/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers discover flaw in Vingcard's Vision locks, used in 140K hotels in 160 counties, that lets them create master key using $300 reader and old key card

IN 2003, FINNISH security researcher Tomi Tuominen was attending a security conference in Berlin when a friend's laptop …

Wired Andy Greenberg

Context & Ripple Effects

This finding extends a pattern Wired has tracked across physical-access security: researchers repeatedly show that shared cryptographic keys and cheap hardware defeat locks and vehicles at fleet scale. The closest precedent in hotel locks is the profile of Aaron Cashatt, who turned a bug disclosed by researchers in 2012 and $50 of hardware into 75+ room burglaries — evidence that published lock research reaches criminals, not just vendors.

The same template appeared in cars: the Volkswagen key-fob cloning research showed millions of vehicles sharing cryptographic keys that inexpensive radio hardware could exploit. Six years after the Vingcard disclosure, the Saflok hacking technique hit RFID locks across 13K properties — suggesting the hotel-lock industry's fix cycle did not close the class of vulnerability.

First-order effects

  • Hotels running Vingcard Vision locks — roughly 140,000 properties in 160 countries — must rely on Vingcard for patches or lock replacement, since the master-key forgery needs only an old guest card and a $300 reader an attacker can carry casually.

Second-order effects

  • Hotel chains and their insurers face pressure to audit lock firmware and re-key or upgrade estates, shifting procurement toward vendors who can push cryptographic updates rather than ship fixed-key hardware.

Third-order effects

  • If the Cashatt precedent repeats, disclosure-to-remediation lag becomes the real attack window: embedded locks deployed for decades cannot be patched like software, pushing the industry toward replaceable, updatable credential architectures — the same reckoning the automotive immobilizer findings forced on carmakers.

The trend: Shared-key designs in deployed-at-scale physical security — hotel locks, car fobs, immobilizers — keep falling to low-cost hardware, and the gap between researcher disclosure and fleet-wide remediation is where the risk lives.