Open Sesame: how vulnerable is your stuff in electronic lockers

Dennis Giese, braelynn

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In "Open Sesame: how vulnerable is your stuff in electronic lockers," security researchers Dennis Giese and braelynn explore the often-overlooked security posture of electronic locker systems, specifically focusing on models from market leaders Digilock and SAG. The talk aims to shed light on critical vulnerabilities within these devices, particularly in offline managed lock systems—those found in environments like gyms, universities, and government buildings where master keys or administrative PINs are used to manage multiple lockers without constant network connectivity. This research underscores a significant gap in the security landscape, as these systems often safeguard personal belongings, sensitive equipment, or even critical infrastructure, yet their underlying security mechanisms may be deeply flawed.

Watch on YouTube

Visual summary for Open Sesame: how vulnerable is your stuff in electronic lockers by Dennis Giese, braelynn
Visual summary for Open Sesame: how vulnerable is your stuff in electronic lockers by Dennis Giese, braelynn

Key moments

  1. 0:00 Introduction to Open Sesame talk and speakers
  2. 1:06 Speakers reveal cease and desist letter from Digilock
  3. 2:25 Overview of talk goals: reverse engineering Digilock and SAG locks
  4. 3:00 Crucial message: raising awareness about PIN number security
  5. 3:10 Vendor disclosure and Digilock's active work on fixing issues
  6. 4:00 Motivation: why consumer locks are easily bypassed
  7. 4:30 Lock Picking Lawyer example of trivial gun safe bypass

Open Sesame: how vulnerable is your stuff in electronic lockers

Speakers: Dennis Giese, Security Researcher, Hardware Hacker; braelynn, Independent Security Researcher

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=GPODCSvZMyM

Overview

In "Open Sesame: how vulnerable is your stuff in electronic lockers," security researchers Dennis Giese and braelynn explore the often-overlooked security posture of electronic locker systems, specifically focusing on models from market leaders Digilock and SAG. The talk aims to shed light on critical vulnerabilities within these devices, particularly in offline managed lock systems—those found in environments like gyms, universities, and government buildings where master keys or administrative PINs are used to manage multiple lockers without constant network connectivity. This research underscores a significant gap in the security landscape, as these systems often safeguard personal belongings, sensitive equipment, or even critical infrastructure, yet their underlying security mechanisms may be deeply flawed.

The importance of this research extends beyond the mere convenience of securing personal items. Electronic lockers are ubiquitous, and their compromise can lead to theft, unauthorized access to secure areas, or broader security breaches if they are integrated into larger access control systems. Giese and braelynn's work is particularly timely given the increasing reliance on electronic access solutions in various sectors. By reverse engineering these devices and demonstrating methods for firmware and configuration extraction, the researchers aim to raise critical awareness about the insecure handling of PIN numbers and master key systems, which form the backbone of these locker's security.

Adding a layer of intrigue and emphasizing the talk's significance, both speakers revealed they were targets of a cease and desist (C&D) order from Digilock, which was reportedly withdrawn on the day of their presentation. This incident highlights the sensitive nature of disclosing vulnerabilities in widely deployed commercial products and underscores the often-contentious relationship between security researchers and manufacturers. Despite the legal challenges, the researchers proceeded with their presentation, stressing the importance of responsible disclosure and the public's right to understand the security implications of devices they interact with daily. Their findings serve as a stark reminder that even products from reputable manufacturers can harbor significant security weaknesses, necessitating constant vigilance and rigorous security testing.

Background

▶ Watch: Introduction to Open Sesame talk and speakers (0:00)

The motivation for "Open Sesame" stems from a long-standing interest in the security of embedded devices and a broader trend of examining the often-underestimated vulnerabilities in physical access control systems. Dennis Giese, a seasoned security researcher and hardware hacker known for his work on vacuum robots and other IoT devices, has a history of scrutinizing electronic lock systems. His previous work includes a paper published over a decade ago on Siemens and Voss door locks and later research into Schlage electronic locks, commonly found in government buildings and universities across America. This talk is presented as a continuation of Giese's prior research, building upon insights shared at a "Berlin 24" event. Braelynn, an independent security researcher with a background in application security and APIs, has recently expanded into hardware hacking, driven by an interest in robots, cameras, and smart locks, making her a fitting collaborator for this deep dive.

