Electronic lockers are everywhere - offices, gyms, hotels, hospitals, co-working spaces. You choose a PIN, toss in your stuff, and trust that it's safe. The same goes for electronic safes in hotel rooms and offices. But what does the lock actually do with your PIN? Turns out, it remembers it. And not very carefully.
We demonstrate how someone with access to a single open locker or safe can extract credentials, clone manager keys, and open every lock in an installation using cheap and widely available tools. More critically, we show how harvested PINs open more than just lockers: the same PIN that protects your locker or hotel safe often unlocks your phone, your laptop, and your bank card.
We discuss why reusing a PIN across devices is a terrible idea, how RFID credentials stored in locks can be used to open doors they were never meant to open, and whether vendors have actually fixed anything since we first told them about these issues.
If you've ever chosen the same PIN for your locker, your safe, and your phone - this talk is for you.
This talk is a continuation of our DEFCON 32 research on electronic locker locks. We discuss the general problem of how electronic locks handle user-chosen secrets, revisiting vulnerabilities in locks from multiple manufacturers. We focus on what these devices store: user PINs, RFID UIDs, manager credentials, and audit logs - often in plaintext and trivially extractable.