Tech Talk

Recent posts

We’re hardly out of the woods with COVID-19, and that means many properties will have to make do with a customer base mostly derived from local leisure, staycations and workcations from drive-to markets. With fewer overall guests, outside of cost savings efforts we must simultaneously look at maximizing the revenue per available guest (RevPAG), and there’s no better way to go about this than by sharpening your use of the PMS.

This is the last issue of Siegel Sez before this year’s CYBER HITEC event. HITEC is an event I have not missed in 30 years, and historically it has always been a great place to find innovation.

Toxicity Kills
Posted: 10/07/2020

It doesn’t matter if it is toxins in your physical environment or toxins in your mental environment. This stuff kills! 

It’s said that when someone’s mindset shifts, everything around them can change at the same time, and in our current setting, the importance of being in the right headspace, both personally and as an organization, can’t be discussed enough.

In my last installment, I introduced four areas of hospitality technology that I believe have been significantly changed by COVID-19. I covered contactless technologies in depth in that first article. This week I will turn to the other three areas: social distancing; health and sanitation; and communications.



want to read more articles like this?

want to read more articles like this?

Sign up to receive our twice-a-month Watercooler and Siegel Sez Newsletters and never miss another article or news story.

x
 

New POS Threat - Onsite Assessment vs. Check the Box

08/09/2016
by David Durko

Last week a new hacking device that threatens many POS and door lock systems circulated like wildfire. We have been fielding a large number of calls from clients and prospects asking questions about the story and the risks to their properties.

The reality is if this tool becomes generally available the threat landscape will expand significantly for hoteliers. The tone of our calls was somber since this is yet another risk our clients have to face. It also shines on the painfully slow rollout of EMV across all of the name brands (mag stripe vs. chip and pin).

The bright spot that came from our calls was a general agreement that having a data security firm perform an on-site assessment that includes interviewing, training and raising the overall awareness of the staff makes the property a little more secure. Certainly much more secure than a property that simply performs a “check-the-box” exercise. It also put a spotlight on the PCI controls that are often missed by hotels. Logging firewall activities, logging of OS and applications, file integrity monitoring, pentesting, vulnerability management and more.

If this hacking tool makes its way into the wild it will be difficult to prevent an attack.  But assessment, awareness and management of cardholder systems could help mitigate the risks.  At the end of the day an onsite assessment trumps “check the box.”      

Data theft is a constant concern for hotels, but a new tool developed by a security researcher may raise the alarm on physical security in hospitality. Weston Hecker, a security researcher with Internet security company Rapid7, modified existing technology to create a device capable of reading and duplicating hotel keycards, and is even capable of guessing every room’s key across a property.  The device was designed by altering the MagSpoof tool developed last year by hacker Samy Kamkar. At the time of its development, MagSpoof was able to wirelessly read magstripes off of cards used for door entry or payment transactions by producing a magnetic field similar to a mag stripe when swiped, storing card data for later use.

Hacker’s modification only adds $6 worth of hardware to the MagSpoof, and allows a hacker to take the information from any key, which includes encoded information regarding guestroom numbers and checkout dates, and then guesses the correct information to create a copy. The device can then run through every possible combination of these details before letting the user into a room.  While hotel door locks continue their shift to radio frequency identification and Bluetooth technology and away from magstripes, it remains to be seen how this device would be used to access rooms under these circumstances. However, not all hotels have fully upgraded past magstripes, making them more vulnerable than ever to entry. At the same time, while credit card companies are shifting to chipped cards and card readers, magstripes still remain a popular option for travelers meaning point-of-sale systems could become a larger target. Hacker’s tool can inject keystrokes into a PoS system with a magstripe reader simply by being placed near it, forcing the reader to accept data as long as it remains within a few inches.

About The Author
David Durko
CEO
Security Validation


David Durko is the CEO of Security Validation a leading managed data security and privacy firm servicing the hospitality industry.

 
Comments
Blog post currently doesn't have any comments.
Leave comment



 Security code