The speakers frame their research within the context of a well-established field of lock hacking. Historically, much of the focus in physical security research has been on high-security locks and safes, where the potential impact of compromise is extremely high, often involving valuable assets or critical data. Researchers in this domain frequently employ sophisticated techniques like side-channel attacks to bypass robust mechanical and electronic defenses. However, the speakers note a distinct difference when it comes to consumer and commercial-grade electronic locks and cabinets, which are "known to be bad." These devices often suffer from fundamental flaws, including mechanical bypasses (as demonstrated by the "Lock Picking Lawyer" YouTube channel, where a gun safe could be opened by simply prying open a plastic handle), trivial vulnerabilities, and insecure software implementations.

Crucially, "Open Sesame" specifically focuses on offline locks that are managed, meaning systems where access control (like master keys or administrative PINs) operates without continuous network connectivity. This distinction is vital because it implies that any vulnerabilities found would not rely on network-based exploits but rather on direct interaction with the device or its internal components. The talk explicitly does not cover several related areas, including:

  • Management software: The software used to configure or monitor these locks remotely.
  • Reprovisioning: The process of factory resetting or reconfiguring a lock.
  • Physical attacks using magnets: Common, non-destructive bypasses for poorly shielded electronic locks.
  • Destructive attacks: Methods like drilling, decapping integrated circuits, or other means that physically damage the device to gain access.

By narrowing their scope to offline, managed electronic lockers and excluding these other attack vectors, Giese and braelynn highlight vulnerabilities that persist even when traditional physical and network-based attack surfaces are considered. They emphasize that they chose Digilock and SAG as examples not because they are inherently worse than competitors, but precisely because they are market leaders with a "good reputation" and "quality products." This choice underscores a critical message: if even well-regarded manufacturers can make security "mistakes," then the broader industry faces significant challenges in securing these pervasive devices. The initial legal pressure from Digilock further underscores the sensitive nature of these findings, suggesting that the vulnerabilities discovered were not trivial.

Key Findings

▶ Watch: Overview of talk goals: reverse engineering Digilock and SAG locks (2:25)

The primary findings of the "Open Sesame" talk revolve around the identification and demonstration of significant security weaknesses in electronic locker systems from leading manufacturers, specifically Digilock and SAG. While the provided transcript did not enumerate specific CVEs or detailed exploit chains, the speakers' stated goals and the context of their research clearly point to several critical discoveries:

Firstly, Giese and braelynn successfully identified vulnerabilities within the firmware and operational logic of Digilock and SAG electronic lockers. These vulnerabilities are not merely theoretical but enable unauthorized access to locked compartments. The talk focused on offline managed locks, meaning the flaws could be exploited without requiring network access, often by interacting directly with the lock unit. This is particularly concerning for environments like gyms, schools, and workplaces where these lockers are extensively used for storing personal or sensitive items.

Secondly, a core contribution of their research was the development and demonstration of ideas and methods to extract typically firmware and configurations from these devices. This capability is paramount for an attacker, as it allows them to:

  • Reverse engineer the firmware: By obtaining the firmware, an attacker can analyze the code for logical flaws, hardcoded credentials, weak cryptographic implementations, or backdoors.
  • Extract sensitive configuration data: This includes critical information such as PIN numbers (user PINs, master PINs, administrative PINs) and potentially access control lists or unique device identifiers. If this data is stored insecurely (e.g., unencrypted, weakly encrypted, or using easily reversible hashing algorithms), its extraction directly compromises the lock's security.

The most important part of their talk, as highlighted by the speakers, was to raise awareness about PIN numbers. This suggests that the vulnerabilities likely involve the insecure storage, handling, or authentication mechanisms related to PINs and master keys. In an offline managed system, a compromised master key or PIN could grant an attacker universal access to all lockers managed by that system, posing a severe risk to the security of an entire facility. The fact that the researchers were able to develop methods for firmware and configuration extraction strongly implies that these sensitive data points were not adequately protected within the devices.

The impact of these findings is substantial. The ability to bypass or extract credentials from market-leading electronic locks means that the perceived security of these systems is significantly overstated. For individuals, this translates to a risk of theft from lockers. For organizations, it could lead to unauthorized access to secure areas, loss of valuable equipment, or even data breaches if sensitive materials are stored within. The speakers confirmed that they responsibly reported their findings to the vendors, with Digilock reportedly "actively working on fixing the issues." This positive response from Digilock, despite the initial legal pushback, validates the severity and authenticity of the researchers' discoveries and underscores the importance of ongoing security research in the embedded device landscape.

