Another thing I haven’t had a chance to blog before now:
Vaultek makes gun safes. Among their models is the VT20i, which has a fingerprint reader and Bluetooth. You can use Bluetooth and an app to unlock the safe.
And, yes, you already know where this is going, don’t you?
In this case, the responsible party is Two Six Labs. This is a pretty fascinating takedown.
High points:
- “The manufacturer’s Android application allows for unlimited pairing attempts with the safe. The pairing pin code is the same as the unlocking pin code. This allows for an attacker to identify the shared pincode by repeated brute force pairing attempts to the safe.”
- “There is no encryption between the Android phone app and the safe. The application transmits the safe’s pin code in clear text after successfully pairing.”
- “An attacker can remotely unlock any safe in this product line through specially formatted Bluetooth messages, even with no knowledge of the pin code…the safe does not verify the pin code, so an attacker can obtain authorization and unlock the safe using any arbitrary value as the pin code.”
Even if you aren’t into guns, or safes, or gun safes, I think this is a pretty good “how do I go about banging on a Bluetooth device” primer.
Somewhat to their credit, Vaultek says they are offering a patch, though it looks like you’ll have to send your safe back to get it. (Vaultek says they’ll cover shipping both ways, which can’t be cheap.)
Edited to add: something from Vaultek’s site on this issue:
Either of these methods are not easily captured and require several factors to execute including time, the right equipment, and close proximity to the safe.
They also refer to the attack as requiring “special equipment”. The “special equipment” is an Ubertooth, which you can get here and here, among other places.
As for proximity, that’s a good question that Two Six Labs didn’t address: with the right antenna and Bluetooth adapter, how far away can you be to make a successful attack? Does anyone remember the “Picking Bluetooth Low Energy Locks from a Quarter Mile Away” talk from DEFCON 24?
(Yes, door locks have to be accessible from the outside, while your gun safe is almost certainly inside. Modern construction almost certainly attenuates the signal some. But how much? Could I drive through the neighborhood with a Sena UD100 or something very much like it, just sniffing for Vaultek safes? And then come back later to attack them?)