Remotely Cracking Smart Gun Safes: Verifying Secure Bluetooth Low Energy Implementations

No ratings

Presented at CODEBLUE2018@TOKYO 2018 by

In this talk we will detail the discovery and exploitation of multiple security vulnerabilities in the Vaultek VT20i smart gun safe. These vulnerabilities allowed us to leak the safe's PIN code, and create a generic application to remotely open any of these safes without the PIN code. The VT20i is a very popular product designed for the safe storage of firearms and is one of Amazon’s top sellers in several categories. These vulnerabilities are present due to the Bluetooth smart functionality added to the safe and the corresponding Android application. Along with detailing the technical approach and workflow to finding and exploiting these sorts of Bluetooth implementation bugs in smart devices, we will use these vulnerabilities to highlight how product manufacturers and distributors can verify and protect the security of their own devices and applications, and demonstrate the need to include security audits early in the product manufacturing process.