183
submitted 5 days ago* (last edited 5 days ago) by floofloof@lemmy.ca to c/cybersecurity@sh.itjust.works

https://archive.is/1NWAe

Omo and Rowley say they informed Securam about both their safe-opening techniques in spring of last year, but have until now kept their existence secret because of legal threats from the company. “We will refer this matter to our counsel for trade libel if you choose the route of public announcement or disclosure,” a Securam representative wrote to the two researchers ahead of last year's Defcon, where they first planned to present their research.

Only after obtaining pro bono legal representation from the Electronic Frontier Foundation's Coders’ Rights Project did the pair decide to follow through with their plan to speak about Securam's vulnerabilities at Defcon.

all 15 comments
sorted by: hot top controversial new old
[-] boatswain@infosec.pub 65 points 5 days ago

Gotta love the EFF. Just threw a bunch of cash to them.

[-] Tar_alcaran@sh.itjust.works 8 points 3 days ago

Funfact, safe makers: It's not libel if it's true.

[-] black_flag@lemmy.dbzer0.com 23 points 5 days ago

"Just pop the battery and you'll find a JTAG port where you can kindly ask for the manufacturer's master key" is fucking wild

[-] db0@lemmy.dbzer0.com 9 points 4 days ago* (last edited 4 days ago)

Oh but you need a password to do that. Unfortunately that password was something like 12345

[-] DemBoSain@midwest.social 38 points 5 days ago

If you're in the market for an electronic safe, here's a list of brands to skip:

Beyond Liberty Safe, Securam ProLogic locks are used by a wide variety of safe manufacturers including Fort Knox, High Noble, FireKing, Tracker, ProSteel, Rhino Metals, Sun Welding, Corporate Safe Specialists, and pharmacy safe companies Cennox and NarcSafe, according to Omo and Rowley’s research. The locks can also be found on safes used by CVS for storing narcotics and by multiple US restaurant chains for storing cash.

[-] fibojoly@sh.itjust.works 25 points 5 days ago

If I've learnt anything from the Lock Picking Lawyer : the fancier the supposed safety feature the easier it is to circumvent.
Every time he looks at a Web 3.0 piece of junk, it gets opened even faster than any of the physical locks. It's kinda terrifying, honestly.
Like, a magnet in the right spot and you're good to go, is what I'm saying.

[-] sturger@sh.itjust.works 13 points 5 days ago

Well, before I can read how to break into safes, I have to break into the website that says it won't show me the article without a subscription. That should keep those safes...er... safe.

[-] black_flag@lemmy.dbzer0.com 7 points 5 days ago

Firefox reader mode did it for me. Just block js on the page somehow.

[-] Whostosay@sh.itjust.works 6 points 5 days ago
[-] sturger@sh.itjust.works 4 points 5 days ago

Ha ha ha! Nope! Following that link, I have to click a captcha to prove I'm not a robot.

The layers of security theater are stacking higher and higher. What's next? They send me through TSA to make sure I'm not carrying a tube of toothpaste that is too big?!

[-] anyhow2503@lemmy.world 10 points 5 days ago

Sounds like someone is trying to get randomly selected for a cavity search.

[-] roguetrick@lemmy.world 11 points 5 days ago

The specialized equipment the safe maker says is needed is a Python script, lol.

[-] zqps@sh.itjust.works 4 points 4 days ago* (last edited 4 days ago)

Phew, how fortunate that people who try to crack safes never think to use readily available equipment. That would be a real challenge for those poor manufacturers.

this post was submitted on 09 Aug 2025
183 points (100.0% liked)

Cybersecurity

8050 readers
72 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS