Attacking Classified Safes and Vaults from the Cold War to Now

Deviant Ollam

ShmooCon XX (Final) · Day 2 · Bring It On

Overview

In "Attacking Classified Safes and Vaults from the Cold War to Now," renowned physical security expert Deviant Ollam takes the ShmooCon audience on a captivating journey through the clandestine history and modern realities of breaching secure containers. Drawing from his extensive experience as a Sava certified and GSA certified safe technician, Ollam dissects the evolution of safe vulnerabilities, the ingenious methods developed to exploit them, and the often-surprising defensive strategies employed by governments and individuals alike. This talk is a rare blend of historical espionage, technical deep dive, and practical security advice, revealing that the cat-and-mouse game between those who protect secrets and those who seek to uncover them is far more complex and human than commonly perceived.

Watch on YouTube

Visual summary for Attacking Classified Safes and Vaults from the Cold War to Now by Deviant Ollam
Visual summary for Attacking Classified Safes and Vaults from the Cold War to Now by Deviant Ollam

Key moments

  1. 0:00 Talk introduction and speaker welcome
  2. 2:00 Deviant Ollam's journey in the hacker community
  3. 4:20 Deviant Ollam's lesser-known safe technician expertise
  4. 5:00 How safe technicians open locks by drilling
  5. 6:10 Understanding glass relockers as a safe security feature

Attacking Classified Safes and Vaults from the Cold War to Now

Speakers: Deviant Ollam, Physical Security Consultant and Safe Technician

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=yIutY_X2FcU

Overview

In "Attacking Classified Safes and Vaults from the Cold War to Now," renowned physical security expert Deviant Ollam takes the ShmooCon audience on a captivating journey through the clandestine history and modern realities of breaching secure containers. Drawing from his extensive experience as a Sava certified and GSA certified safe technician, Ollam dissects the evolution of safe vulnerabilities, the ingenious methods developed to exploit them, and the often-surprising defensive strategies employed by governments and individuals alike. This talk is a rare blend of historical espionage, technical deep dive, and practical security advice, revealing that the cat-and-mouse game between those who protect secrets and those who seek to uncover them is far more complex and human than commonly perceived.

Ollam’s presentation challenges conventional wisdom about the robustness of safes, particularly those used by government entities for classified materials. He meticulously illustrates how, for decades, the perceived impenetrability of these containers has been systematically undermined by determined adversaries, from Cold War-era spy agencies to modern-day penetration testers. The talk serves as a critical reminder that physical security is a dynamic, multi-layered discipline, not a static product, and that a deep understanding of both offensive and defensive techniques is essential for protecting sensitive assets in an ever-evolving threat landscape.

The significance of this talk extends beyond the niche world of safe cracking. It offers invaluable insights into threat modeling, the importance of defense-in-depth, and the human factors that often compromise even the most sophisticated security systems. By demystifying the art and science of safe neutralization, Ollam empowers security professionals to think more critically about their own physical security postures, urging a shift from static solutions to adaptable, resilient strategies that account for both historical lessons and emerging threats.

Background

▶ Watch: Talk introduction and speaker welcome (0:00)

Deviant Ollam's journey into the world of physical security began over 25 years ago, attending hacker conventions like Defcon 8. With a collection of over 400 badges and more than 200 stage appearances, he has become a prominent voice in the community, advocating for knowledge sharing and continuous learning. His career is dedicated to physical security, encompassing breaking into buildings, educating others, and even manufacturing tools designed to defeat common physical controls, such as devices to prevent under-door attacks on hotel rooms. Beyond his public persona, Ollam is a professional safe technician, working on vaults, Skiffs (Sensitive Compartmented Information Facilities), and military bases, which provides him with unique insights into the practicalities and vulnerabilities of high-security containers.

