How to open a safe
github.com
github.com
The vuln is in the back of the panel because it's accepting the reset code command. The front panel isn't vulnerable because it's not a trusted component here anyway, the bypass actually just talks directly to the back panel.
You are however correct that the front panel probably shouldn't be sending an actual reset code command, but that is really a protocol level problem not specifically a front panel issue. It's possible to make that safe by having the back panel first transition into appropriate state upon being primed with existing code or valid factory code before accepting the reset command but an even better fix is to couple both the validation of the existing code + the desired new code into a single command that is validated in one shot.
The vulnerability really is in the inside panel and changing the outside panel to just be a keypad wouldn't have prevented the mistake.
If someone has brought tools (portable angle grinder, hydraulic bolt cutters, or a prybar) sufficient to take out most locks, they'll take out most locks unless you upgrade A LOT. At which point they can usually use the same tools to defeat the hasp, and you're still compromised.
The SmartKey locks have two major flaws: a tiny endoscope camera can view the positions of the sliders and allow visual decoding of the correct position of each one independently (very specialized expensive equipment, about $350[2]), and it's possible to stick a shim in between the cylinder and body of some of the locks to tension the sidebar directly. Without a way to tension the sidebar it's extremely difficult to get any feedback.
[1] https://www.reddit.com/r/lockpicking/wiki/beltranking#wiki_r...
[2] https://www.lockpicks.com/catalog/product/view/_ignore_categ...
If you need high security, you are buying a product very different than a master lock, and you need to consider the integrity of the entire system it is connected to.
Low security locks work mainly by deterrent, and even if they were without vulnerability, the container you’re attaching it to probably is vulnerable. Brute force attacks are the much more common scenario against low security locks, and there’s not much of a low cost solution to that; it requires expensive materials: https://youtu.be/2guvwQvElA8
If you put an unpickable lock on sheet metal box, you’re spending more money, but not actually improving security.
The reason that master locks are popular is because they are fairly reliable, easy to get keys for, have useful feature sets, etc. These are the features that commercial users often care about the most. They don’t want to spend more money to get an unpickable lock that interrupts their daily business when it inevitably gets dirty, keys are lost, etc. especially if it provides no additional resistance against an angle grinder.
I think you misunderstand the threat model and/or use case. Most of the time I don't think anyone expects locks to do anything except keep honest people honest and dissuade the lowest level of opportunistic attacks.
A sledge hammer is cheap. It can open just about any door. The difference between a cheap door and hardware and a high end security door might be ~5 minutes of hammer time. (Nothing can stop hammer time). Nothing will stop someone with time and tools.
But if that threat model were a concern, we'd see a lot more bars on ground-level windows and the like. No one cares. Because 99.99% of the time, it's not going to be a problem.
Now, there are definitely use cases out there where it makes a big difference and people want the security. But MOST of the time, people aren't trying to stop or slow down someone with bolt cutters, a bump key, or shim.
A lock is (should be) tamper-evident.
All locks can (probably) be bypassed (eg: sledgehammer), but it’s best if it is visible that tampering has occurred.
For instance, if you have a shed with windows and a hasp on it, that it has a $10 master lock on it is the least of your security problems.
If you're storing $100m in gold bars in said shed, putting the $10 master lock on it is also probably the least negligent thing you're probably doing.
Edit: I mean here it looks like that ripping off the front-panel and powering the solenoid will get you into the safe.
https://www.youtube.com/watch?v=0SEHUqkbIjU
TL;DW Decision making should be on the secure side of the door, and communication should be encrypted.
An attacker who can intercept and replay the comms between the keypad and the controller, can probably also intercept and replay the signals from the physical buttons into the keypad's microchip. Or perhaps more likely, point a hidden camera at the keypad.
Sadly this is an issue of market demand rather than poor engineering. Good security costs more and this is priced into the safe/lock ecosystem - if you want real security buy a commercial safe with a Group 1 lock. Sadly though this leaves consumers at risk who don't understand this. They buy a safe from a brand they recognize and they think they are in good shape. Meanwhile I get shunned on forums by actual safe techs by encouraging muggles to do their own research and buy higher quality commercial safes 2nd hand for less money.
"No response". Understandable when you don't have any way to easily put it right, although I suppose they could have at least asked OP to keep it a secret until they could rectify it.
Turned out the hotel had no problem opening it at all.
The biggest security vulnerability in these “safes” is not the lock. It’s that a thief can simply pick it up and walk away with it.
These safes usually have a rating to be resistant to fire, but they usually lack any burglary-resistance ratings.
Burglary rated safes are expensive. They’re more expensive than the crap most homeowners want to put inside of their safe.
The second problem is the possibility to open the PINpad from the outside with the safe closed.
It seem to me that those two problems could easily be fixed by the manufacturer... and I can't understand that they just didn't do it right upfront
If someone cuts it open with a dremel, I'll notice as soon as I happen to see it.
So, depending on your perspective, they’re either really good, or entirely unusable.
A buddy of mine's dad dealt in wholesale jewelry and my friend inherited one of his dad's safes (I don't recall the brand offhand). It's over 5,000 pounds, has a tempered glass relocking plate in the door to defeat drills, etc. It is far beyond what almost any gun owner would go for. If something were to somehow fire the relockers, it would be an expensive proposition to get into the safe afterwards.
They’re more expensive than what 99% of homeowners put inside of their safes.
+ Motive
+ Opportunity
You want your thing to be very safe? Forget the safe, throw it in the ocean encased in a cement block. Very secure, will not be retrieved. Note - I said ocean, not a lake.
Biometric and pin pad locks are quick. Less secure sure but quick.
If an attacker has the triangle of means (tools, knowledge), motive and opportunity (physical access) then any lock can be defeated if only because you can torch through the lock.
Security is always a tradeoff. "More" secure is not always the correct tradeoff.
My friend Victor would disagree. Of course, finding the block would be much harder than going down in DSV Limiting Factor to get it.
Like you are just doing their job for them at that point.
Not that it would in any way excuse it.
A warrant and a circular saw will get you through really any consumer safe in seconds so I highly doubt they would go through all that risk to make it slightly easier to access but maybe there's concern of damaging evidence with forced entry or something.
The safe would've lost its purpose entirely if it was possible to open the lock without resetting the PIN. I'm sure there's a vulnerability in there that allows for that (after all, the microcontroller allows for opening the safe without entering the right code, a very basic mistake to make!) but this project doesn't entirely defeat the safe yet.
If someone cuts it open with a dremel, I'll notice as soon as I happen to see it.