Hacker Unlocks ‘High Security’ Electronic Safes Without a Trace
wired.com
wired.com
I find it easy to believe there are additional unlock codes for use by locksmiths, law enforcement and so forth.
I'm not buying another electronic lock any time soon.
"Unlock" is the key verb here, and any good safe should have that property to as great an extent as possible within its economic target. There is a critical distinction to make between the ability to "unlock" something and the mere ability to "gain access" it. While both ultimately yield up whatever is being protected, part of the core concept of "unlocking" is that it's non-destructive and trivially reversible, and thus to some extent provides some of the services of checksumming to the real world. It's not merely about preventing unauthorized access, but knowing about unauthorized access that couldn't be prevented. Any decent locksmith should be able to access any standard safe (that's their whole job) without any keys, but for a good safe that should require physical bypass (such as drilling, mechanical or energetic application, etc) to be involved, which will leave marks. In a legitimate scenario that's fine, because legitimate scenarios (including the government getting a warrant in an investigation) are not covert. As always in security an adversary with access to and willingness to use sufficient resources may be able to figure something out, but to point is to make that a bar sufficient to whatever level that situation needs.
If an electronic lock makes it trivial though to not merely gain access, but for non-owners to "unlock it", ie., to access with a speed and transparency equivalent to that of a legitimate operator, then that is actually a different and more concerning threat profile no matter what the case. As another example, it's certainly hardly an unknown threat that somebody could trivially smash the windows on a typical car to gain access to the interior. But that doesn't mean someone shouldn't be concerned if a newer car with an electronic lock can be trivially made to unlock in a way that's indistinguishable from the owner. There is a risk/reward economic difference that in turn changes the security threat profile.
Buying Security: https://www.youtube.com/watch?v=u_7GLxmyaXM
Choosing a high Security Lock: https://www.youtube.com/watch?v=nsJZ_kKjXcE
(Be ware of about 2 minutes 30 seconds of sarcasm in the last one!)
Otherwise, browse through the rest of his videos, skipping the challenge locks unless it's something that fascinates you: https://www.youtube.com/user/bosnianbill/videos
Essentially, cheap locks can be bypassed very easily (almost anything by Masterlock). More expensive locks ($60+) will have more pins, making them harder to pick, and often have replaceable cores. Of course, security isn't just about the lock, which is addressed in the first video.
Hope this gives you a starting point!
It really is a clever attack!
I'm really surprised at the way he mentions the microcontroller tests if the key is correct or not, by simply looping through and breaking on an incorrect number.
The problem, of course, is that in the security realm, coding to break the loop as soon as the answer is known wrong is what provides these types of side channel attacks. But since 99.9% of programmers also do not write code for these environments when tasked to do so they just do what they are used to doing everywhere else (break early, when you know you are done with the checks) without realizing they are leaving an unlocked backdoor as a result.
https://codahale.com/a-lesson-in-timing-attacks/
tl;dr, the method for doing "secure" string comparison was vulnerable to timing attacks for much of Java's history.
if hashing_function(unknown_pass) == hashed_pass:
you're doing it wrong...Instead, use the compare function built into your crypto library, which should hopefully be hardened against timing attacks.
In most languages, == and === are not safe against timing attacks.
It's telling that even the very smart person who did such a great write-up made a few mistakes again in initial attempts at demonstrating a corrected algorithm that actually blew the whole thing up again.
Because it's so subtle, the odds are very good that most current systems are fallible to this.
By contrast, if you were comparing my submitted password to a stored password, I could use your response time to know that I got the first n characters right. Since n is a prefix of the password, I've learned something about the password, I can lock down those characters, and then guess more, etc. That much I understand.
But the case you're talking about is a comparison of hashes. In that case, timing attacks can tell me that my guess's hash's first n characters match the password's hash's first n characters. So now what? How do I adapt future guesses to learn more characters? What have I learned about (a preimage of the hash of) the password?
If partial hash collisions were, in any way, helpful in guessing the full collision, Bitcoin mining algorithms would adaptively change their guesses as they discovered that their nonces only led to a partial match.
1. https://security.stackexchange.com/questions/111040/should-i...
The batteries may die, which means there must be a physical lock as well. Either the physical lock is less secure than the electronic lock (in which case an attacker will focus on the physical lock) or it is more secure than the electronic lock (in which case why not rely on the physical lock?).
That doesn't even begin to get into the fact that the profession of electronic locksmithing is still in its infancy and as a result electronic locks tend to be laughably insecure in the first place. The whole reason to have a safe is to keep things … safe. Why pay all that money and get nothing in return?
[1] http://www.yale.co.uk/en/yale/couk/productsdb/smart-locks/Ke...
So there is no mechanical lock fallback. The fact that you can remove the batteries (and even the number pad) without unlocking the safe does seem to present some DoS attacks, but I assume that isn't a major concern.
[1] http://www.sargentandgreenleaf.com/pdf/630-302_6120_op.pdf
This vuln was found in Sargent & Greenleaf locks. These are UL-listed locks suitable for securing cash in commercial establishments. They have no key bypass.
These locks have the batteries outside the safe, so there is no dead battery issue. However, this enables easy current measurements, as the hacker showed.
FYI, at this level there are no "electronic safes" - just regular safes with electronic locks, which have the same form factor as mechanical safe locks.
Why an electronic lock? Much faster to enter the combo, proof against robo-dialers, can maintain an audit trail of multiple employees, can issue different combinations to different employees and revoke access.
Wouldn't a simple capacitor foil that attack?
Why not just have an A/C port somewhere so you can supply your own power if the battery dies? The worst a criminal could do at that point is try to crank a high amperage current through it and try to fry the computer, which would not unlock it.
I generally see a battery compartment on the exterior, so if the batteries die you just replace them and then enter the code. Sometimes the key lock does something like immobilize the dial or handle, so it's a second factor, not a bypass.
>Why pay all that money and get nothing in return?
On consumer-level safes, who knows. Beyond that: individually identify users, revoke specific users, have an audit trail of who opened it when, make the ACLs depend on time of day.
Clearly, that standard is a little ridiculous.
Electronic locksmithing is not in it's infancy. The FF-L-2740B specification is already a 5 year old.
1. Every mechanical lock can be opened using a tool called ITL2000. It is a robotic arm that tests all the combos of the mechanical lock.
2. The maintenance of codes in a bank using mechanical locks is very complicated and costly. When the person in a branch who knows the combo takes holidays a locksmith has to go to the branch to change the combination, for example. In an electronic lock (SG-6121) there are the master code and 9 codes, one of them opens the lock without waiting for the delay.
Like other commenters here I'm wary of using an electronic lock because I'm not able to inspect the code for backdoors. I wonder if there's enough of a hacker market to warrant creating a crowdsourced electronic safe (or retrofit of the electronics of an existing electronic safe).
Also, slides show a 1/4" hole, and then the lock and an EEPROM; could it be feasible to melt plastic enough through this hole that one could then expose and flash the EEPROM with UV, resetting it?