GettyImages-584806542.jpg He was able to use another side-channel approach, though, a timing attack, to open the lock. Plore observed that as the system checked a user code input against its stored values there was a 28 microsecond delay in current consumption rise when a digit was correct. The more correct digits, the more delayed the rise was. This meant that Plore could efficiently figure out the safes keycode by monitoring current over time while trying one through 10 for each digit in the keycode, starting the inputs over with more and more correct digits as he pinpointed them. Plore did have to find a way around the safes penalty lockout feature that shuts everything down for 10 minutes after five incorrect input attempts, but ultimately he was able to get the whole attack down to 15 minutes, versus the 3.8 years it would take Skip Tracer to try every combination and brute force the lock. Burglars arent going to bother with this. Theyre going to use a crowbar or a hydraulic jack from your garage or if theyre really fancy theyll use a torch, Plore said. I think the more interesting thing here is [these attacks] have applicability to other systems. We see other systems that have these sorts of lockout mechanisms. Plore said that he has been trying to contact Sargent and Greenleaf about the vulnerabilities since February. WIRED reached out to the company for comment but hadnt heard back by publication time.

For the original version including any supplementary images or video, visit https://www.wired.com/2016/08/hacker-unlocks-high-security-electronic-safes-without-trace/