Two clever students at MIT have built this impressive brute force safe cracker. Their target: a document safe with a S&G 8400 lock. The 8400 is a group 1 manipulation proof lock. Group 1 locks will resist manipulation by an expert for at least 20 hours. These guys used a stepper motor to move the dial and built a custom controller for it. The dial has butterfly knob in the center which must be rotated before and after each combination. That job is handled by a hobby servo. The torque required to open the safe is higher than the stepper motor, so when the optical encoder detects that the motor has stalled you know you’ve found the combination.

  1. lolersticks says:

  2. boo says:

    What i also cant understand, is why dont they say in the article what was in the safe?

  3. steve says:

  4. Matt0817 says:

  5. Aeri says:

  6. DarkAxi0m says:

    ive often wondered how feasable something like this would be, and i know

  7. Mike says:

    @steve (and everyone else)

    The 20 Hr rating includes the time it would take to get into the safe using an oxy/acetylene torch. To rate a safe, they take the quickest time out of using a torch, picking it, using a boroscope, etc…

    So no, an oxy/acetylene torch would not be faster. (Even if you didn’t worry about the documents inside)

  8. Marc says:

    a oxy/acet torch works great until you hit an air pocket or a concrete pocket. i’ve taken many vehicles appart with a torch and even things like mud on frame rails really affect your cutting. a little bit of concrete between a few layers of steel would really really slow you down.

  10. DarkFader says:

    Do they use current limiting for the stepper motor?

  11. AndrewNeo says:

  12. jewelthief says:

    so the article doesn’t list the average number of combinations that are tried, nor does it list the amount of time combination that the machine requires. Is there any way to get these two figures to determine how much longer than the 20 hour minimum this technique requries? (I assume it doesn’t beat the safe’s minimum time rating)

  14. PacketMonkee says:

    If ya’ll go and read the link…

    “The Autodailer successfully detected the correct combination after running for about 21,000 cycles.”


    “…that opened a “manipulation proof”, high security safe in just a few hours.”

  15. steve says:

  16. Fragged says:

  17. ben says:

  18. PacketMonkee says:

  19. pocketbrain says:

  20. steve says:

  21. yes no I this is says:

  22. History says:

  23. rockwalker says:

  24. Smach says:

  25. krip says:

  26. fro0ty says:

  27. Marked says:

    “by Mike
    @steve (and everyone else)

    The 20 Hr rating includes the time it would take to get into the safe using an oxy/acetylene torch.

    The 20 Hr rating does not include using an oxy/acetylene torch or other tools.
    The longest time rating for burglary protection on safes is 60 minutes.

    Manipulation proof locks are more to keep spies out than a burglar.
    The government stoped useing these type of locks 15 years ago.

  28. steve says:

  29. Freiheit says:

    Reducing the keyspace is one of the worst things you can do as a secur-er and one of the best things to do as an attacker.

    Another example is the default password my university uses after a reset. its first inital/last initial/birthday(mmddyyy)/last4 of social or student id.

    The first initial and last initial are part of the email/userid. The birthday can be found in the student directory (myspace and facebook werent popular when I did this test). That leaves a mere 1000 combonations and no retry limit. A simple java app popped it in about 3 minutes (with a delay to make it not look like a DoS).

    For some more fun, dont look at locks. Look at hinges. If the hinge is on the outside of what you’re locking only a proper safe bolt will keep the door on.

  30. pretorious says:

    The article links to some really useful sites. I guess the 20hr rating assumes that the safe is in a secure enough location that someone carrying a torch would be noticed :P Brick of thermite maybe? Considering attacks like this, wouldn’t it be safer to make your combination one of the “forbidden” ones as they outnumber the secure ones?

  31. jewelthief says:


    I did read the article, there is no indication as to if the number of attempted combinations on the one safe they opened is indicative of the average number of combinations that are required.

    additionally, citing “a few” hours is pretty vague.

  32. steve says:

  33. krip says:

  34. oliverjenks says:

  35. Fragged says:

  36. rob says:

  37. 10 says:

  38. joelanders says:

  39. rednerd says:

    FYI, the S&G 8400 is obsolete for high level gov. security. All of the new locks are self powering electric locks. If you misdial the safe it automatically locks you out for an increasing number of minutes.

    Ohh yah, and the 20 man hr rating is for manually getting the combo to the safe. Usually physically busting the safe open is no more than 20 minutes. But heck isn’t it faster and quieter to break into a building with a jack and a pallete and steal the entire safe rather than sit there with a firey (alarmy) torch or a noisey cut off wheel?

  40. babas says:

  41. rob says:

  42. steve says:

  43. steve says:

  44. rob says:

  45. andrew says:

  46. HaX80r says:

  47. Dave says:

  48. 0hn0es says:

  50. Bud says:

