, more than 300 units were issued in this half month. " Li Dehui said.
"Basically can open, we tried the lock of * * * 10, all open. The dealer came to the news that he represented six door locks, all of which were opened by black boxes. " Li Dehui replied.
Li Dehui took out three smart locks for testing, all made by dealers in China.
The experimenter tested the smart lock on the spot.
First, the XXX brand smart lock was tested, including fingerprint, password, magnetic card, key and other opening functions, and the price was more than 5,000 yuan.
"Every lock has a different point, which may be on the top, middle, bottom and even on the side. So keep moving and find the unlocked position. " Li Dehui said.
In this way, the experimenter kept moving up and down, left and right, just like mine sweeping.
After half a minute, the experimenter changed a small black box to continue the experiment. Suddenly, with a swish, the door lock was opened. The unlocking position is fixed at the swipe of the door lock. Need 1 min.
The second is a brand of smart lock, the price is more than 3000 yuan, and it is also a variety of opening methods such as magnetic card, fingerprint and password.
The experimenter slowly searched from top to bottom. About 1 minute, the door lock is opened, and the unlocking point is also set at the card swiping place.
The third lock is an ordinary ××× smart lock, the price is about 1000 yuan, and the function is similar. But it only took the experimenter five seconds to open the lock. The experimenter used his own smart lock to test, but the door didn't open, but the door lock crashed.
The experimenter's home is in a residential area in the north of Hangzhou, and the house was delivered on 20 14. The smart door lock was installed by the developer, and the brand and logo logo were not visible.
Unexpectedly, just as the little black box approached, the door lock suddenly crashed-
After being attacked by the black box, the door lock system did not respond, the backlight was not bright, and the system prompt tone disappeared, just like a door lock without battery. No operation can open the door.
Finally, the experimenter connected a No.7 battery to the emergency power supply of the door lock, and the system restarted and returned to normal. Hangzhou Lock Market Blind Test 10 Smart Lock Opening II.
Finally, the experimenter went to a hardware lock market in Hangzhou, randomly entered two lock shops, and made a blind test of the 10 locks on sale.
The first one is a smart lock, priced at 1800 yuan. Luck is better. When the black box is near the middle of the keyboard, the door lock is opened.
However, eight smart locks were tested continuously, and they could not be opened. They all behave the same-they can trigger the system backlight and voice broadcast, but they just can't unlock it.
Finally, I opened an X brand smart lock at the price of 900 yuan. At first, it was only half the effort-the bolt of this lock is segmented and it has to be retracted twice before it can be opened. But after being attacked by the little black box, the lock tongue kept coming in and out, but it didn't fully open.
The experimenter kept charging the sunspot for nearly 20 times and finally opened the lock.
Experts believe that after actual measurement
The biggest defect is the motor input signal of the smart lock.
On June 23rd, Li Yangyuan, Chief Technology Officer of Suzhou Mindray Microelectronics Co., Ltd., was interviewed by Curious Lab.
First of all, Li Yangyuan does not agree that cutting corners is the chief culprit of this incident.
After Yongkang Expo, Li Yangyuan also received a small black box from his partner Ningbo Xzhou Lock Industry, asking him to test a smart lock under the brand.
Regulator and current overload protection are used to optimize and protect the power supply system. When we use the coil to unlock the lock, we can hear the voice broadcast:' It has been opened', indicating that the overall function of the smart lock, including the power supply, is normal. The coil pulse did not destroy the power supply system, so it can be inferred that it has nothing to do with the voltage regulator. "
Secondly, Li Yangyuan believes that there is indeed the possibility of "crashing and restarting, leading to cracking".
So, are there any other possibilities?
Generally, it takes three steps to open a smart lock:
First, input, such as password, fingerprint, face recognition, etc. ;
2. Authentication: The chip identifies and authenticates the input signal;
Implementation, certification is correct, the system sends out command signals, rotates the motor, and opens the door lock.