Technical Deep Dive

▶ Watch: Crucial message: raising awareness about PIN number security (3:00)

While the provided transcript outlines the goals and implications of the research, it does not delve into the specific, granular technical details of the vulnerabilities or the exact methodologies employed for firmware and configuration extraction. However, based on the stated objectives of the talk – "overview of the reverse engineering of Digilock and SAG locks," "vulnerabilities," and "ideas and methods how you can extract typically firmware and configurations" – we can infer the general technical areas that would have been explored.

The core of the technical deep dive would likely have revolved around hardware reverse engineering and firmware analysis. For hardware reverse engineering, researchers typically begin by physically disassembling the lock unit to identify key components. This would involve locating the microcontroller (MCU), non-volatile memory (such as NOR flash, NAND flash, or EEPROM), and any other integrated circuits responsible for processing input (keypad), controlling the locking mechanism, and storing data.

Potential avenues for firmware extraction often include:

  1. Debugging Interfaces: Many microcontrollers expose debugging ports like JTAG (Joint Test Action Group) or SWD (Serial Wire Debug) during development. If these interfaces are not properly disabled or secured in production devices, an attacker can use them to read out the entire firmware image from the MCU's internal flash memory. Tools like OpenOCD or dedicated JTAG/SWD debuggers (e.g., Segger J-Link, Bus Pirate) would be used for this purpose.
  2. External Memory Dumps: If critical firmware or configuration data resides in external flash or EEPROM chips, these chips can sometimes be desoldered and read directly using a universal programmer (e.g., TL866, RT809F). This method bypasses any software-level protections implemented by the MCU.
  3. Bootloader Exploits: Some MCUs have a built-in bootloader that can be accessed via a serial interface (UART). If this bootloader has vulnerabilities (e.g., allows unsigned firmware updates, has an insecure debug mode, or lacks proper authentication), it could be coerced into dumping its current firmware.
  4. Side-Channel Attacks: While the talk explicitly excluded "side channel attacks" in the context of high-security safe locks, certain simpler side channels (like power analysis or electromagnetic analysis) could potentially reveal secret keys or memory contents, especially if the device uses weak cryptographic primitives or lacks proper shielding. However, given the focus on "firmware and configuration extraction," direct memory access or logical flaws are more probable.

Once the firmware is extracted, firmware analysis would commence. This typically involves:

  • Disassembly and Decompilation: Using tools like IDA Pro, Ghidra, or Binary Ninja, the raw binary firmware can be disassembled into assembly code or, in some cases, decompiled into a higher-level pseudo-C code. This allows researchers to understand the program's logic.
  • String and Data Analysis: Searching for readable strings within the firmware can reveal error messages, debug information, or even hardcoded credentials. Analyzing data sections can expose the structure of configuration data.
  • Identification of PIN Handling Logic: The researchers would specifically look for functions related to input processing (keypad scans), PIN storage, PIN comparison, and master key authentication routines. The goal would be to understand how PINs are stored (e.g., plaintext, hashed, encrypted), how they are verified, and how master keys interact with user PINs.

The speakers' emphasis on PIN numbers and master key systems strongly suggests that the discovered vulnerabilities were related to insecure data storage or weak cryptographic practices. For instance:

  • Plaintext Storage: PINs or master keys might be stored in non-volatile memory without any encryption or hashing, making them trivial to read once the memory is dumped.
  • Weak Hashing/Encryption: Even if PINs are hashed, they might use outdated or easily reversible hashing algorithms (e.g., MD5, SHA-1 without salting). Similarly, encryption might use weak keys, easily guessable algorithms, or be implemented incorrectly, allowing for decryption.
  • Predictable Master Keys: In some systems, master keys are derived from predictable patterns or are hardcoded across a product line, allowing an attacker to generate them once the derivation logic is understood from firmware analysis.
  • Authentication Bypass: Logical flaws in the authentication routine could allow an attacker to bypass PIN verification altogether, perhaps by sending a specific sequence of commands or exploiting a buffer overflow.

Given that these are offline managed locks, the ability to extract configurations and firmware implies that the entire security model can be compromised without needing to interact with any centralized server. An attacker with physical access to one lock might be able to extract enough information to compromise all similar locks in a facility, posing a systemic risk. The specific technical details, if they were to be revealed, would likely involve memory addresses, specific microcontroller types, and possibly custom tools developed by the researchers to automate the extraction or analysis process. However, without these specifics in the transcript, we can only infer the general categories of technical vulnerabilities and attack methods implied by the speakers' objectives.

