
DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 41:54
The video reveals that many high-security electronic safes use insecure design practices, such as storing unlock codes externally and in plaintext, making them vulnerable to exploitation by attackers with physical access. A key finding is that the Liberty Safe incident—where a code was handed over to the FBI—was not due to a backdoor, but because of a management practice where the manufacturer keeps a record of the manager code linked to the safe’s serial number. This practice, though well-intentioned, creates a security risk if exposed. The video demonstrates that the codes are stored in the keypad outside the safe and can be extracted via reverse engineering using specialized tools, such as a glitch-based exploit targeting the Prologic L02 lock. This exploit, called "code snatch," works by reading firmware from the lock’s debug port and decrypting the stored codes using a known 128-bit encryption protocol (XXTEA). The recovery mode, which allows resetting codes via a locksmith, is also vulnerable because it relies on a predictable, non-secret algorithm in the firmware, with no hardware security. The video emphasizes that these vulnerabilities persist in widely deployed locks, including those used in pharmaceutical and cash drop safes, and that manufacturers like Secure RAM have not issued meaningful mitigations despite being aware of the flaws. The main threat is real and actionable—organized crime and nation-state actors could exploit these weaknesses with minimal effort. The root cause is poor threat modeling and a failure to apply modern security standards to physical devices. The video concludes that the industry needs stronger, up-to-date security frameworks, including independent testing, cryptographic evaluation, and mandatory threat modeling, to ensure physical security products are truly secure.
[Key Takeaways:
• The Liberty Safe incident stems from a management practice, not a backdoor 1:19-1:26.
• Unlock codes are stored externally
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Mark and James are here to amaze you with their safe cracking skills with cash drums and drugs and guns. >> Oh, welcome everybody to our talk cash drugs and guns. Why your safes aren't safe. So, we're start off here with a little introduction. So, my name is Mark. I lead an awesome engineering team. We build embedded products. We secure embedded products. We usually work on stuff where our hack our attackers have physical access. So I have a background in highly regulated design, industrial, aerospace, military, IoT, that kind of stuff. And I'm James. I work with Mark, although this work is not part of our professional work. I do a lot of the same stuff. um product design, sometimes cyber security design, sometimes cyber security analysis and reverse engineering, which is what I find reall…