When the black box breaks the smart lock, there is no information input and identification authentication. The problem lies in the execution of the third step. The final opening of the smart lock is driven by the rotation of the motor, so Li Yangyuan thinks that the key point of the test should be the input signal of the motor.
"It is very likely that the pulse interference of the small black box generates current, and the signal is generated by the components inside the smart lock, which makes the system mistakenly think that it is a normal command and triggers the motor to start."
In order to verify this conjecture, Li Yangyuan took apart a smart lock and unplugged the power inside. When the black box approached the circuit board again, something magical happened-
Obviously, there is no power supply and there is a voltage response on the multimeter. Then turn on the power and attack the test with the black box again. At this time, the lock was opened! That is to say, under the interference of electromagnetic waves, there is current, which, like a signal bullet, triggers the motor to drive the chip, so the lock is opened.
"Even if you don't use a small black box, it is possible to drive the motor as long as it is a device that will produce electromagnetic interference."
Li Yangyuan picked up an ordinary walkie-talkie and slowly approached the door lock where the power supply was removed. It really only took 1 sec this time, seconds open!
Using walkie-talkie to test, as long as the frequency is high, it can also interfere with the smart lock. Fully automatic intelligent lock is the easiest to open.
There are two ways to start the motor of the smart lock: fully automatic and semi-automatic.
Specifically, as long as the automatic smart lock is certified, the lock tongue will automatically return and the door will automatically open; There are also semi-automatic ones that need to be turned to open.
In Li Yangyuan's view, the difficulty of cracking these two different startup methods is very different.
The semi-automatic handle door lock has two motor control lines, and the two lines need to meet a high-low level difference, just like ECG, which is an unlocking signal.
"This requires a small black box to find a specific location, plus luck to open the door lock."
Automatic door locks usually use a key switch when unlocking from the inside. Because for a better user experience, only a short press is needed. For jammers, it is certainly much easier to make one line produce instantaneous potential changes than two lines produce different continuous potentials. Is the smart lock that has not been cracked by the black box really safe?
Some lock dealers are glad: "My lock has not been cracked by the black box, and my lock is safe."
But Li Yangyuan disagreed.
"First of all, the black box is an unlocking tool, not a standard testing tool. Its power, distance, frequency and other factors will affect the success rate of unlocking.
"Secondly, in terms of risk, it should be universal, because it is an industrial standard for DC motor drive chips to be controlled by level, and DC motor drive circuits all over the world do so. The smart lock is opened by wireless interference. This is not a problem of cutting corners, but a design loophole. "
Black and white photos printed on A4 paper can actually fool models.
Intelligent Locksmith Face Recognition System: The more functions a lock has,
The more back doors are left!
During the whole interview, "Curious Lab" heard the locksmith say many times: The more functions the lock has, the more back doors it will leave! Black and white photos printed on A4 paper fooled face recognition.
In a talent apartment in Suzhou Industrial Park, engineer Wu Hanfeng demonstrated the vulnerability of a domestic smart lock face recognition system to Curious Lab.
The experiment is divided into three steps-
First, the experimenter's face is registered in the system.
Then, I took a photo of the experimenter and printed it in black and white on A4 paper.
Finally, the black and white photos printed on A4 paper are close to the face recognition probe on the smart lock.
- Related articles
- Can I go to work in Texas with Yan Yijin?
- Notice of Anyang Housing and Urban-Rural Development Bureau
- What about Yantai Muping Haiwang Aquatic Products Co., Ltd.?
- Tantalum mine recruitment
- Jiangyan Huaxing marine machinery factory recruitment information, Jiangyan Huaxing marine machinery factory?
- What are the minor fault codes of Shanghai Mitsubishi elevator LEHY-II?
- Are veterans in Hefei Aquarium free?
- Regulations of Yangjiang Municipality on the Protection of Water Quality in Yang Mo River Basin
- In which district of Chengdu is Jiang 'an Campus of Sichuan University?
- Is Xuebajun a subsidiary of Xueersi? Xuebajun has gone bankrupt?