I'm expecting a talk at the next DefCon where they dump the firmware on Liberty's electronic locks...
@taiiat0 Жыл бұрын
at Defcon? nah if there's something at Defcon it'd more likely be "how to bypass every Electronic Lock that exists" than just one specific Model or Series 🤣
@ebouwman034 Жыл бұрын
So a 5 minute talk.
@judgemoses9015 Жыл бұрын
me when I expect something
@williamp6800 Жыл бұрын
I’m waiting for someone to play Doom on one.
@cland2225 Жыл бұрын
Liberty does make a nice steel box. Assuming their prices nosedive in the future, a Liberty safe and new mechanical lock could be a good deal...
@zxggwrt Жыл бұрын
Yeah seriously that’s all they’re supposed to be. If some boomer doesn’t want his I’ll take it!
@Tunkkis Жыл бұрын
Perhaps on the used market, to not give them any more money.
@mrbyamile6973 Жыл бұрын
@@Tunkkison the used market with no bill of sale, cash only. Don't need anyone tracking down the previous owner and information. I still wonder what the safe company I bought my mechanical locked safe from did with the codes we had them program into my safe. I had to order the safe and had a confidential piece of paper with the code we wanted programmed. Is that paper sitting in a crappy file cabinet with my name and address?
@ictpilot Жыл бұрын
Why a just a boomer?
@mrbyamile6973 Жыл бұрын
@@ictpilot I wondered why he targeted Boomers also, I think its possible that Boomers and Gen X (myself a gen-x however I've been called a boomer despite that being my parents generation) are more concerned about privacy. The younger generations grew up with smart phones and lack of privacy and have become accustomed to being tracked digitally between phones, electronic transactions, and all the social media self administered tracking such as posting pictures of the food they are eating at what restaurant.
@jessthemullet Жыл бұрын
A friend of mine passed away earlier this year, and he had a Liberty safe. His was a mechanical version. At the time, we didn't know where the combination was, and we were still trying to find a copy of his will, Estate Documents, etc. We called Liberty, and they wouldn't tell us a damn thing without notarized statements from law enforcement to prove the giant heavy safe wasn't stolen. Plan B was call someone from SAVTA, and with the paperwork we had, prove it wasn't stolen, and have them call as a licensed professional to get us in. Even then, there was some vetting required because they were reasonable professionals who took it seriously. I honestly expected that level of vetting and honest security from them, on multiple levels. That factory is here in Utah, and I know people who've worked there. I had respect for this company before this. Had.
@LordSStorm Жыл бұрын
You just said that they required LE validation then you attack them for having LE validation. Its insane that with all the data that EVERYONE provides LE, that somehow people are shocked that safe MFRs would provide the data to LE.
@FasutonemuMyoji Жыл бұрын
Three letter agency called and told them 'Trust me Bro', that's not LE validation. They might have even had the correct paperwork but it wasn't even asked for. That's why ppl are mad. Nobody expects them to hang up and not help LE. They just want them not to need a gallon of Listerine to wash the boot taste out of their mouths.
@entropy11 Жыл бұрын
Given the statement that Liberty just released on twitter, seems likely they handed out a manufacturer reset code, and they know they screwed up by handing out anything without a court order. This is going to hurt them, and they earned it. You can't be a safe company if you've lost the trust of your customers.
@requited2568 Жыл бұрын
Even companies and corporations will not be happy with them for not requiring a court order.
@marcogenovesi8570 Жыл бұрын
lol so they handed a code they shouldn't even have had, and did so without court order? ooooh this is not going to be good for their future sales I don't think
@EraYaN Жыл бұрын
@@marcogenovesi8570no they have those codes by design, since dummies forget safe codes on the regular. It’s essentially part of customer service.
@FuzzBangbuster Жыл бұрын
They claim the feds had a warrant in their post. Doesn't matter, they should not have divulged that info, period.
@Combat_Pyro Жыл бұрын
I am in the market for a safe and literally was going to buy a liberty. Now I'm not so sure. Whatever I buy will be mechanical and I will pay a guy to come change the combination. One thing I know is that Liberty needs to pay a price for this breech of consumer trust.
@xmarkxcx Жыл бұрын
These companies should be putting themselves in a position where if the government come knocking they don't have anything to provide.
@Scotty_in_Ohio Жыл бұрын
That would go for customers then too (i.e. next of kin for the deceased owner, etc.) which has been Liberty's position (to keep record of the combo based on the safe's serial number for when an owner forgets or the family has proper ownership of it) - they (Liberty Safe) is trying to change that into an opt-out approach but I tend not to believe them. the response should always be - sorry we can't help - call a locksmith or buy a $29 Harbor Freight angle grinder to see what's inside that safe...
@i-love-comountains3850 Жыл бұрын
@@Scotty_in_Ohio it's worth noting that the floors of safes are quite often the least protected. cutting hinges typically doesn't work, and cutting the door typically triggers other permanent lockouts. door attacks on safes are typically futile (excepting electronic locks, obv), go figure, and the heat required to torch through would likely destroy the contents, or far worse if a gun/ammo safe😅😅 an old foreman of mine knocked over his gun safe trying to move it alone with pulleys and prybars, triggering the deadlock. when I showed up to work that day (his basement remodel) I asked what he's gonna do and after a glass of scotch and a cigar we settled on a wet cut concrete saw against the bottom. worked like a charm😆
@ictpilot Жыл бұрын
A lot of thefts have occurred with diamond tip cutting wheels on the top of the safe.
@Combat_Pyro Жыл бұрын
Im with you on this. If a safe guy can get in anyway, so be it, I'll leave a few hundred bucks in my harbor freight safe for my wife and kids to use to pay the safe guy, lmao
@seeharvester5 ай бұрын
@@i-love-comountains3850 Bingo. I just happen to have one of those myself. No safe is 'safe'. 14" Stihl gas saw, diamond blades and metal blades.
@johnp214 Жыл бұрын
As a locksmith. If you don't want unwanted entry in your safe the easy way you remove the serial numbers on the safe and keypad. Or if it is a dial lock just have a locksmith change the combo to a custom combination. Although if they want in bad enough they will get in so buy good quality and make them work hard for it.
