Tuesday, May 13, 2025
Germany Latest News
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe
No Result
View All Result
Germany Latest News

Top-selling handgun safe can be remotely opened in seconds—no PIN needed

by The Editor
December 10, 2017
in Tech
0
Top-selling handgun safe can be remotely opened in seconds—no PIN needed
EnlargeTwo Sixes Labs

One of Amazon's top-selling electronic gun safes contains a critical vulnerability that allows it to be opened by virtually anyone, even when they don't know the password.

The Vaultek VT20i handgun safe, ranked fourth in Amazon's gun safes and cabinets category, allows owners to electronically open the door using a Bluetooth-enabled smartphone app. The remote unlock feature is supposed to work only when someone knows the four- to eight-digit personal identification number used to lock the device. But it turns out that this PIN safeguard can be bypassed using a standard computer and a small amount of programming know-how.

As the video demonstration below shows, researchers with security firm Two Six Labs were able to open a VT20i safe in a matter of seconds by using their MacBook Pro to send specially designed Bluetooth data while it was in range. The feat required no knowledge of the unlock PIN or any advanced scanning of the vulnerable safe. The hack works reliably even when the PIN is changed. All that's required to make it work is that the safe have Bluetooth connectivity turned on.

BlueSteal Vaultek Unlock Demo

Vaultek holds out the VT20i as a reliable way to keep guns and other valuables safely secured and out of the wrong hands. With more than 250 customer reviews on Amazon, it boasts an overall rating of 4.5 stars out of a possible five stars. Marketers also say the safe is compliant with Transportation Security Administration rules required for people to fly with guns carried in checked luggage.

In an e-mail, Vaultek officials said the attack demonstrated in the video would be hard to execute.

"What you are not seeing is the prep time required to isolate the correct code and the time required to study the safe and it's transmissions, and the subsequent decoding time needed to generate the final code," company officials wrote. "This can take hours of work and also requires the ability to observe a correctly paired phone."

Not so fast

Two Six Labs researchers, however, disputed the claim and said the Vaultek statement fundamentally mischaracterizes their exploit.

"Once you have developed this capability or written a script to do it, you can affect any safe in this product line in a matter of seconds," Austin Fletcher, Two Sixes Labs' lead vulnerability research engineer, told Ars. "Anyone can do this."

In a blog post disclosing the vulnerability, the researchers included most of the code required to exploit the vulnerability. A competent developer would need 20 to 60 minutes to supply the missing portion. With that, the developer could build a smartphone app that could silently break into any existing VT20i safe in seconds, as long as Bluetooth was turned on.

Vaultek officials said they are in the process of introducing changes to their safes after receiving a private report two months ago about Two Six Labs' findings. "Vaultek takes personal security very seriously and we constantly monitor our products and will make every effort to continually improve," Vaultek officials wrote.

Daniel Su, Two Six Labs' research engineer, told Ars he doesn't believe the bug can be fixed in existing safes. That assessment, he said, is based on the fact that the flaw resides in the firmware that runs on the safe. "We have not seen any evidence of there being a firmware update mechanism," he said. E-mails from Vaultek left Ars' questions about the lack of an update mechanism unanswered.

Two Six Labs also reported two other vulnerabilities in the popular safe. One, stemming from a lack of encryption in the Bluetooth communications, allows attackers within range to obtain the unlock PIN.

A second weakness allows anyone to make an unlimited number of attempts to pair a Bluetooth device with the safe. The safe design allows PINs that are four to eight digits long, but it only accepts digits 1 through 5. That means there are a maximum of 390,625 combinations (that is, 58). The number of combinations will be considerably smaller number if owners use a PIN shorter than eight digits.

The vulnerability means that anyone who relies on a VT20i safe to secure valuables should immediately turn off Bluetooth connectivity and leave it off indefinitely. Safes can still be locked and unlocked using a traditional physical key, as well as by owners' fingerprints. Some Amazon customers, however, have complained the fingerprint feature is flawed as well.

Original Article

Ars Technica

The post Top-selling handgun safe can be remotely opened in seconds—no PIN needed appeared first on News Wire Now.

Related posts

What Are the Pros and Cons of Sperm Freezing Technology?

What Are the Pros and Cons of Sperm Freezing Technology?

September 8, 2023
How Tech Partnerships Can Keep the E-Commerce Boom Going?

How Tech Partnerships Can Keep the E-Commerce Boom Going?

September 8, 2023
EnlargeTwo Sixes Labs

One of Amazon's top-selling electronic gun safes contains a critical vulnerability that allows it to be opened by virtually anyone, even when they don't know the password.

The Vaultek VT20i handgun safe, ranked fourth in Amazon's gun safes and cabinets category, allows owners to electronically open the door using a Bluetooth-enabled smartphone app. The remote unlock feature is supposed to work only when someone knows the four- to eight-digit personal identification number used to lock the device. But it turns out that this PIN safeguard can be bypassed using a standard computer and a small amount of programming know-how.

