The Sectors Were Open: Finding a Hole While Closing One
I ended the last post like this: "Those 1,900 devices are in another city; next week we'll go there and update them on site."
We went last week. We updated 1,880 devices in three days. And on the way back I had something with me I hadn't expected: someone else's security hole.
The room number in ballpoint
We stayed at an institution's guesthouse in the city. While we were checking in, I noticed the receptionist creating a new card for us on the reader on their desk — I recognised the device, I work with one like it.
As we took our cards and headed for the rooms, we noticed a room number written in ballpoint on my colleague's card. It wasn't the room he'd been given. The receptionist saw us glance at each other and said, "don't mind that number, your rooms are different." We didn't mind it.
It occurred to me afterwards: if you drop that card, whoever finds it also learns which door it opens. A guest had probably written it for their own convenience. I didn't dwell on it at the time either — my head was already on the next day. Back then I thought it was the least important part of the story.
There was something I liked at the door of the room: the lock was a smart lock from a well-known, good brand. I badged in, went inside, and fell asleep thinking about the devices I'd be updating in the morning.
The day we didn't look at the paper
In the morning we went to the city's water and sewerage authority. After a short chat with the department head who'd be handling us, they assigned one of their staff to us. They also handed us a small piece of paper: the names of the construction firms and the number of devices at each, written by hand.
We didn't look at the paper. We wanted to start and finish as fast as possible.
Here's what was lucky for us: none of the devices had been installed in homes yet. All 2,900 were still in cartons, waiting either in the construction firms' storage or in the authority's warehouse. We weren't going to be going door to door.
At the first site they set aside an office for us. While I was setting up, the firm's people brought in the first carton. I took a device out of it and turned on its Bluetooth.
The device was on the current version.
All three of us were delighted; in our heads half the job was already done. To be safe we opened the other cartons too and tested one device from each — all current. Then we looked at the paper. There were 1,026 devices at this site, and the total at the bottom of the page was 2,900-odd.
Those 1,026 devices were the ones I wrote about in the last post. The ones I'd updated over FUOTA at the office without breaking their seals. That day I hadn't opened a single one of their boxes; now the same devices were out of the carton and in my hand, and I was looking at my own work. It was a strange feeling.
But that's where the joy ended. 1,026 of the total were already done, and the remaining 1,880 were exactly the batch we had come to update. The job hadn't shrunk by half; it was what it had always been. There was no bad news — there just wasn't any good news either.
680 and 1,200
We moved on to the second firm's site. The first job, again, was to open one of the cartons and run a version test.
This batch was not current.
Three of us, from midday until evening, finished the 680 devices there.
The next day we went to the authority's warehouse; the remaining 1,200 devices were there. They gave us an office again and brought the cartons right to us. That day we updated 750 devices and then stopped — we wanted to see the city too, and we spent the evening walking around. We finished the remaining 450 before noon on the last day.
The best part of the job wasn't at a desk
While we were working at the second site someone from the firm came by, introduced to us as one of their IT people. I learned later that he was actually there temporarily, helping out his relatives' company. I can't give his name because I didn't ask his permission, but he was both very engaged and genuinely knowledgeable on the software side.
While I updated devices I told him about our modules and the platform our company builds. He told me about the ERP system he had written himself for the construction industry. When the work was done he wanted to show me; we went over to his office. Honestly, I hadn't thought an ERP could be that tidy and that fast.
Something similar happened at the warehouse. The conversations with the authority's staff showed me how hard the field really is, and out of those same conversations I took notes on how I could improve the device. This happens to me on every field trip: the person who knows your product best is the one who picks it up every day.
The sectors were open
On the last day we were checking out of the guesthouse. While I waited for my teammates to come down from their rooms, room card in hand, that lock came back to mind.
What did this company use for cards, I wonder?
I got my phone out, opened NFC Tools and tapped the card: MIFARE Classic 1k. The same card I use all the time.
Then, out of habit, I tried to read the sectors. On this card every sector is locked with a key, and the card leaves the factory with a default key everyone knows; whoever commissions the system is supposed to wipe that key during installation and write their own. In my own work I don't skip that step. So I already knew how it would go: the app wouldn't get the key, it would throw an error and give up.
I opened the read page and held the card up to the phone.
Every sector was sitting there in front of me.
I couldn't believe it and tried again. Same result.
Because NFC Tools is not a cracking tool. It doesn't break ciphers, it doesn't do cryptography; it tries the known default keys one after another, and that's it. If one works, it means exactly one thing: the keys on that card had never been changed. The card was sitting there exactly as it left the factory.
Don't get me wrong, I don't want to overstate this: what I saw was that I could read that card. I didn't try to open anyone else's door, and I didn't want to. But in this situation there is no serious barrier between reading and writing; if the key is still the default, the sector is open to writing too.
So there is no cipher that got broken here. There is a door that was never locked. The difference matters: the first takes an attack, knowledge, equipment, time. For the second, having a phone in your hand is enough.
What really bothered me wasn't my own room. A lot of public servants were staying at that guesthouse, some of them from law enforcement. Once you start thinking about what is behind those doors, this stops being about someone going through a suitcase very quickly.
In the lobby
I closed the app. I didn't save a single line of what it had read; the first thing that came to mind was "leave this here".
Then I left my suitcase in the lobby and went to reception.
I explained it. He had understood that I'd tapped the card with my phone, but what that meant hadn't landed. I held out the phone, tapped the card again, and turned the screen towards him. His expression changed. He said he would tell his superiors.
While I waited for my teammates to come down, I sat in the lobby and wrote the first lines of the email I would send to the lock company. Then we checked out and went to the warehouse, finished the remaining devices before noon, counted the cartons and handed them over. In the evening we walked around a bit again. On the drive back to Ankara the only thing the team talked about was new projects.
But that email stayed on my mind. I still don't know exactly where the fault lies — the team that did the installation may have skipped that step, or the system may not force you to change the default key. Both come out at the same door: tell the manufacturer. The email has gone, and there's no reply yet. Then again, not much time has passed.
I'm not writing the company's name or the city here either. That door is still that door.
What I took away
For three days we picked up 1,880 devices one by one to close a hole in our own product. And every night I slept in a room whose door I opened with a card.
Security is more often a process problem than a technology problem. The lock can be solid, the card can be trustworthy, the software can be flawless. But if a default setting is left forgotten at any link in the chain, the whole system stays only as secure as that link.
It's no different in our own work. On one side we're working hard to update devices without opening the box; on the other, a single field left unfilled during installation can make the entire security model meaningless.
But the thing that stayed with me from this story isn't the vulnerability.
Nobody asked me to look at that card. I was just curious. That is what I had been doing for three days anyway: opening a carton to check a version, wanting to see how an ERP was written, asking the person in the warehouse how the device behaves in the field. All of them are different shapes of the same reflex.
For me, R&D means genuinely trying to understand how the thing in your hand works, before it means building something new.
Sometimes you find out a device's firmware version.
Sometimes you find out the door is open.