@SaberusTerras Жыл бұрын
If they arrested him under a warrant, and secured the house under a warrant, they could have taken their time to get a warrant for the safe code after the fact. Feels like the only reason to get the code ahead of time was for the PR stunt of walking out with all his guns.
@requited2568 Жыл бұрын
@@sumduma55social engineering at it's finest, it is just always surprising who falls for it.
@feeish Жыл бұрын
The warrant likely already had a clause granting access to the safe; They wouldn't need a second warrant unless they felt they wanted to ensure they covered their end of the investigation and prevent a fruit of the poisonous tree issue.. Give how the feds like to come down hard and cause as much cost for the investigatee I'm shocked they even used a backdoor and didn't just drill it open and ruin the safe any way.
@GunFunZS Жыл бұрын
There's another PR stunt which is to say "your little laws do nothing to protect you. we do what we wan😊t." In a loud Darth Vader voice.
@kstricl Жыл бұрын
@@feeish The big issue though, is they did not receive a copy of the warrant before providing the information. Had they been sent a copy of the warrant (through their lawyer) and acted accordingly, this video would not have been made. Only exception they should make, for everyones' sake, is if there were a person physically trapped (i.e. kidnapping situation, toddler trapped, etc.) or the registered owner gives written permission.
@Matt-xc6sp Жыл бұрын
@@sumduma55yeah they were invited to the capitol by the dude who lost an election and didn’t want to give up power.
@p.t.anderson1593 Жыл бұрын
I have a suspicion that Liberty Safe company, due to their back door policy, is about to take it in the back door...
@bmitch3020 Жыл бұрын
My cheap Sentry fire safe has an unchangeable master code. That's the code you get when contacting Sentry with the serial number. Given the safe can be easily opened with a timed bounce on a bed, strong magnet, circular saw, drill, etc. it seems pointless to try to add extra security.
@marcogenovesi8570 Жыл бұрын
it's in a different price class than the liberty safe in the story
@bmitch3020 Жыл бұрын
@@marcogenovesi8570 definitely a different class. This was more a comment that Sentry users didn't change their codes from the default, where they just don't have that option without replacing the lock.
@DrunkguyFawkes4 Жыл бұрын
@DeviantOllam OPTION 2, I have bought a second hand Liberty safe, there are 2 codes. 1 is the owners and 1 is a master code. When I bought the safe I wasn't given the owners and had to request it from Liberty safe. I needed a noterized reciept and the serial number, cost me $25. They sent me their master combo to my lock (if their Tech needs to get in or the owner no longer has the code i.e. forgotten, owner died etc)
@happyundertaker6255 Жыл бұрын
Thank you for this.
@RobertMorgan Жыл бұрын
As a notary, forging a notarized document is a felony in all 50 states, it's perjury. THAT SAID, it's not like there's an easy way to check on someone's notary commission, without calling the local court that issues the commission, and you can fake a perfect looking stamp in minutes with a laser engraving machine. So that opens an interesting avenue for committed threats.
@DrunkguyFawkes4 Жыл бұрын
@@RobertMorgan I am in Canada (not US). I used an actual lawyer to noterized the reciept. Took about 36 hours to get the code, I doubt they would even have confirmed it (very small town lawyer, in a different country......) They probably just want something on file to cover their ass.
@danielbrandstetter8713 Жыл бұрын
in fairness, in their most recent tweet liberty safe explained that they will allow people to write in and have their master safe code removed from liberty's database (which implies that the master codes are unique, which is good), and that they will now require a subpoena. Which is the best thing they can do now after all this. However, that's still a bit of a "too little, too late" thing.
@HonestAuntyElle Жыл бұрын
NSA. If the database ever existed, it's pretty safe to assume feds likely would have a copy / wiretap of that process. And if they don't, they will shortly, if the opt out happens afterwards.
@danielbrandstetter8713 Жыл бұрын
@@HonestAuntyElle I wouldn't disagree, but there's not much that Liberty safe can do about that
@Scotty_in_Ohio Жыл бұрын
To add to what others have said - that once the admin or highest level code is changed it's been changed and there really isn't a way to by pass that (with just the lock serial or through the keypad) - I cautioned the buyer of my last house (where we included the safe I had and didn't move to my new home) to run through the entire process to set the combos (multiple ones) before using the safe as I had replaced the "admin" / top level numbers when I had the safe installed and I had done it again when I moved out. As others have pointed out the documentation you receive with the e-lock from Liberty (the S&G ones at least) isn't complete - it gives instructions on how to "add" combos but not really how to change the "master" / "admin" combo but it _does elude to it_ - about 5 minutes on your favorite search engine will uncover the full docs and while they are a bit different depending on model you can still tell based on the keypad layout what version you have.
@ianhasnochannel Жыл бұрын
This is a good reminder that as someone like a safe company or a locksmith, even if you want to help, requiring a warrant before you do anything protects you. Personally, I think it's most likely that they looked up the safe by serial number and gave the shipping combination, but it's also not unlikely that most, if not all, consumer-level electronic safes have override codes in a manufacturer database.
@LavenderSystem69 Жыл бұрын
Which Liberty safes have. In fact, they're so kind (/s) as to have documentation with all their manufacturer codes available on their website, without so much as a security verification to prove that you're the safe's owner to protect against foul play, be it by private citizen or government agency. Great for getting yourself back into your safe in a hurry if you forget your combination, terrible for actual security of sensitive inventory (i.e. firearms and/or ammo)
@cascadianrangers728 Жыл бұрын
First thing after I installed my gun safe, door up, in a concrete slab, was change the combination for the mechanical lock. Now not only do you need the combination, but you have to pass a strength check to lift door
@seeharvester5 ай бұрын
How much does the door weigh? Because laying it flat like that makes prying much easier.
@chriswitmer9754 Жыл бұрын
The first thing that popped into to my head is how this reminds me of to the whole Apple refusing to unlock iPhones. How much of a difference is there between physical property and digital property. As far as I’m concerned property is property.
@canadafree2087 Жыл бұрын
Or how Amazon Ring Doorbell did give video footage to police when they asked, all without telling the customer.
@entropy11 Жыл бұрын
Apple is big enough to bully most countries and isn't afraid of some lawfare.
@RobertMorgan Жыл бұрын
Apple didn't refuse anything, they complied...the difference is them complying was nothing because they were physically unable to open that phone, there was no mechanis, to do so. They used encryption even they could not break. That seems to be the way to me, do what you want, you can't threaten me because there is no remedy. It can't be done you can't force it to be done. It's like pouring JB weld into a keyway, then demanding a locksmith impression or pick the lock to open it. It's not that he's refusing, he just CAN'T.
@cakearmy_maxgaming6346 Жыл бұрын
they could break the encryption if they wanted. They have the damn keys. @@RobertMorgan
@ClickClack_Bam Жыл бұрын
@@RobertMorganExactly. Police raided some VPN recently & told them to tell them where the info they were looking for was at on the drives. They told them they don't collect that info so there's nothing to show them. The Police left empty handed. Perhaps an encryption of the safe software should be implemented where when the customer changes from the default combination to their custom combination, THAT info CAN'T be read because it's encrypted & the original combination is useless & dumped from memory.
@turbo1431 Жыл бұрын
As a heads up, Liberty also makes safes under the "National Security" brand... which have electronic locks on them that say "Liberty" on them.
@TimPeterson Жыл бұрын
hold up. the first piece of advice you have to prevent an out of control government that has cooperation from corporations and is using unreasonable force to go after political opponents is to not be fascist?
@kimhill9241 Жыл бұрын
You didn't do your homework, guy never stepped foot in the capital building.
@forbiddenera Жыл бұрын
I would not be remotely surprised to see every single electronic lock having a secret factory code. Also as an ee, your explanation was plenty fine for the purpose.
@charlottelanvin7095 Жыл бұрын
Once there is a search warrant, LE is getting into that safe by hook or by crook. A method of getting the electronic lock open seems to be known to Liberty. I think the head of legal should have said: asking nicely is insufficient for me to help, if you subpoena the information, I'll provide it. That would have been a better look but it doesn't change the outcome. LE was getting into that box that way or another way. Oh yeah, and a safe tech is going to defeat a mechanical lock too if he is lawfully instructed to do so.
@RaDeus87 Жыл бұрын
Very much this, no way to keep LE out if they want to. I was going to suggest that hiding the safe might work, but then I realized that if they know you have a safe, or you have 10 unaccounted guns, then LE will just start tearing your house apart until they find it.
@RobertMorgan Жыл бұрын
At that point you WANT them to destroy it, as you record this, so when they do open it, sans contraband, it further bolsters my future lawsuit lol.
@bigboi1004 Жыл бұрын
@@sumduma55I'm gonna need a source on that "metal card being a machine gun" claim.
@@bigboi1004search for the AutoKeyCard on Google and you will find some info.
@maniakaz Жыл бұрын
I can confirm that Gardall has the combination of their mechanical locks (S&G in my case) as it was when it shipped (My safe is 20 or so years old too). When I was having an issue with the dial they asked me for the s/n and the combination I was trying and they confirmed it was the combination at the time of they shipped the safe out. I replaced the Sargent & Greenleaf dial myself and set my own combination.
@RobertMorgan Жыл бұрын
159# That's all I'll say. That's the factory display mode open code on quite a few brands of mid-tier gun safes. Try it next time you're at a Cabela's, Bass Pro, Academy, hell it works on the safes at tractor supply and Farm and home as well. It's a simple fix to change it after purchase, IF they change it.
@aaronlandry3947 Жыл бұрын
One aspect that isn't really talked about is what if there's a corrupt officer who's trying to do stuff under the table off record and just calls Liberty safe and provides fake documentation in order to get master codes to stuff that he shouldn't have access to? That's another reason why it's important to not acquiesce to a simple request and to force the government to issue a subpoena for this information. A subpoena is something that the company lawyers can easily reference and verify is accurate and there's usually enough time for the lawyers to do exactly that before they comply with it. Here they basically just handed over the master code with a basic phone call.
@kstricl Жыл бұрын
Different device, but similar solutions- Security PVR. We have one at work that was bought through auction, so we did not have the security codes. After an email to the manufacturer, we provided proof of purchase with the serial and were sent a reset code. Thankfully for the previous user, they had kept the hard drives, so nothing to find in it. So remember: remove your data from devices that have anything personal before disposal, they can't recover what doesn't exist.
@S_Roach Жыл бұрын
Don't just remove the data. Remove the drives. There are ways to SUPPOSEDLY make the data unrecoverable, and the drive still usable, but as far as I know, there is still nothing that beats putting an old-school aluminum platter drive in a hot enough fire, or hitting a laptop-sized hard drive, (glass platters), with a hammer a few times. Don't know what to do about SSD. Microwave?
@Nozzred Жыл бұрын
@@S_Roach Microwave might work or just wack it with a hammer. CD/DVD really fun in microwave.
@paulstimpson830 Жыл бұрын
If law enforcement hadn't managed to get hold of the safe serial number from the sticker, this raises two other questions for me: Is there some magic thing you can type into the keypad that reveals the serial number even if the safe is locked? Do all Liberty safes of a given model or, worse, all locks of the same type across all models of safe have an identical override code? If all locks from whichever Chinese OEM manufacturer they used have the same override code and someone with hostile intent dumps the firmware out of one, that would be a serious security concern. Time for someone to make an open source replacement lock board for these safes?
@briancorbino2043 Жыл бұрын
The best answers I can come up with as to why Liberty would collude with the State are either fear: "We'd better play along so we don't get raided" or sympathy: "Ownership is on the same page as the State on this issue, so play along."
@marcogenovesi8570 Жыл бұрын
I'm thinking it would be possible to make a "replacement board" that is based on Arduino ecosystem. Then you can provide the full source code for its firmware and since the user can wipe and reprogram it from zero starting from known source code it would be more trustworthy than whatever closed source firmware is running on the board that comes with the safe
@l0ckmanjohn Жыл бұрын
You are probably right that you could make an arduino controller and it would probably give some security through confusion just make sure the markings can't be seen through the post hole. However. there are better electronic locks out there. This one is made to be inexpensive and mass produced. You could get rid of this attack with the arduino. but there are physical attacks that would still work with very little effort.