As the video demonstration below shows, researchers with security firm Two Six Labs were able to open a VT20i safe in a matter of seconds by using their MacBook Pro to send specially designed Bluetooth data while it was in range. The feat required no knowledge of the unlock PIN or any advanced scanning of the vulnerable safe. The hack works reliably even when the PIN is changed. All that's required to make it work is that the safe have Bluetooth connectivity turned on.

BlueSteal Vaultek Unlock Demo

Vaultek holds out the VT20i as a reliable way to keep guns and other valuables safely secured and out of the wrong hands. With more than 250 customer reviews on Amazon, it boasts an overall rating of 4.5 stars out of a possible five stars. Marketers also say the safe is compliant with Transportation Security Administration rules required for people to fly with guns carried in checked luggage.

In an e-mail, Vaultek officials said the attack demonstrated in the video would be hard to execute.

"What you are not seeing is the prep time required to isolate the correct code and the time required to study the safe and it's transmissions, and the subsequent decoding time needed to generate the final code," company officials wrote. "This can take hours of work and also requires the ability to observe a correctly paired phone."

Not so fast

Two Six Labs researchers, however, disputed the claim and said the Vaultek statement fundamentally mischaracterizes their exploit.

"Once you have developed this capability or written a script to do it, you can affect any safe in this product line in a matter of seconds," Austin Fletcher, Two Sixes Labs' lead vulnerability research engineer, told Ars. "Anyone can do this."

In a blog post disclosing the vulnerability, the researchers included most of the code required to exploit the vulnerability. A competent developer would need 20 to 60 minutes to supply the missing portion. With that, the developer could build a smartphone app that could silently break into any existing VT20i safe in seconds, as long as Bluetooth was turned on.

Vaultek officials said they are in the process of introducing changes to their safes after receiving a private report two months ago about Two Six Labs' findings. "Vaultek takes personal security very seriously and we constantly monitor our products and will make every effort to continually improve," Vaultek officials wrote.

Daniel Su, Two Six Labs' research engineer, told Ars he doesn't believe the bug can be fixed in existing safes. That assessment, he said, is based on the fact that the flaw resides in the firmware that runs on the safe. "We have not seen any evidence of there being a firmware update mechanism," he said. E-mails from Vaultek left Ars' questions about the lack of an update mechanism unanswered.

Two Six Labs also reported two other vulnerabilities in the popular safe. One, stemming from a lack of encryption in the Bluetooth communications, allows attackers within range to obtain the unlock PIN.

A second weakness allows anyone to make an unlimited number of attempts to pair a Bluetooth device with the safe. The safe design allows PINs that are four to eight digits long, but it only accepts digits 1 through 5. That means there are a maximum of 390,625 combinations (that is, 58). The number of combinations will be considerably smaller number if owners use a PIN shorter than eight digits.

The vulnerability means that anyone who relies on a VT20i safe to secure valuables should immediately turn off Bluetooth connectivity and leave it off indefinitely. Safes can still be locked and unlocked using a traditional physical key, as well as by owners' fingerprints. Some Amazon customers, however, have complained the fingerprint feature is flawed as well.

Original Article

Ars Technica

The post Top-selling handgun safe can be remotely opened in seconds—no PIN needed appeared first on News Wire Now.

Previous Post

Ajit Pai jokes with Verizon exec about him being a “puppet” FCC chair

Next Post

Revealed: Winners of the ‘Oscars of watches’

Next Post
Revealed: Winners of the ‘Oscars of watches’

Revealed: Winners of the 'Oscars of watches'

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Fake mobsters tried to extort $198K from landlord

Fake mobsters tried to extort $198K from landlord

6 years ago
Sudan protests: President ‘completely satisfied’ with police despite brutality claims

Sudan protests: President ‘completely satisfied’ with police despite brutality claims

6 years ago
No. 16 Wisconsin overwhelms Savannah State 101-60

No. 16 Wisconsin overwhelms Savannah State 101-60

6 years ago
National Enquirer Parent Company Settled With Feds Over Payment To Alleged Trump Mistress

National Enquirer Parent Company Settled With Feds Over Payment To Alleged Trump Mistress

6 years ago

FOLLOW US

  • 139 Followers
  • 87.2k Followers
  • 202k Subscribers

BROWSE BY CATEGORIES

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

BROWSE BY TOPICS

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
No Result
View All Result

Recent Posts

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities
  • What is a Mail Order Wife?
  • What to Discuss on a First Date?

Categories

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Tags

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
Federal Government focuses on “integrated security”
latest news

Federal Government focuses on “integrated security”

by The Editor
June 14, 2023
0

Berlin (dpa) – The Federal Government is responding to the challenges of an increasingly unstable world order by means of a “policy...

Read more

Recent News

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities

Category

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Recent News

OnlyFans Platform Analysis

June 12, 2024

How to Day German Fashion

May 5, 2024
  • About
  • Advertise
  • Careers
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.