Hollywood-style heists took on real-world potential on Saturday as hackers at a Def Con gathering showed how to crack safes in full view of security cameras without ever being seen.
Independent computer researchers Eric Van Albert and Zach Banks found a way to pull off the movie-script ploy of intercepting surveillance camera streams and then looping back video of nothing amiss while, ostensibly, safes or vaults are being emptied.
“We set out to create our own device as close to the movies as possible,” Van Albert said as the pair demonstrated their work to an overflow crowd. “To see how possible this kind of attack actually is.”
They spent about US$500 to build a device they could splice into an ethernet cable carrying imagery from surveillance cameras to screens being watched by guards.
The creation, a box of electronics, reroutes incoming video feeds to their computer, where software tends to the job of creating harmless-looking footage that is then used to mask a heist.
A team planning a theft would need to get access to the cable handling surveillance video. After that, a video signal intercept could be controlled from a far-off location, according to the hackers.
Once a safe or vault was emptied and the team is safely away, the device could be removed with a victim being none the wiser.
Or it could be left in place to taunt guards by routing messages to their video screens or even playing back the heist.
“So, now they go and try to chase you down and stop the robbery, while you are 100 miles [161km] away and they are wondering what is going on,” Banks said.
The looping video hack came just hours after researchers for security firm Bishop Fox showed how to hack open a smart safe made by Brinks using a computer thumb drive.
A key to cracking the computerized safe was plugging into a universal serial bus (USB) port built into one side to allow technicians to fix problems, such as it refusing to open.
The safe cracked by Daniel Petro and Oscar Salazar was designed to scan currency to track how much money was put in by merchants and use the Internet to credit bank accounts accordingly.
The safe has touch screen controls that could have also worked for the hack, but opting for the USB port was much faster because a more powerful computer could be used, according to the researchers.
“You need physical access to do the hack,” Petro said. “But you need physical access to carry away the cash, so it is required either way.”
Looping video from surveillance cameras might help with that but it could be too late. Petro and Salazar said they shared their research with Brinks, which came up with a fix.
‘IN A DIFFERENT PLACE’: The envoy first visited Shanghai, where he attended a Chinese basketball playoff match, and is to meet top officials in Beijing tomorrow US Secretary of State Antony Blinken yesterday arrived in China on his second visit in a year as the US ramps up pressure on its rival over its support for Russia while also seeking to manage tensions with Beijing. The US diplomat tomorrow is to meet China’s top brass in Beijing, where he is also expected to plead for restraint as Taiwan inaugurates president-elect William Lai (賴清德), and to raise US concerns on Chinese trade practices. However, Blinken is also seeking to stabilize ties, with tensions between the world’s two largest economies easing since his previous visit in June last year. At the
UNSETTLING IMAGES: The scene took place in front of TV crews covering the Trump trial, with a CNN anchor calling it an ‘emotional and unbelievably disturbing moment’ A man who doused himself in an accelerant and set himself on fire outside the courthouse where former US president Donald Trump is on trial has died, police said yesterday. The New York City Police Department (NYPD) said the man was declared dead by staff at an area hospital. The man was in Collect Pond Park at about 1:30pm on Friday when he took out pamphlets espousing conspiracy theories, tossed them around, then doused himself in an accelerant and set himself on fire, officials and witnesses said. A large number of police officers were nearby when it happened. Some officers and bystanders rushed
Beijing is continuing to commit genocide and crimes against humanity against Uyghurs and other Muslim minorities in its western Xinjiang province, U.S. Secretary of State Antony Blinken said in a report published on Monday, ahead of his planned visit to China this week. The State Department’s annual human rights report, which documents abuses recorded all over the world during the previous calendar year, repeated language from previous years on the treatment of Muslims in Xinjiang, but the publication raises the issue ahead of delicate talks, including on the war in Ukraine and global trade, between the top U.S. diplomat and Chinese
RIVER TRAGEDY: Local fishers and residents helped rescue people after the vessel capsized, while motorbike taxis evacuated some of the injured At least 58 people going to a funeral died after their overloaded river boat capsized in the Central African Republic’s (CAR) capital, Bangui, the head of civil protection said on Saturday. “We were able to extract 58 lifeless bodies,” Thomas Djimasse told Radio Guira. “We don’t know the total number of people who are underwater. According to witnesses and videos on social media, the wooden boat was carrying more than 300 people — some standing and others perched on wooden structures — when it sank on the Mpoko River on Friday. The vessel was heading to the funeral of a village chief in