@marcogenovesi8570 Жыл бұрын
@@l0ckmanjohn I don't understand. The main point of replacing the electronic board is to avoid factory backdoors, not whatever "security through confusion" is. What does "make sure they can't see the markings" solve exactly? Even if someone knew there is an arduino inside how does that help them? "There are better electronic locks" does not mean anything and is kind of bs for a lot of "high end" locks. The board in a e-lock is just a microcontroller connected to the keyboard contact matrix (that is outside the safe) and a tiny flashchip for storage of the password. There is nothing you can make "better" because that's all it is, the entire point of digital electronics is that the complexity is in the software not the hardware. An arduino is also mass produced and inexpensive. With an arduino or similar generic microcontroller board you can also program it to run some interference against the battery scan tool or whatever other attack if you want, but that was not my main point. Yes I'm also fully aware that replacing an electronic control board won't make the safe more secure against physical attacks. It would be strange to believe otherwise
@bosstowndynamics5488 Жыл бұрын
Kludging your own lock controller together might make you feel a bit better about less chance of deliberate back doors, but any system like this is going to be full to the brim with accidental exploits from the Arduino itself not being a cryptographic grade processor (those magic black boxes will work way better for instance), and from all the subtle implementation errors that are sure to happen. Rule number one of electronic security - don't roll your own. Get something very widely used that's been aggressively audited and is off the shelf and easy to configure.
@marcogenovesi8570 Жыл бұрын
@@bosstowndynamics5488 accidental exploits like what? What is this amateur hour? This is not a server with a public IP it's a very basic electronic door control system that is inside the safe itself. The only thing that is exposed is the keyboard but that is on digital input pins (i.e. can be ON or OFF) not on a bus. I'm not sure even the "magic black boxes" are using any form of encryption for pin storage, what's the point of encryption if it's all inside the safe. That said Arduino is an ecosystem with many different microcontrollers added as time goes on, the newer ones have enough resources for the crypto libraries and/or have hardware-accelerated TLS/AES/whatever accelerators so you can do whatever you want and encrypt your key too. Nobody audits "widely used off the shelf and easy to configure" consumer electronics. IoT is a raging dumpster fire and has always been a raging dumpster fire.
@RoamingAdhocrat Жыл бұрын
yeah, if you wanted an aftermarket lock controller, there's probably much better platforms than Arduino which wouldn't necessarily cost a lot more
@brianhignett8954 Жыл бұрын
Take Deviant's advice, swap out your electronic safe lock, they are "convenient" but that's about all. They can be opened many ways, LBB, Phoenix?, Ionic gel, even a UV light. And easily disconnected from the safe creating a lock out. A three wheel or preferably a 4 wheel mechanical safe lock will last "forever" - they have been around for over 150 years - some still working. Yes some can be manipulated - a rare manual skill. A robotic dialler can work, as can a robotic manipulator. Time consuming in most cases and hardly covert. Electronic locks?... "not if they pack up, but when." When a customer gets seriously locked out of a safe with an electronic lock, they always ask for a mechanical replacement, bill shock I guess.
@johncage5368 Жыл бұрын
Very interesting. Looking forward to your analysis of their locks, finding out what Liberty Unsafes (... and probably S&G?) really did there.
@mishmashmedley Жыл бұрын
What's really a bad sign here is that they raided a guy who was at the capitol that day, but DID NOT PARTICPATE in the invasion of the building... this makes me not want to attend ANY public gathering of any kind.
@DIY_Miracle Жыл бұрын
The feds ultimately want people to be scared of dissenting. I imagine most of these are just show trials. Forces us dissenters to put ourselves in harms way unfortunately.
@thephantom7059 Жыл бұрын
as an EE and multi-field dabbler I have rolled my own solution a backup mechanical with a primary custom User Interface with quick access with all power on the controller filtered, shielded and suppressed no operational noise is heard in EMF and silent on the wire. with the panel having it's own power being electrically isolated from the controller's power and signal lines the black box only sees the interfaces power draw. also the controller has several forms of intrusion detection and other forms of communication independent of the house connections same goes for the alarm and camera systems. Overkill, absolutely Yes! but this is more vindication the companies can't be trusted to do the right thing. I would rather lance my safe if something went wrong then grant Tom, Dick and Harry access via a unknown backdoor.
@DeviantOllam Жыл бұрын
That's some badass dedication right there!
@ZOMBIEHEADSHOTKILLER Жыл бұрын
all the lock info is great..... but i have to point out that protesting, at your countries capital, isnt "fascist" .....its a basic right.... protests are part of the checks and balances of the whole government/public relationship...... and protests, are supposed to be disruptive, uncomfortable, and even terrifying for the government..... if the government dosnt like it, then they have the option of governing in a way that keeps the keeps the protestors from wanting, or needing, to protest................ the government has the right to do what the public says, and nothing else.......... and the public has the right to keep the government in check, by any means necessary.......... the government dosnt have to like what the public does, it just has to accept it.
@sittingstill3578 Жыл бұрын
Someone literally used an attack vector like this on my coworker today while we were at work. Perfect timing, dude.
@theaberrantdon Жыл бұрын
I just got off the phone with Liberty. They told me that the code that was given was a secondary master code that is unique to each individual safe and seperate from the code that you set for your safe. They also said that they are offering to expunge anyone's master reset code from their records, if you want to take on the risk of them not being able to let you into your safe, if you forget the code.
@443DM Жыл бұрын
So there's going to effectively be a list of everyone that asked for their master reset code to be expunged. Great.
@johndoe-wk1ru Жыл бұрын
Are X09/X07 locks vulnerable also?
@MonkeyJedi99 Жыл бұрын
And what major crimes was this guy even suspected of that the troops get to cut the internet, destroy private property (cameras), probably destructively entered the home, and knew to go after that safe that they somehow knew what model was present?
@noneyabusinessyoushouldbes7924 Жыл бұрын
He was invited into the capitol building to petition the government for redress of grievances, so basically the same as a serial killer???
@amadensor Жыл бұрын
According to the user manual, Browning retains a copy of the combination to mechanical lock safes in case it is lost. Is changing the combination of a mechanical s&g lock a user thing, or a tech thing?
@kg6hum Жыл бұрын
If there is a second unknown code, would that also show up in the differential power analysis at startup? If no one has noticed it before, maybe it only loads and checks against it after the first code didn't match?
@Pralix2000 Жыл бұрын
Liberty has or had a combination escrow service that was voluntary. You could put your combination in their supposedly secure service and if you forgot your combo or died, they could provide the combo.
@auroran0 Жыл бұрын
I wonder if there will now be a rush on mechanical locks or replacement electronic locks for people who are not dumping their Liberty Safes outright. Also, their social media does mention a warrant for what good that is.
@S_Roach Жыл бұрын
I know of a robot someone built to crack a safe. One of the things he noticed was that the fake gates, or whatever they're called, had a different thickness from the real gate, making feeling out the play a practical attack.
@HelloKittyFanMan Жыл бұрын
"There's a reason I don't do it." Well yeah, but reasons are just anything. What's important is that there's a _purpose_ that you don't do it.
@JasonEngland Жыл бұрын
I think that Liberty offers a "you give us your actual, non-factory combo and we'll give it back to you if you ever forget/lose it" policy. If true, that's a 4th possibility.
@onlineconsumer4796 Жыл бұрын
If you get several that allow you to change their locks, you should do a video on how to change the locks out.
@Elkadetodd Жыл бұрын
Mechanical locks need something to prevent brute forcing. An internal electronic device that blocks the system for X minutes after 30 complete turns of the dial or something. "oops my battery died" recovery on electronic locks should involve a little hand-crank generator you manually turn to charge an internal capacitor - not exposed power leads you can measure draw off of. If it's a safe (not a fireproof box), opening it should take attacking it with plasma cutters. (probably after you push it in the swimming pool to try to protect the contents)
@ryanwilson_canada Жыл бұрын
I have a sentry safe, it has the cheapest of cheap wafer locks in it. I actually pick it most of the time because its faster than trying to figure out where i left my keys. Lol, that said, its a fire safe, passports, birth certificates etc. Stuff like that. Important things, that would be a pita to replace in the event of a fire. It serves its purpose, nothing more. I certainly wouldn't store a firearm in it.
@RobertMorgan Жыл бұрын
Right, and you store that safe INSIDE your fire rated gun safe. I also have fire resistant document storage bags in the sentry safe.
@ryanwilson_canada Жыл бұрын
@RobertMorgan i dont go quite that far. But it's in a completely concrete room in my basement. Also. I live in canada. So no need for a gun safe until i have some time to apply for my pal, though i do have a few proper fire rated safes given my work, I'm just lazy, and dont want to move them down there until i can actually use them. Not the lightest things in the world.
@grant_HH Жыл бұрын
Didn't you mention something in one of your talks about Babek being bored in a hotel room, dismantling the safe and finding that 00000 was baked into the firmware as a master code that the manufacturer didn't know anything about? Completely different grade of product but still :O
@ryshellso526 Жыл бұрын
Flipperzero has a rainbow attack for hotel safes. ;)
@grant_HH Жыл бұрын
@@ryshellso526 I wonder if I can convince my wife not to leave the passports in the hotel safe 😬
@MarcelEnglmaier_1 Жыл бұрын
I have a liberty safe installed by NWSafe. They specifically tell you there’s an emergency code that they can only retreive when you prove you’re the owner to NWSafe when they install it. I’ll prob have a new lock installed now…
@Coltgov191145 Жыл бұрын
There is a 4th method... most electronic safes have a backup key if the power ever fails, the serial number matches the factory cut key and they could have aquired that serialed key from liberty with the warrant and opened it that way...
@bllfrg777 Жыл бұрын
Most proper electronic safe locks in the US don't have a key backup. Some of the cheaper stuff definitely does, but the vast majority of safes in the mid to high tier consumer and low to mid tier commercial grade that use electronic locks have no key override. Instead, the batteries are located outside of the safe under the keypad. If the lock itself fails, you just have to get it drilled. I always advise my customers that if the safe has a key to bypass the electronics, the electronics are almost certainly garbage.
@tweedeldee8122 Жыл бұрын
I remember 20 or so years ago researching safes and Liberty was doing marketing BS back then. They claimed their safes were more "secure" because it had hidden hinges that could not be attacked. But any good safe's hinges only serve to hold the door and attacking/cutting them accomplishes nothing. I went with Amsec and old school dial. No problems.
@RobertMorgan Жыл бұрын
right, cut off the hinges, so what, that doesn't affect the dozen 2" locking lugs sticking 4" into the frame securing the door.
@ChevyConQueso Жыл бұрын
Good choice. Liberty is a joke compared to Amsec's available options. However, the price shows it.
@camronbay1 Жыл бұрын
Well depending on the model Amsec you have some of the craftsmanship is not to great.
@blackmoon8459 Жыл бұрын
@@camronbay1 As someone looking into getting a good safe for documents as well as things that go pew, are there specific models that are the bare minimum of "good craftsmanship" on Amsec safes? Mainly so I can go, "Okay, that's where 'good' starts, let me look at these and better." One would think a $4k safe would have decent craftsmanship, but I don't personally know Amsec as a brand, so I don't know what a "cheap" Amsec safe looks like vs a good one.
@camronbay1 Жыл бұрын
@@blackmoon8459 If your looking for a good amsec safe go with a Amvault or a RF 6528 remember a safe is a investment other excellent safes to look at as well John Tann/ISM just to name a few.
@MrGibsontoldnolies Жыл бұрын
On board until the "don't be a fascist" remark in regards to the capital incident.
