Electronic locks can provide security- and convenience-enhancing features, with fingerprint readers an increasingly common feature in these products. When equipped with a wireless radio, they become a smart lock and join the billions of IoT devices proliferating our world. However, such capabilities can also be used to transform smart locks into fingerprint harvesters that compromise an individual's security without their knowledge. We have named this the droplock attack. This paper demonstrates how the harvesting technique works, shows that off-the-shelf smart locks can be invisibly modified to perform such attacks, discusses the implications for smart device design and usage, and calls for better manufacturer and public treatment of this issue.
翻译:电子锁可以提供安全和方便的功能,指纹阅读器在这些产品中越来越常见。当安装无线收音机时,它们会成为智能锁,加入成成百上千个扩散我们世界的IoT装置。然而,这种能力也可以用来将智能锁转换成指纹采集器,从而损害个人的安全,而个人却不知道这一点。我们称之为投放锁攻击。本文展示了收割技术如何运作,表明现成的智能锁可以不可察觉地被改装来进行这种攻击,讨论智能设备设计和使用的影响,并呼吁改进制造商和公众对这一问题的处理。