The fundamental principle of safe security, as Ollam explains, is not to be impenetrable, but to make an attacker's burden "odious" – requiring excessive time, cost, noise, and effort. For civilian safes, common techniques for gaining entry when a combination is lost or forgotten include drilling into the lock casement and using a borescope to manipulate the internal wheels. Manufacturers have developed countermeasures, such as glass relockers, which are small pieces of tempered glass designed to shatter if drilled, triggering extra bolts to fire and secure the door. Historically, some safes from the 1920s to World War II even contained chemical agents like chloropicrin or phosgene as deterrents, posing significant hazards to technicians who might encounter them without warning.

Surprisingly, many government safes, known as GSA containers, are often less robust than high-end commercial safes. These containers frequently resemble filing cabinets or map and plan containers, designed for a limited amount of forced entry resistance. Their security relies heavily on defense-in-depth, mandating additional layers of protection as per DOD manual 5200, such as armed guards with specific patrol frequencies (e.g., every 2-4 hours) or alarm systems with mandated response times (e.g., 15-30 minutes). Ollam cites the infamous incident of the root key signing ceremony where a Type II map and plan container postal safe had to be drilled open, underscoring the reality that even critical government infrastructure relies on these seemingly humble containers.

Once a safe has been neutralized (opened by force), it typically undergoes a rigorous repair process. For government safes, this adheres to the 809b repair process, which involves packing drilled holes with steel pins, ball bearings, and other ultra-hardening materials to make future attacks significantly more difficult. The exterior is then textured, sanded, and painted to match the authorized GSA container colors: black, parchment, Federal standard gray, or the increasingly rare wood grain. The speaker notes that the wood grain option, once meticulously applied by a single authorized individual, is now dwindling because repairs necessitate repainting in standard gray, removing the aesthetic camouflage. Historically, government containers underwent periodic recertification, requiring inspections that involved removing the lock and checking beneath the dial ring for undocumented entry attempts. However, this process was deemed too laborious and eventually phased out, leading to new challenges in detecting surreptitious attacks.

Key Findings

▶ Watch: Deviant Ollam's journey in the hacker community (2:00)

Ollam's talk reveals several key findings regarding the evolution of safe security and the vulnerabilities that have shaped its development:

  1. Shift in Forced Entry Tactics: As manufacturers introduced hardened steel and ceramic composites (e.g., Mosler's RSOM process) to protect the lock mechanisms from drilling, attackers adapted. The focus shifted to the safe's bolts, which could be defeated by specialized tools that "chop" them off, a process taking approximately 30 minutes. To counter this, modern GSA containers are designed with replaceable drawer heads, simplifying repair after such an attack, acknowledging that the safe itself offers only about 10 minutes of forced entry resistance before relying on external physical security systems.
  1. Non-Destructive Manipulation is a Persistent Threat: Beyond overt forced entry, non-destructive attacks remain a significant concern. Manipulation involves discerning the internal "contact points" of a lock mechanism to deduce the combination without causing damage. Ollam references a past ShmooCon event where an audience member successfully manipulated a safe lock on stage. Another non-destructive method, vibration attacks, was accidentally discovered in the Navy when ship vibrations caused safes to open spontaneously. This led to the development of tools like the Jacob's Jiggler and can still be replicated on cheaper safes using a common palm sander.
  1. Duress Mechanisms and Time Locks: To address scenarios where an authorized user is forced to open a safe, duress mechanisms were developed. These locks incorporate an extra gate on one of the wheels, allowing an "overdrive" combination (e.g., dialing 10 digits past the correct number) to trigger a silent alarm without the attacker's knowledge. While effective for certain scenarios, time locks, which prevent a safe from being opened until a pre-set time, were found to be inadequate during emergencies like the Pearl Harbor attack on a Sunday, highlighting the need for flexible access during critical events.
  1. The Group Classification System: Safe locks are categorized by their resistance to manipulation. Group 1 locks (e.g., the 2937 used in armories) are built to tighter tolerances with specific features to defeat skilled manipulation, making them more expensive. Group 2M locks offer a cheaper alternative, incorporating "false gates" and an "eccentric roller" to complicate manipulation without achieving Group 1 standards.
  1. Radiologic Resistance and Its Defeat: The Cold War introduced the threat of radiologic attacks (X-raying safes). In response, Group 1R locks were developed, featuring plastic wheels (often made of Delrin) to obscure internal mechanisms from X-ray imaging. However, as Ollam details from newly declassified information, adversaries quickly adapted, switching from powerful Cobalt 60 isotopes to lower-energy Iridium 192 and employing scintillation counters to detect subtle changes in radiation through the plastic, effectively defeating this countermeasure.

Technical Deep Dive

▶ Watch: Deviant Ollam's lesser-known safe technician expertise (4:20)

The core of a combination safe lock comprises multiple wheels, each with a gate (a notch). When a combination is dialed, these wheels rotate, and the gates must precisely align under a fence, allowing a lever arm to drop and retract the bolt. Ollam highlights that the small holes often present in these wheels, while intended for balancing, inadvertently create vulnerabilities to vibration attacks. If a safe is subjected to sufficient vibration, these unbalanced wheels can "settle" into alignment, allowing the fence to drop and the safe to open.

The most chilling technical deep dive concerns the radiologic attacks carried out by the Polish "Invisible Team" (Division 9) during the Cold War. This clandestine unit, detailed in Tomasz Iwicki's book "Niewidzialni" (Invisible), operated with astonishing ingenuity and disregard for personal safety. Their methods extended beyond safes, encompassing urban mountaineering to access embassies, bribing baggage handlers to steal and copy keys from incoming Western technicians, and perfecting flaps and seals work to open, read, and reseal diplomatic bags and cables before they reached their intended recipients. A specialized sub-team, Group B, even engaged in "hooliganism" – staging car accidents or public disturbances – to create distractions and buy more time for their comrades operating inside embassies. They used Craftsman shoes (or "museum slippers") to move silently within facilities, and their familiarity with specific buildings was so profound they noted details like "the third step squeaks on the left side." They were also known to brute-force Simplex 900 locks by exploiting insufficient button presses.

Their most advanced technique involved radiographic attacks. Division 9 established a dedicated facility with a Gantry crane and a giant hole in the floor, equipped with radioactive isotopes like Cobalt 60. These isotopes, often acquired through scientific front companies under the guise of materials testing, were used to image the internal mechanisms of safes. The process involved placing the isotope on one side of a safe and photographic film on the other. After exposure, the film was developed, often in makeshift darkrooms like embassy bathrooms, using near-infrared bulbs. An expert, Czesław, could interpret these "ultrasound-like" images to deduce the combination within a few hours.

The handling of these isotopes was alarmingly reckless. They were transported in minimal shielding, causing vehicles to sag under the weight and requiring frequent driver changes due to radiation exposure. On-site, agents would wave isotopes around with pliers to position them, receiving full blasts of radiation. To counter the West's introduction of plastic (e.g., Delrin) wheels in Group 1R locks, designed to obscure X-ray images, the Invisible Team adapted. They switched to Iridium 192, a lower-energy isotope capable of penetrating plastic more effectively. Crucially, they didn't rely on film alone; they used scintillation counters – devices that detect radiation and display it on a dancing needle or digital readout. By slowly moving the Iridium 192 source and observing the counter's fluctuations as it passed over the plastic wheels, they could map the internal positions and deduce combinations, effectively nullifying the plastic wheel defense. Ollam playfully notes that cheap Bluetooth scintillation counters are now available, hinting at future "stupid" experiments.

The talk also delves into the post-Cold War era with the advent of electromechanical locks in the 1990s, specifically the Moss Hamilton X-Series (X-07, X-08, X-09, X-10), designed by Clay Miller. These locks were intended to replace older "Black Label" program locks with more technologically advanced "Red Label" solutions. However, almost immediately upon the X-07's release, Mike Madden, a DOE engineer at Livermore, discovered a reproducible and reliable defeat using a simple bent wire. This vulnerability sparked a fierce industry battle. Sergeant and Greenleaf (S&G), a major competitor, attempted to have the X-07 removed from the Qualified Products List (QPL), but their efforts were thwarted by the formidable political connections of Jimmy Hamilton, a key figure in Moss Hamilton. Madden's research was subsequently classified, unclassified, and eventually shelved, leading him to leave the lab due to immense pressure.

The suppression of this information reached a dramatic climax when Dave McCom, a respected safe lock technician and author, prepared an article detailing the X-07's vulnerability for his trade publication. In an incident reminiscent of the "Cisco gate" controversy at Black Hat, legal threats from Moss Hamilton led to the entire print run of McCom's publication being shredded on a loading dock. Moss Hamilton later purchased the copyright to the story to ensure its permanent suppression. Despite known, repeatable vulnerabilities, over a million X-Series locks were shipped and remain on GSA containers, and the X-07 is still on the QPL to this day, a testament to how political and market forces can sometimes override critical security concerns.

Demo / Proof of Concept

▶ Watch: How safe technicians open locks by drilling (5:00)

While Deviant Ollam's talk was rich with technical explanations and historical anecdotes, it did not feature a live, real-time demonstration or proof of concept during the presentation itself. Instead, Ollam leveraged a wealth of visual aids and referenced past and future demonstrations to illustrate his points.

He showed photographs and diagrams of various safe internal mechanisms, drilling operations, and the use of borescopes to manipulate lock components. He referenced a video he had made previously demonstrating the process of opening a crudded-up safe lock. For non-destructive attacks, he spoke about a past ShmooCon 2 talk where a participant successfully manipulated a safe lock on stage, and explained the mechanics of the duress mechanism with animated diagrams.

Regarding the sophisticated radiologic attacks, Ollam displayed images of the actual Group 1R safe locks with plastic wheels, and the types of radioactive isotopes and scintillation counters that were used by the "Invisible Team." He mentioned that he has collaborators interested in putting some of these Group 1R locks "into a beam" for future testing, suggesting a potential "part two" to his talk that might include a more hands-on demonstration of these techniques. He also brought physical examples of these locks and associated tools to the lockpick village for attendees to examine and discuss after the presentation. Therefore, while no live PoC was conducted during this specific talk, the speaker effectively conveyed the technical principles through detailed explanations and visual evidence, with the promise of future practical demonstrations.

Defensive Implications

▶ Watch: Understanding glass relockers as a safe security feature (6:10)

Deviant Ollam's insights offer critical defensive implications for securing classified materials and personal assets alike, emphasizing that security is a continuous process of evolution and adaptation.

  1. Defense-in-Depth is Paramount: The most significant takeaway is that no single security measure is sufficient. Government safes, despite being GSA-certified, offer limited forced entry resistance (around 10 minutes). Their true security lies in the multi-layered defense provided by armed guards, alarm systems with rapid response times, access control, and robust ID verification. Defenders must ensure all layers are robust and coordinated, as a weakness in one layer can compromise the entire system.
  1. Constant Vigilance Against Evolving Threats: Security postures cannot remain stagnant. As demonstrated by the Cold War-era "Invisible Team" adapting from X-ray to scintillation counter techniques, and Mike Madden's rapid discovery of a defeat for the X-07, adversaries will always seek new ways to bypass existing controls. Defenders must continuously research, test, and update their systems, anticipating and responding to new attack vectors.
  1. Beyond the Container: Focus on Detection and Response: Since safes are designed for time delay rather than absolute impenetrability, the emphasis shifts to detection and response. Effective alarm systems, surveillance, and a well-trained, rapidly deployable response force are crucial. The goal is to detect an attack in progress and intervene before sensitive information can be compromised, rather than relying solely on the safe to withstand a prolonged assault.
  1. Integrity of Repair and Maintenance: The repair process for neutralized safes, particularly the 809b procedure for government containers, is critical. Improper or shoddy repairs (e.g., using putty and Bondo instead of hardened materials) can create new, easily exploitable vulnerabilities. Strict adherence to repair protocols and thorough inspection processes are essential to maintain the safe's original resistance level.
  1. Comprehensive Threat Modeling: Organizations must adopt a holistic approach to threat modeling, considering not only sophisticated destructive attacks but also non-destructive methods like manipulation, vibration attacks, and even the "human factor" (e.g., users setting weak combinations, or being coerced to use duress codes). Threat models should account for historical tactics, which can often be repurposed or inspire new attacks.
  1. Decentralization for Personal Security: For personal assets like wills, testaments, and important documents, Ollam advises against relying on a single, high-security safe. Instead, he advocates for distribution and decentralization – having multiple copies stored in different locations, possibly with trusted friends or family members. This defense-in-depth strategy for personal life mitigates the risk of a single point of failure, whether from theft, fire, or other unforeseen events.
  1. Ethical Considerations and Political Influence: The history of the X-Series locks highlights how political and market pressures can sometimes override known security vulnerabilities, keeping flawed products on the Qualified Products List. Defenders and security researchers must remain vigilant, advocate for transparency, and push for the removal of compromised systems, even when facing significant institutional resistance.