@porkersthewonderdog Жыл бұрын
This has nothing to do with the politics of the accused. Liberty Safe gave the code over simply because the FBI said they had a warrant for searching the house. Liberty Safe is not obligated to aid law enforcement because of a warrant they are not named on. The only justifiable way for Liberty Safe to give over a master code to law enforcement is with a subpoena for it. If you think for a second that they only gave the code because the accused is, in your words, "a fascist" you are mistaken, Deviant. They likely have done it in the past with other people and the only reason it has come to light is BECAUSE of the accused going public about the obvious breach of trust and privacy by Liberty Safe. Of course if Liberty Safe hadn't given them the code, they would have gotten into the safe destructively and then the accused would have had recourse to be reimbursed for the damages.
@JohnS706 Жыл бұрын
I've wanted to swap the electronic lock from my Secureit cabinet to a mechanical for years now. Does anyone know how to find what fits?
@Hebdomad7 Жыл бұрын
Mechanical locks can be manipulated. There are machines that can dial a mechanical safe. But those who can open mechanical safes quickly are a very rare breed. If you want a safe lock basically nobody is hacking into that is very reliable, have a look at a Kaba X10 Safe Lock. It's the kind of lock a typical three letter agency would use on it's own files.
@MysteriousFigure Жыл бұрын
Only issue is that you have to be approved by the US gov to buy it (FF-L-2470B), clearly some security through obscurity attempt, and not necessarily designed to keep out people forever (more so keep them out to a level where by the time you start drilling, the feds / guards with guns have already arrived before you get into the lock)
@TheLaughingWolff Жыл бұрын
Those can be a pain to open even when you know the combination. The x10 is pretty great 👍
@DeviantOllam Жыл бұрын
@@MysteriousFigureI can buy them. 😉 if you want one, they're about $1400 officially. But I can also buy the X-09 as new old stock generally... much more reasonable at around $300 my price, if I can find them from a few specific suppliers. 😁👍
@minigpracing3068 Жыл бұрын
There are videos on youtube on how to change the electronics on these safes. Also, it appears that owner's manuals for Liberty are on their website.
@BandEAtoZ Жыл бұрын
As a safe technician that sees a plenty of gun safes, I know I will get a ton of request to do electronic safe lock assessments, master code resets, combination changes & new lock sales. Yet least we forget, most gun safes are just residential security containers (not even good enough to be called safes) and any law enforcement professional likely had 5 other methods of entry to the fancy painted box. This issue of the factory (or salesman) retaining a copy of your combination or a special pin tied the serial number on your electronic safe lock is pervasive throughout the industry. It is a feature meant to support lost combination recovery for customers and warranty work. While many locks can be totally reset, some do have a fixed reset code that will always make for an easy safe opening. Know what your lock can do, and always change all available default / shipped from the factory combinations. But what I believe is all of these issues are nothing compared to the volume of cheap, junk boxes that fall open to a stern glare that are out there. Come on folks, if it light enough to carry in, it can be carried out. If you are buying the cheapest safe, expect low-priced results. ~BandEAtoZ
@LiamVonOahu604 Жыл бұрын
Mahalo. Great breakdown of not only this, but the bigger issues regarding this as well.
@443DM Жыл бұрын
Do you offer a service to swap the electronic locks between two safes? Asking for a friend. But I would *guess* there's a (published? unpublished?) method for the lock to spit out the serial number.
@09FLTRMM77 Жыл бұрын
Thank you for your time making this video! You have answered a TON of questions I had rolling around in my brain!!
@JD-gn6du Жыл бұрын
I’ve always thought that electric locks for safes were a bad idea. Mechanical lock has always been my preference
@LavenderSystem69 Жыл бұрын
Portland area. I'll absolutely take you up on that offer. All I need ahead of time is a recommendation for a solid mechanical lock that you recommend based on your expertise
@DeviantOllam Жыл бұрын
S&G 6630 is a solid choice for reasons I'll show in the next video I'm releasing
@LavenderSystem69 Жыл бұрын
@@DeviantOllam Is the 6730 an acceptable alternative? I'm having difficulty finding any 6630s for sale
@Poorehouse Жыл бұрын
@@LavenderSystem69not as secure. The 6630 is more resistant than the 6730.
@BlainesEscapeCorner Жыл бұрын
What about the keyhole in mechanical locks. Doesnt the manufacturer have a key.
@matthewmiller6068 Жыл бұрын
Don't most safes the manufacturer has the master codes for when someone forgets and wants back in? Most of the safes I have owned the directions say you can provide proof of purchase and serial and get the master programming codes back to reset or override it. Granted mine have all been paperwork safes not gun safes but its like a customer support "get back in" feature to make users happy
@jessicav2031 Жыл бұрын
If manufacturers are STILL not protecting against such trivial attacks, it sounds like the design really is lazy enough to have some stupid master code. I wouldn't expect a company that can't be bothered to add a low pass filter or a supercap (charge the cap and disconnect from the external supply to make the code check) to write good firmware or have good key management. I'm an EE working on embedded systems and my safe has a mechanical lock. If it's closed source, it's backdoored.
@ceefusjenkins2281 Жыл бұрын
Did / Are you going to publish the firmware dump course? I'd love to see it.
@ArtturiSalmela Жыл бұрын
8:39 The way the thing reads a 1 or a 0 affecting the power draw is so cool! Very impressive that you can make a device to detect it!
@viru52000 Жыл бұрын
The Quartering contacted Liberty Safes and found out they have a master code for BOTH mechanical & digital locks. They also said this is industry standard.
@gingewonka Жыл бұрын
funny he mentions cabelas... cabelas brand safes are rebranded liberty safes...
@Stuie444 Жыл бұрын
Just FYI - the mechanical lock that Liberty uses comes with a "dial key" that is capable of bypassing the mechanical dial lock. So they are just a susceptible, since I'm sure they all have either A) a database of the key pin numbers for your serial or B) a master key that will work on any safe. If you are serious about the issue - don't replace with a Liberty mechanical dial.
@markgman4157 Жыл бұрын
My Liberty came with a SecuRam Safelock. The Liberty manual shows only how to change the user code and says you can register your safe and they can then recover lost codes. However, SecuRam says there are 2 codes, the user code and a manager code or supercode. You can reset both codes using a reset button on the back of the lock. Liberty doesn't tell you about that either. So Liberty isn't telling the full story on this particular safe/lock.
@PaladinStem Жыл бұрын
I have a Winchester branded gun safe and if I remember correctly the manual states that if you register it with the manufacturer they can provide a recovery key. With this I am thinking about swapping to another lock. Edit: checked their website and they do have a process for getting a recovery code.
@marcogenovesi8570 Жыл бұрын
time to shop for another lock
@famousamoso7 Жыл бұрын
You do realize the recovery key only works if 1) you register the safe under your name and 2) have the serial # of the safe) So if you dont register it then the government doesn't know you have it and it you removed the serial # from the safe as Deviant suggested then if the government was concerned they couldn't get any help from the manufacturer.
@TrueHelpTV Жыл бұрын
If you have time, I was just wondering something; does a licensed locksmith have any legal bound duties to not disclose things like "master codes" once they know them and/or if they are, are they still legally bound not to tell people it if the information is sourced third party like say for instance I told you the code; and to expand on that point is there a duty bound legal obligation not to share it if the company told locksmith A, who then told locksmith B at a random conference the code (and can he tell him the code since he's a locksmith and so does that now make person B now bound or not?) I hope you see where I'm going with this, because Murphy's law tells me that these codes should be leaking more often
@crimsonhalo13 Жыл бұрын
Wow, that was fast! :) Thanks for putting this video out to educate us.
@gabrielanderson1604 Жыл бұрын
I just looked at the electronic locking mechanism on my Canon safe with a SecuRam lock, it had six numbers on a sitcker on the lock that are very much not the combination I programed into it. When I punched the numbers on the sticker into the number pad on the front it unlocked without hesitating.
@JaykPuten Жыл бұрын
If there's a master code to get in... It's *NOT A SAFE* it's a METAL BOX For alot of people, they just realized they bought a *BOX* with the *ILLUSION* of safety... Sure all safest can be gotten into, but non-destructively... I dislike that Someone is gonna buy the cheap liberty safes off eBay, and make hardware to find the master code... Cus why not? Be it through the electronics, or the idiot way of going through all combos, someone will
@rmp5s Жыл бұрын
Now I wonder...are there back door codes for any mechanical locks out there? Is there any way to check?
@MedusalObligation Жыл бұрын
Certain fire alarms systems are protected by login codes that are user and dealer changeable. If you are the dealer (or Government) and the code is lost, you can contact their tech support. They have you enter a code on the keypad. A date sensitive code pops up. They read that code and run it through an algorithm that spits out the programmed dealer code. Safes may be no different.
@PsRohrbaugh Жыл бұрын
Yeah but fire alarms do a completely different job from a safe.
@MedusalObligation Жыл бұрын
@@PsRohrbaugh You are missing the point. The safe can be set up the same way in the electronics. You change your code. Authorities want access. They contact safe mfg and mfg has them enter a code. They take the display readout, run the algorithm and give the current code.
@allenshepard7992 Жыл бұрын
"Special tool" wow - no one else mentioned this. Yes this issue has been a wake up call for many. Yes complying with any court order or search warrant is good and the proper thing to do. However the exposure of data breachers is scary. Much like GM or Tesla having a back door for my car and than that code being accidentally released. I like your idea of swapping a lock on a Liberty safe for a mechanical lock.
@porkersthewonderdog Жыл бұрын
They complied with a search warrant they were not named on. That is NOT the proper thing to do. If the company actually cared about their customer's rights they would require a subpoena to give the master code over to law enforcement.
@GamesFromSpace Жыл бұрын
Blocking that black box device seems trivial, so I'm confused. Either use the external power supply to charge an internal supply, or add a lot of noise to the power draw, or simply encrypt the stored memory. Cant tell what the code is if its literally encoded. This last one is basic security for software which uses passwords.
@GlennBrockett Жыл бұрын
A quality low pass filter on the power supply should be enough to defeat the blackbox attack I would think. Or completely decoupling the external power from the processor (Charge a capacitor from the external source, disconnect and run from that capacitor rather than the external source.)
@marcogenovesi8570 Жыл бұрын
the electronics is seen as "whatever" so they get whatever is cheapest. If they can save 0.01$ by not using a capacitor to filter the noise they will. THis is true in general for consumer electronics
@DeviantOllam Жыл бұрын
Correct. Various manufacturers have now started trying to prevent the use of the tool by changing their circuit design slightly.
@matthewellisor5835 Жыл бұрын
Dev, what are your thoughts on group 2 v. 2M as replacement? I have never and don't plan to ever purchase an electronic lock for such use but o expect that I likely to find a good deal on a heavy box soon. I know that it's 120 minutes but what is different in the internals?
@DeviantOllam Жыл бұрын
The biggest difference between those two is the addition of what is called an "eccentric roller" in the tip of the nose where the lever interfaces with the cam. Group 2M safe locks are often constructed that way. Along with some other things like some potentially false gates and such. This makes conventional manual manipulation much harder. They are still susceptible to something like an auto dialer, however.
@timbober1 Жыл бұрын
I want to have a small safe for important papers in the old well room in my basement. It’s surrounded by concrete on three sides. Not fireproof on one side (door to the house). I would almost prefer a key type lock. I don’t have guns (not opposed to them, just don’t own any) do you have any suggestions, if this is something you can’t answer I understand.
@lyfandeth Жыл бұрын
"Lucy, you got some 'splaining to do!"
@shanedk Жыл бұрын
9:45 - It seems to me the only way this can work is if they're storing the code unhashed, and so it will read the ones and zeroes of the actual code and reveal it. Otherwise, they get garbage that's useless to them unless they can somehow run a preimage attack. This is why the standard is to NEVER store such a code unhashed.
@ElizabethGreene Жыл бұрын
The combinations are super short with a tiny keyspace though, so even if they hash it it's (relatively) trivial to brute force it.
@tiagotiagot Жыл бұрын
So companies didn't even hash the code in the old models, just stored it plaintext? How long ago were those designs created?
@cryptoking6360 Жыл бұрын
I have a sentrysafe and the manual says "Factory code: The safe will ALWAYS unlock using this 5 digit code found in the owner's manual. This code cannot be deleted." I don't like it but it's not an isssue since the code seems unique to my safe, there's no external S/N, and I never registered it or associated it with me...and it's bolted into concrete.
