Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

It Only Takes 8 Seconds for a Hacker to Open Your Garage Door


b2ap3_thumbnail_garage_hackers_400.jpgHackers have proven to be a crafty and suspicious lot, and can take advantage of even the most benign technology to infiltrate networks. However, we don’t often associate them with objects in the physical world. Now, even something as simple as a decade-old communications device can be used to open the right garage doors.

The device in question was built from a discontinued toy from 2007 called the IM ME. Manufactured by Mattel, it’s a device that was advertised as a secure wireless instant messaging system, sort of like an archaic mobile phone that allows for texting. It stores an address book of other users of the IM ME system, and allows for communications between devices so long as the device had an Internet connection. Looking at it now, you wouldn’t be surprised to hear that it’s no longer supported or even remotely useful these days, especially since smartphones are so much more dynamic and effective for communication.

Last year, it was discovered that this toy could be altered to hack into any garage door that’s equipped with an insecure fixed code transmitted from a remote, rather than one that uses a “rolling code” that’s constantly changing with every button press. The flaw was discovered and exploited by Samy Kamkar, who works as an independant developer and technology consultant. He reportedly built the device out of the IM ME, adding only an antennae and a simple open-source hardware attachment.

Kamkar explains that his device, which he dubs the OpenSesame, works in a different fashion from what are known as “code grabbers.” Ordinarily, code grabbers are devices that capture the code from the garage door button when it’s pressed, and can then reuse the code at a later time. This requires the presence of the hacker when the button is pressed. OpenSesame can accomplish this without being anywhere near the user, which makes it significantly more versatile and dangerous.

The most dangerous part of this hacking experiment is the fact that any hacker can walk up to a vulnerable garage door and have it open in around eight seconds. As reported by WIRED:

Using a straightforward cracking technique, it still would have taken Kamkar’s program 29 minutes to try every possible code. But Kamkar improved his attack by taking out wait periods between code guesses, removing redundant transmissions, and finally using a clever optimization that transmitted overlapped codes, what’s known as a De Bruijn sequence. With all those tweaks, he was able to reduce the attack time from 1,771 seconds to a mere eight seconds.

If you want to know how OpenSesame works, you can watch this video. If you’re unsure of whether or not your garage door is vulnerable to this particular issue, you can watch this video released by Kamkar:

This just goes to show how dangerous and unpredictable some of the things on the Internet of Things can be. With so many devices capable of communicating with each other through near-field and Bluetooth communications, in a worst-case scenario, it becomes a liability that can quickly spiral out of control. Concepts like these should make your business question if it’s prepared to handle the dangers that are approaching in the form of unregulated Internet of Things devices. Considering how much your business stands to lose, you shouldn’t be putting your organization at this kind of risk.

We can give your business’s network a quality assessment to ensure that it’s not vulnerable to other Internet of Things devices and emerging technologies. To learn more, give us a call at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 30 April 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Workplace Tips Backup Innovation User Tips Data Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications Business Continuity Smartphones Communication IT Support Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Windows Upgrade Phishing Managed IT Services Ransomware Data Backup Outsourced IT Windows 10 Office Server Save Money Data Recovery Cloud Computing Windows 10 Passwords Saving Money Holiday Gadgets Chrome Virtualization Social Media Tech Term Managed IT Services Microsoft Office Automation Managed Service Cybercrime Artificial Intelligence Operating System Facebook Computers Health BYOD Mobile Device Management Internet of Things Networking IT Support Wi-Fi Hacking Remote Spam Alert Managed Service Provider Office 365 Telephone Systems Covid-19 Information Information Technology BDR Bandwidth Social Engineering Mobility Recovery Employer-Employee Relationship Router Human Resources Application Law Enforcement Remote Monitoring Big Data Password Money App History Encryption Applications Mobile Computing Data Breach Government Remote Computing Private Cloud Mobile Office How To Managed IT Blockchain Paperless Office Apps Office Tips Training Data Storage Patch Management VPN Website Servers Budget Two-factor Authentication Avoiding Downtime Mouse HaaS Data Security Bring Your Own Device Data Management Work/Life Balance Wireless Flexibility Vulnerability Marketing Gmail Windows 7 Word Google Drive Infrastructure Voice over Internet Protocol WiFi Settings IT solutions Entertainment Vendor Management USB Virtual Reality Apple Data Protection Social User Error Save Time Meetings Cleaning Vendor Managed Services Risk Management Software as a Service Display Telephone System Hacker Staff Machine Learning End of Support Connectivity Remote Work The Internet of Things Conferencing Physical Security Lithium-ion battery Education Employee/Employer Relationship Scam Safety RMM HIPAA Sports Redundancy Firewall Keyboard Fraud Best Practice Digital Signage SaaS Unsupported Software Remote Worker YouTube Black Market Cryptocurrency Charger IT Consultant Compliance Network Congestion Document Management OneNote Computer Care Procurement eWaste Comparison Net Neutrality Solid State Drive Workplace Strategy Wireless Technology Humor Current Events Downtime How to Telephony Samsung CES Help Desk Printing Data storage Wearable Technology Automobile Business Technology Value Content Management Retail Hard Drives Access Control Instant Messaging Spam Blocking Electronic Medical Records Managed Services Provider Robot Computing Infrastructure Virtual Assistant Excel Authentication Database Going Green Biometrics Hiring/Firing Virtual Desktop Remote Workers Virus Processor Battery Update DDoS Shadow IT Unified Threat Management Legal Computer Accessories Hard Drive SharePoint Google Docs Business Intelligence Internet Exlporer Identity Theft Audit Worker Customer Service PDF IT Management Computing Environment Botnet Printer Fax Server Bluetooth IT Plan Augmented Reality Proactive IT Workers Twitter Messaging Benefits Cabling IT service Video Games Search Engine Worker Commute FENG NIST Policy Printer Server Business Mangement Hypervisor Trending Experience Dark mode Tablet IBM Smart Tech Trend Micro Addiction SMS Smart Technology Amazon Default App Domains Scalability Flash Business Owner Procedure Recycling Saving Time Google Search IaaS Maintenance Software Tips Wiring dark theme NarrowBand Supercomputer Practices Shopping Emails Cache AI Amazon Web Services IT Infrastructure Search Sync Bloatware iPhone Safe Mode FinTech Criminal Bing GDPR Tablets Hosted Computing Social Network Netflix Wireless Internet Two Factor Authentication Online Shopping Investment Entrepreneur Files Root Cause Analysis File Sharing Employees Employee/Employer Relationships Music Specifications ISP Shortcut HBO Camera Windows 365 Chromecast Knowledge Inventory Cost Management Consultant Wire Video Conferencing Evernote ROI Skype Social Networking Colocation Data loss Sales Uninterrupted Power Supply Analytics Bitcoin Travel Shortcuts Troubleshooting Millennials Cryptomining Outlook Printers Point of Sale Leadership Personal Monitor Best Available Smart Office Supply Chain Management Wireless Charging Start Menu Running Cable WIndows 7 Screen Mirroring Monitoring Loyalty Batteries Digitize Books Workforce Frequently Asked Questions Virtual Private Network Windows 8.1 Memory Reputation Windows 10s Streaming Media Cables Windows Server 2008 R2 Mobile Content Cast Customer relationships Tech Support Nanotechnology IT Assessment Emergency Telecommuting Manufacturing Techology Tip of the week Project Management Email Best Practices Laptop webinar Customers Public Cloud Employer Employee Relationship Cortana Professional Services Security Cameras Audiobook User Computer Tips Science PowerPoint Assessment Digital Signature Managed IT Service Windows Media Player OneDrive Biometric Security Windows Server 2008 Warranty Virtual CIO Touchpad Tools HVAC Peripheral Google Apps Distributed Denial of Service Politics Customer Relationship Management Advertising Managing Stress Digital Security Cameras Television Analysis Using Data Devices Copiers 5G Administrator Analyitcs Programming Enterprise Content Management Quick Tip Notifications Cameras Smartwatch MSP Ergonomics Public Computer Accountants Thought Leadership Development Transportation Credit Cards OLED Regulations Microchip Relocation Computer Fan Password Management PCI DSS Rootkit Password Manager Virtual Machine Antivirus Multi-Factor Security Employee 2FA Windows 8 Fiber Optics

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code