Key Takeaways

  • Physical security is a multi-layered defense challenge: Safes, especially government GSA containers, are designed for time delay rather than absolute impenetrability, relying heavily on external security measures like guards, alarms, and rapid response.
  • Attack techniques constantly evolve: From simple drilling and manipulation to sophisticated Cold War-era radiographic attacks using Cobalt 60 and Iridium 192 isotopes, adversaries continuously innovate to bypass physical controls.
  • Non-destructive methods are a significant threat: Techniques like lock manipulation, vibration attacks (e.g., Jacob's Jiggler), and the use of scintillation counters against plastic-wheeled (Group 1R) locks can compromise safes without leaving obvious signs of forced entry.
  • Political and market forces can undermine security: The case of the Moss Hamilton X-Series locks (X-07), which remained on the Qualified Products List (QPL) despite known, repeatable vulnerabilities and attempted censorship, illustrates how non-technical factors can impact national security.
  • Continuous evolution and robust threat modeling are essential: Defenders must constantly update security postures, conduct thorough threat modeling, and ensure proper repair procedures (like 809b) to counter both historical and emerging attack vectors.
  • Defense-in-depth extends to personal security: For critical personal assets, distributing copies and items across multiple secure locations and trusted individuals offers greater resilience than relying on a single, centralized safe.

About the Speaker(s)

Deviant Ollam is a highly respected and prolific figure in the physical security and hacker communities. With over 25 years of experience attending and speaking at conferences, beginning with Defcon 8, he boasts a collection of over 400 badges and has presented on stage more than 200 times. His journey as a speaker notably began at ShmooCon 1, where he delivered his first accepted talk.

Professionally, Ollam has built a career around breaking into buildings and educating others about physical security vulnerabilities. He owns a company that designs and manufactures specialized tools and equipment used for physical entry, including devices that prevent common attacks like under-door entry. Beyond his work as a security consultant and educator, Deviant Ollam is a certified safe technician, holding both Sava certified and GSA certified credentials. This expertise allows him to work hands-on with high-security containers, vaults, Skiffs, and military bases, providing him with unparalleled insights into the practical aspects of physical security and its inherent weaknesses. He is a passionate advocate for sharing knowledge and fostering community growth within the security world.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk is an absolute masterclass in physical security, blending deep technical insight with fascinating, previously unpublicized historical context. Deviant Ollam, a true practitioner, pulls back the curtain on everything from safe manipulation and drilling techniques to the chilling realities of Cold War espionage, including the use of radiological isotopes by the Polish 'Invisible Team' to defeat classified safes. He concludes with a critical, uncomfortable look at the political suppression of a significant vulnerability in government-used electromechanical locks. This is not just a talk; it's a vital history lesson and a stark reminder of the constant, high-stakes game in securing…

Heather Calloway (CISO) — MUST SEE

Deviant Ollam's session is an indispensable, historically rich examination of physical security vulnerabilities in classified safes and vaults. It transcends mere technical exploits to expose critical governance failures and the profound impact of political and market forces on institutional security posture. This is a masterclass in understanding the absolute necessity of robust defense-in-depth, continuous threat evolution, and effective detection and response, making it essential viewing for any CISO or leader responsible for protecting sensitive assets.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)