@anthony10370 Жыл бұрын
Why don’t they make parallel memory chips that when one get a 1 written. The other gets a 0 in the same spot. Then when it’s read with the power supply the line could be flat?
@Combat_Pyro Жыл бұрын
which gun safes would you recommend other than liberty?
@artstrutzenberg7197 Жыл бұрын
Is there any sort of compiled list of third party companies that sell mechanical locks that fit the shape/profile for liberty safes? (Something like this might be useful for the folks that want to swap out their locks for a mechanical lock) Do these locks have the ability to be updated with new firmware? If so has there been any effort to push the lock makers to switch to something that is open source? (If anything you would think an open source firmware for an e-lock + bug bounty might lead to something that is more secure)? Finally the attack that utilizes power analysis to figure out the code--any chance you could produce a video on this attack vector? (What I'm also curious about: when the lock makers addressed this attack, did it require physical changes to the lock (board changes) or was it a change to the firmware)
@HelloKittyFanMan Жыл бұрын
"Stay... 'SAFE' out there!" Ha, nice pun!
@Jmr2urbo Жыл бұрын
Is there a possible Fire Fighter code to let them in if a kid locks himself in or something to that effect?
@n8loux Жыл бұрын
What do you use for password management? Id be interested to see short video on the best way to do that nowdays
@ihateyankees3655 Жыл бұрын
I really, really don't want to give money to this company if they have a policy of "No subpoena? No problem!"
@kaschberle6948 Жыл бұрын
im very glad that i opted for a safe with mechanical combination lock. "Fun" side note from germany: There was a ruling recently which basically said that the mechanical key to a gun safe has to be stored in a container that has the same "grade" as the gun safe itself. This makes locks with a mechanical key basically useless because where do you want to store that key then? In yet another safe?
@AalbertTorsius Жыл бұрын
It's -turtles- safes all the way down.
@marcogenovesi8570 Жыл бұрын
in a combination safe? How do combination safe score as "grade"? higher or lower than the hun safe that require the key?
@kaschberle6948 Жыл бұрын
@@marcogenovesi8570 combination lock are perfectly fine. the "grade" only refers to the safes mass, wall thickness etc.
@namibjDerEchte Жыл бұрын
@@kaschberle6948 To put it into better words, it's trying to be a difficulty scale for a burglary, like being in the basement or so while you're on sleeping on an upper floor, or in an apartment building with neighbours that eventually wake up from power tools and call a noise complaint if it persists. And a save properly anchored to a reinforced concrete slab/room-corner is not easy to get off without possibly risking local structural failure of the building (i.le., part of the floor of the room falling down, or the wall/column with what it alone supports crashing down), at least if you're in a hurry. A heavy safe is also not easy to get out of a building if the surroundings are designed to block quick lifting equipment from being set up, especially from the mid triple digit kg range up. _Especially_ if it has wall/floor stuck to it on more than one side from cutting it out with the wall&floor it's attached to. Mostly it's indeed just to last until security arrives to interrupt the safe cracking/burglary, and a well-attached safe won't leave the building in the 10~15 minutes response time a heavy attack would expect without almost reaching for hollow cutting charges placed to cut the wall/floor it's stuck to out from the rest of the building, followed by reeling/winching it with the wall/floor section out of the broken building and onto/into a truck. At least assuming that just blowing the safe itself up would destroy the contents.
@ssjaken Жыл бұрын
A guy just got 17 years for "shaking a Capitol fence menancingly" during the protest. The government is going full hog. That show of force isnt surprising.
@ssjaken Жыл бұрын
Harvey Weinstein got less time in LA for all the crap he did over the years than a guy shaking a fence who never went into the Capitol.
@Elkadetodd Жыл бұрын
"Don't be a fascist" is crap. Because now that Liberty has stated their policy, we know the same thing could be used by law enforcement to open your safe and find your 3 grams of weed, or your banned-in-your-state standard capacity magazines, or the cash you made at a yard sale and didn't declare on your income tax.
@RobertMorgan Жыл бұрын
The irony of calling the victim here a fascist, as he's perp marched out by fascists lol.
@BasedWoodchipper Жыл бұрын
This. It shows that RTA has picked a side politically. Siding with the feds without saying, "I'm siding with the feds." The feds have already done this to lefties and normies, it just didn't get coverage because fuck them.
@brunswicksquaremusic5905 Жыл бұрын
Do you think the authorities are incapable of Googling the number of a local safe tech?
@mcalsip Жыл бұрын
@@brunswicksquaremusic5905 If you buy a safe from a sporting goods store, you get what you deserve. You can cut into any of those sheet metal, china boxes with a circular saw, a metal cutting blade, and 15 mins.
@ronaldannas1935 Жыл бұрын
I looked for a mechanical lock for my gun safe, I could not find any in my area. When I inquired about them, I was told that the electronic locks were safer. I want to go back and show this to the salesman and ask him if he thinks they are safer still.
@docwil2541 Жыл бұрын
Solid and timely. Thanks for your response. Doc
@cvfdchief9 Жыл бұрын
I'm curious if a magnetic bypass would open it like cheaper versions of similar electronic locks.
@DeviantOllam Жыл бұрын
Strongly doubtful. I've seen a magnet work on electronic Sentry safes, however. Even some surprisingly large ones.
@randomviewer3494 Жыл бұрын
Lol I think I can buy the shitty wafer lock keys from my "safe" company too, if I had too. but as you said, like sentry, its just for fire protection. heck, its a plastic shell with a wafer lock. thats not gonna keep anyone out for longer than them to stop laughing and grab a decent knife.
@stickinthemud23 Жыл бұрын
I taken a screenshot of all your security keys on the backboard and now I can get into all your stuff. 😂
@DeviantOllam Жыл бұрын
They are all blank keys, but I still like the way you think, nonetheless 😁👍
@stickinthemud23 Жыл бұрын
@@DeviantOllam Don’t think too much about my thinking, I just recalled the first video of yours that I saw. Go, Red Team go!