BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidesfrankfurt.org//call-for-paper-presentations-20
 26//speaker//PHF9EW
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-call-for-paper-presentations-2026-3WDFBK@cfp.bsidesfrankfurt.or
 g
DTSTART;TZID=CET:20260910T162000
DTEND;TZID=CET:20260910T164500
DESCRIPTION:Smart locks are rapidly replacing physical keys\, but trusting 
 your front door to an IoT device still comes with significant risks. In th
 is talk\, we will dissect the highly rated SwitchBot Lock Pro and demonstr
 ate how a classic cryptographic implementation flaw allowed anyone to sile
 ntly unlock the door without an physical tampering. By reverse-engineering
  the firmware and analyzing the custom Bluetooth Low Energy (BLE) protocol
  between the outdoor keypad and the indoor actuator\, we discovered the sy
 stem relies on AES in Counter (CTR) mode with zero integrity checks. We wi
 ll demonstrate how we exploited this to create a universal\, software-only
  UNLOCK payload. Join us as we showcase the live exploit\, break down the 
 vendor's flawed patch\, explain how backward compatibility significantly d
 elayed the patch\, and celebrate our massive 100€ bug bounty.
DTSTAMP:20260923T103626Z
LOCATION:Großer Saal
SUMMARY:Keyless Entry: Hacking SwitchBot Smartlocks - Kolja Grassmann
URL:https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/
 3WDFBK/
END:VEVENT
END:VCALENDAR