Demo / Proof of Concept

▶ Watch: Motivation: why consumer locks are easily bypassed (4:00)

The provided transcript for "Open Sesame: how vulnerable is your stuff in electronic lockers" does not contain any description or mention of a live demonstration or a pre-recorded proof of concept video. While the speakers aimed to "show you some ideas and methods how you can extract typically firmware and configurations from that kind of devices" and discuss "vulnerabilities," the transcript does not detail any specific demonstration of these exploits in action. It is possible that a demonstration was presented live at DEF CON 32 but was not captured or transcribed within this particular bundle.

Defensive Implications

▶ Watch: Lock Picking Lawyer example of trivial gun safe bypass (4:30)

The findings presented in "Open Sesame" carry significant defensive implications for both organizations that deploy electronic locker systems and the manufacturers responsible for their design and production. The core message—that even market-leading, "quality" offline managed locks can be vulnerable to firmware and configuration extraction—demands a re-evaluation of current security practices.

For Organizations (e.g., Gyms, Universities, Corporate Offices):

  1. Conduct Comprehensive Audits: Organizations utilizing Digilock, SAG, or similar electronic locker systems, especially those operating in an offline managed capacity, should immediately conduct security audits. This involves understanding the specific models deployed, their firmware versions, and how master keys and user PINs are managed.
  2. Inquire with Vendors: Proactively engage with lock manufacturers regarding known vulnerabilities, patch availability, and recommended security configurations. Given Digilock's reported active work on fixing issues, users should seek updates on these fixes and deployment guidance.
  3. Evaluate Data Sensitivity: Assess the sensitivity of items typically stored in these lockers. If lockers are used for high-value personal belongings, sensitive documents, or critical equipment, the risk profile significantly increases. Organizations might need to consider alternative, higher-security storage solutions or enhance physical surveillance around locker areas.
  4. Implement Strong PIN Policies: If user PINs are the primary access mechanism, enforce strong PIN policies (e.g., minimum length, complexity requirements, disallowing sequential or common numbers). While this might not mitigate firmware extraction, it reduces the risk of brute-force attacks if PINs are later recovered.
  5. Secure Master Key Management: For offline managed systems, the security of master key systems is paramount. Organizations must ensure that master PINs or cards are stored securely, access is strictly limited, and any procedures for generating or resetting them are robust. The ability to extract firmware implies master keys could be compromised, so a multi-layered approach to security is crucial.
  6. Physical Security Layer: While the talk focused on electronic vulnerabilities, good physical security practices remain essential. This includes surveillance, restricted access to the back of lockers (where electronics might be exposed), and regular inspections for tampering.
  7. Consider Online Alternatives (with caution): While offline locks were the focus, online smart locks introduce their own set of network-based vulnerabilities. If transitioning to online systems, ensure they employ robust encryption, secure communication protocols, and regular, secure firmware updates.

For Manufacturers (e.g., Digilock, SAG):

  1. Secure Firmware Development Lifecycle:
  • Secure Boot and Code Signing: Implement secure boot mechanisms to ensure that only authenticated and cryptographically signed firmware can run on the device. This prevents attackers from loading malicious or modified firmware.
  • Disable Debugging Interfaces: Ensure that debugging interfaces like JTAG and SWD are permanently disabled or secured (e.g., password-protected, blown fuses) in production devices to prevent unauthorized firmware extraction.
  • Hardware Security Modules (HSMs): Consider integrating Hardware Security Modules (HSMs) or Secure Elements (SEs) for the secure storage of cryptographic keys, master keys, and other sensitive data. These hardware components are designed to resist physical tampering and extraction.
  1. Protect Sensitive Data at Rest and In Transit:
  • Strong Encryption for PINs and Configurations: All sensitive data, including user PINs, master PINs, and configuration settings, must be stored using strong, modern encryption algorithms (e.g., AES-256) with unique, securely generated keys. Hashing alone is often insufficient, especially for short PINs.
  • Key Management: Implement robust key management practices, ensuring encryption keys are securely generated, stored, and never exposed in plaintext.
  • Memory Protection: Utilize memory protection features offered by microcontrollers to prevent unauthorized access to sensitive memory regions.
  1. Robust Authentication and Anti-Tampering:
  • Brute-Force Protection: Implement robust brute-force protection mechanisms for PIN entry, locking out users after a certain number of incorrect attempts.
  • Tamper Detection: Integrate physical tamper detection mechanisms that can alert administrators or render the device inoperable if physical access attempts are detected.
  1. Responsible Disclosure and Collaboration: Foster a culture of engaging with security researchers rather than resorting to legal threats. A proactive approach to vulnerability disclosure, including bug bounty programs, can significantly improve product security. The initial C&D against Giese and braelynn highlights the negative impact of such responses.
  2. Secure Update Mechanisms: If firmware updates are supported, ensure they are delivered securely, verified cryptographically, and resistant to rollback attacks.

The "Open Sesame" talk serves as a critical warning that the "stuff in your lockers" may not be as secure as assumed. Both users and manufacturers of electronic locker systems must recognize the inherent risks and adopt a more proactive and security-conscious approach to design, deployment, and management.

Key Takeaways

  • Ubiquitous electronic locker systems, even from market leaders like Digilock and SAG, harbor significant security vulnerabilities. The perceived security of these devices often does not match their actual resilience against determined attackers.
  • Offline managed lock systems are a particular area of concern, as vulnerabilities in these systems can be exploited without network interaction, leading to systemic compromise within facilities like gyms, universities, and corporate environments.
  • Insecure handling and storage of PIN numbers and master keys are critical weaknesses. The ability to extract firmware and configuration data directly from the devices implies that these sensitive credentials may be stored unencrypted or with weak protection, making them vulnerable to compromise.
  • Hardware reverse engineering and firmware analysis are effective methods for uncovering these vulnerabilities. Researchers demonstrated methods to extract firmware and configurations, highlighting the need for manufacturers to implement robust hardware-level security measures like disabled debugging interfaces and secure boot.
  • Responsible disclosure is crucial, but can be fraught with challenges. The speakers' experience with a cease and desist order from Digilock underscores the tension between security research and vendor response, emphasizing the need for better industry-wide engagement models.
  • Organizations and manufacturers must prioritize security in electronic access control. Organizations should audit their systems and demand better security from vendors, while manufacturers must adopt a secure development lifecycle, including strong encryption, tamper resistance, and proactive engagement with security researchers.

About the Speaker(s)

Dennis Giese is a distinguished security researcher and hardware hacker with a keen interest in wireless and embedded security and privacy. He is well-known in the security community for his extensive work on various IoT devices, particularly vacuum robots, earning him the moniker "vacuum robot and IoT collector." Giese boasts an impressive collection of over 600-700 devices, including more than 17 vacuum robots, and maintains a website dedicated to documenting their hardware and security aspects. His primary goal often revolves around rooting vacuum robots, but his expertise extends to a wide array of embedded systems, including electronic locks. Giese has a history of publishing research on electronic lock security, dating back over a decade, and this talk is a continuation of that ongoing work.

braelynn is an independent security researcher, making her debut as a speaker at DEF CON with this talk. While she hacks things for the Viven Security Group during her day job, her presentation at DEF CON represents her personal research and views. Her general focus has been in application security and APIs, but she has recently expanded her interests into hardware hacking for fun. This new passion has led her to explore the security of various devices, including robots, cameras, and smart locks. Both Dennis Giese and braelynn were notably targets of a cease and desist order from Digilock in connection with their research, which was withdrawn just prior to their presentation, highlighting the impact and sensitivity of their findings.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk by Giese and braelynn delivers a critical wake-up call regarding the security of ubiquitous electronic locker systems from market leaders like Digilock and SAG. By demonstrating successful hardware reverse engineering and firmware extraction, they expose fundamental flaws in how PINs and master keys are handled in offline managed systems. The research offers high practical impact, revealing that perceived security is often a dangerous illusion, and provides actionable insights for both users and manufacturers to reassess their physical access control security. The vendor's initial cease and desist order only validates the severity and novelty of their findings.

Heather Calloway (CISO) — STRONG ACCEPT

This research on electronic locker vulnerabilities from market leaders like Digilock and SAG is a critical wake-up call for any organization relying on physical access controls. By demonstrating the ease of firmware and configuration extraction, and exposing insecure handling of PINs and master keys in offline systems, the speakers highlight a pervasive and often overlooked institutional risk. This isn't about clever exploits; it's about fundamental design flaws that demand immediate re-evaluation of physical security postures, procurement practices, and vendor accountability, directly impacting business exposure and governance.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage