[00:02.250 --> 00:03.500] Let's see if we can make this work. [00:03.640 --> 00:07.120] So I'm going to talk about... not talk about lock picking. [00:07.580 --> 00:18.040] So the first kind of disappointment is that if you're here to talk about lock picking, you probably have some time to go down to Starbucks and, you know, play with their wireless network or whatever. [00:20.520 --> 00:21.920] I'm getting old. [00:22.180 --> 00:34.820] I mean, this is one of the properties of, you know, being an old school hacker from the old days, is that as you get older, you discover that hacking your body is a little bit harder than hacking computers. [00:35.100 --> 00:39.480] And in particular, I find that I'm getting less and less good at picking locks. [00:40.740 --> 00:44.560] But to make up for that, I've been thinking about locks for a while. [00:44.720 --> 00:55.000] And one of the things that I do in my day job is I'm a cryptographer and computing systems security person. [00:55.600 --> 01:11.740] And one of the things that I thought about a couple of years ago is the question of can you think about locks locks and physical security using the same mindset that we think about computers and cryptography with? [01:11.910 --> 01:13.970] And the answer is you can. [01:14.210 --> 01:28.480] And in fact, you know, the purpose of my talk is that if you are interested in locks and physical security and you're a computer scientist, you actually have a really big advantage compared with thinking about these things in mechanical terms. [01:28.570 --> 01:32.350] So I'm going to talk about picking locks locks using cryptography. [01:34.320 --> 01:41.960] So in particular, one of the things is, you know, we're computer scientists, right? [01:42.040 --> 01:47.840] The kind of core people here got their introduction to technology through computers. [01:48.070 --> 02:00.850] And the question is why should those of us who are really good at thinking about computers waste our time thinking about these little mechanical, very primitive, you know, kind of 19th century technology. [02:01.650 --> 02:01.700] Technology. [02:01.700 --> 02:05.920] And one of the things is that first of all, you can think about them in the same terms. [02:06.240 --> 02:27.730] And over the last hundred years or so, in particular, since they invented computers, the people responsible for thinking about physical security, the locksmiths and the safe manufacturers and so on, have gone from thinking about these things in very scientific open terms to becoming very insular and private. [02:28.000 --> 02:36.510] And in fact, they've stopped being critical about security in the same way that we think about security. [02:37.010 --> 02:39.040] You know, we tend to be very critical. [02:39.200 --> 02:40.820] We say, well, let's look for the flaw. [02:41.380 --> 02:49.720] The physical security community, by and large, says, well, if somebody finds a flaw, the problem is these people trying to find flaws, not the flaw itself. [02:50.380 --> 02:55.940] So, you know, this idea of independent analysis has kind of gone away from the physical security world. [02:56.610 --> 02:58.640] So we all know what physical security is. [02:58.720 --> 02:59.960] We all know what locks are. [03:01.100 --> 03:06.320] Locks are, you know, there are two major categories of locking mechanisms. [03:06.540 --> 03:13.380] There are combination locks, the kind used on cheap padlocks and to protect safes. [03:13.480 --> 03:15.220] I'm not going to be talking about those here. [03:15.500 --> 03:24.160] They're keyed locks, where you take a physical token and put it in the lock, and the physical token kind of convinces the lock to open in some way. [03:24.300 --> 03:25.820] That's the kind that I'm going to talk about. [03:27.040 --> 03:33.380] Now, you know, it's interesting that even this language is something that's familiar to computer scientists, right? [03:33.440 --> 03:37.080] We talk about keys, cryptographic keys, and things like that. [03:37.240 --> 03:40.700] We talk about people who break into computer systems. [03:41.020 --> 03:42.960] We talk about them being intruders. [03:43.110 --> 03:49.100] These are all, you know, they're not breaking into anything, and they're not intruding on anything in any physical sense. [03:49.320 --> 03:54.180] The language of computer science, again, is taken right out of that physical locksmithing world. [03:55.940 --> 04:00.460] So, it's also possible that we can learn something by studying these things a little more. [04:02.500 --> 04:02.940] Okay. [04:03.320 --> 04:08.500] So, the kind of lock that's most familiar to everybody is called the pin tumbler lock. [04:08.640 --> 04:11.980] Now, this is the picture of the user interface of a pin tumbler lock. [04:12.110 --> 04:13.900] How many of you have ever operated a door? [04:14.520 --> 04:14.900] Okay. [04:15.520 --> 04:25.270] So, this user interface is fairly familiar, even though, you know, on it itself, from the way a computer scientist would look at this, they'd say, this is a terrible user interface. [04:25.440 --> 04:26.680] There are no pop-up windows. [04:27.670 --> 04:28.530] Nothing's labeled. [04:28.740 --> 04:29.420] There's no help. [04:30.060 --> 04:35.590] So, the components of this user interface are really three important parts. [04:35.740 --> 04:41.270] There's the shell, which is the part of the lock that's fixed to the door or the container. [04:41.560 --> 04:46.150] The plug, which is the part that rotates and that operates the locking mechanism. [04:46.330 --> 04:52.320] And the keyway slot, and that's kind of the user interface for the lock where you insert the key. [04:52.520 --> 04:56.300] And if you kind of look through the user interface, you don't really see much. [04:56.440 --> 05:04.820] You might be able to see a little pin there, but you don't get too much of a hint as to what's actually going on inside the lock. [05:05.860 --> 05:09.520] So, what's going on inside is kind of the interesting question. [05:09.970 --> 05:21.270] The boundary between the shell, the part that's fixed to the door, and the plug, the part that rotates, is called the shear line for the shear force that's created. [05:21.460 --> 05:24.680] And that's really where all the action is from a security point of view. [05:25.350 --> 05:28.460] So, what keeps the plug from rotating when there's no key in? [05:28.720 --> 05:40.460] Well, there's a set of pins, or more properly, they're called pin stacks, that protrude out of holes in the shell and go into holes in the plug that keep the plug from rotating. [05:40.720 --> 05:47.400] What the key does is lifts those pins to a particular height where the pin is cut. [05:47.580 --> 05:52.640] And if the key lifts all of the cuts up to the shear line, then the plug can rotate. [05:52.880 --> 05:54.620] So, it's a little mechanical computer. [05:54.680 --> 06:02.080] that tests keys to see whether or not the key knows the secret height to lift each of the pins to. [06:02.360 --> 06:07.520] So, if we took a lock and looked at it from the side and cut it apart with a milling machine. [06:07.680 --> 06:09.080] How many of you have a milling machine? [06:09.760 --> 06:10.240] Okay. [06:10.340 --> 06:15.620] More of you should have a milling machine, particularly if you're interested in physical security hacking. [06:15.800 --> 06:18.760] So, now we're looking at that lock cylinder from the side. [06:18.760 --> 06:21.560] You can see this has six little pin stacks. [06:22.420 --> 06:23.600] Here's the shell. [06:23.740 --> 06:24.520] Here's the plug. [06:24.680 --> 06:26.940] This boundary here is the shear line. [06:27.500 --> 06:28.800] And these are the pins. [06:29.040 --> 06:31.380] And each of these pins, you can see, has a little cut in it. [06:31.600 --> 06:38.900] The key goes in from the front and the little wobbly pieces on the key lift these cuts up. [06:39.000 --> 06:42.820] If it's a correct key, all of them to the shear line and it lets the plug rotate. [06:43.100 --> 06:49.220] So, that's how this little analog mechanical computer works to test keys. [06:50.780 --> 06:55.200] And, you know, again, I'm talking about this in kind of computing terms. [06:55.420 --> 06:59.680] I'm thinking of the function of a lock is as a little key testing machine. [07:00.480 --> 07:01.960] So, how do the keys work? [07:02.120 --> 07:09.400] So, here's some locksmithing terminology if you want to impress a locksmith or more likely make a locksmith really suspicious of your intentions. [07:11.260 --> 07:22.980] The surface of the key where the little notches are cut that lift the pins up to a particular height is called the bidding surface or the bidding of the key. [07:23.540 --> 07:31.420] And the notch height, the height of the key at any particular pin position, is the inverse of the corresponding depth of the cut. [07:31.420 --> 07:37.440] So, a correct key is going to correspond in its height to the height of that cut inside the lock. [07:37.880 --> 07:47.520] So, if you talk about the bidding of the key, that's just a list of all of the heights that the key is cut to at each of the individual pin position. [07:47.920 --> 07:53.500] Now, even though a lock looks kind of like an analog device, in fact, it's really digital. [07:53.500 --> 08:02.520] In the sense that a lock maker is typically going to use a fixed number of different heights that a key might be cut to. [08:02.760 --> 08:08.300] There might be somewhere between five and ten possible heights that a key might be cut to. [08:10.000 --> 08:19.340] And so, you can kind of get a complete description of a key by knowing what kind of lock it fits in and the complete list of the heights that it's been cut to. [08:20.460 --> 08:22.480] So, here's an example of a key. [08:23.080 --> 08:27.880] And this is a key of type SC20 that's conveniently printed on the key. [08:28.240 --> 08:30.060] And here's its bidding surface. [08:30.260 --> 08:31.280] And here are the cuts. [08:31.500 --> 08:35.580] So, the first cut here is cut to this depth, cut number three. [08:35.840 --> 08:37.020] Then it's a little higher. [08:37.140 --> 08:37.980] Here's cut number one. [08:38.080 --> 08:40.420] You can see that's a little higher up than cut number three. [08:40.580 --> 08:43.300] And there's four, a one, a five. [08:43.400 --> 08:44.980] And here's a really deep cut, a nine. [08:45.160 --> 08:48.120] So, this is cut three, one, four, one, five, nine. [08:51.940 --> 08:54.380] And so, a complete description. [08:54.540 --> 09:03.320] You could get a duplicate of this key by walking into a locksmith and saying I need an SC20 key cut to three, one, four, one, five, nine. [09:03.720 --> 09:10.840] And, you know, they would be able to cut it to these specifications and it would work in the same lock as this one. [09:10.840 --> 09:17.000] So, now we've got a kind of concise way of thinking about and describing keys. [09:17.240 --> 09:19.600] And that's going to turn out to be very useful to us later. [09:20.680 --> 09:28.460] So, when we stick that correct key into the lock, that will make all of these cuts line up at the shear line. [09:28.460 --> 09:33.840] And now we can rotate the plug and it will operate the lock. [09:34.020 --> 09:40.400] If you put a wrong key in, it might line some of the cuts up at the shear line. [09:40.560 --> 09:49.200] But as long as at least one is in the wrong place, the lock is going to, from the user's point of view, not operate at all. [09:49.200 --> 10:05.940] So, one of the important properties of these locks is that if the lock is a perfectly designed lock, if there's no mechanical imperfection, a slightly wrong key is the same, from the user's point of view, as a completely wrong key. [10:06.400 --> 10:11.000] And only the exactly correct one will operate the lock at all. [10:11.520 --> 10:15.040] And that turns out not to be true, but I'm going to assume it's true. [10:15.040 --> 10:19.860] You know, I'm going to give the lock maker really the benefit of the doubt and still attack locks. [10:20.960 --> 10:24.640] So, what if you wanted to attack a lock? [10:24.780 --> 10:25.780] How might you think about it? [10:25.940 --> 10:29.220] So, there's some attacks that just bypass the lock completely, right? [10:29.420 --> 10:35.820] So, getting an unauthorized duplicate of a key is an example, where you're not attacking the lock itself, you're just getting a copy of the key. [10:35.980 --> 10:38.020] Or you might bypass the lock, right? [10:38.100 --> 10:43.980] You might go in through the window or stick something under the door to turn the knob from the inside or something like that. [10:43.980 --> 10:50.440] There are other attacks against locks that you might have to worry about, that depend on weaknesses in the lock's implementation. [10:51.160 --> 10:56.280] So, they, you know, depend essentially on the manufacturing process having bugs in it. [10:56.840 --> 11:12.080] So, examples of weaknesses that depend on the lock being manufactured poorly, are things like lock picking, vulnerability to lock picking, or vulnerability to brute force, which in locks means applying brute force. [11:14.300 --> 11:16.780] And in computers, it means something else. [11:17.160 --> 11:20.720] But there are other attacks that are based on design weaknesses. [11:21.080 --> 11:37.140] And what I mean by a design weakness is, even if the lock is manufactured absolutely perfectly, even if physics is really nice to the lock, and prevents, you know, there from being any mechanical imperfections, and anything that's round is actually really round, [11:37.220 --> 11:43.620] and anything that's a particular height is really that height, you're still going to have a flaw. [11:43.860 --> 11:46.820] And that's the kind of attack that I'm going to be focusing on here. [11:49.400 --> 11:50.800] So, let's... okay. [11:51.040 --> 11:53.240] So, one question is, what about brute force? [11:53.520 --> 11:56.740] How secure are locks if you want to try all the keys? [11:57.260 --> 11:59.700] Well, there are two parameters. [12:00.420 --> 12:04.220] One is the number of pins in it, the number of tumblers in the lock. [12:04.480 --> 12:08.640] And the other is the number of different cut depths that it might be used to. [12:08.800 --> 12:19.040] And basically, the maximum number of keys that a lock might have, is the number of cut depths raised to the power of the number of pin stacks. [12:19.780 --> 12:23.060] And that's exponential, in other words, in the number of pin stacks. [12:23.560 --> 12:28.700] And there are a couple of little factors that reduce that slightly, but basically that's pretty close to the number. [12:29.020 --> 12:31.300] So it's exponential in the number of pin stacks. [12:31.460 --> 12:33.620] A computer scientist would say that's great news. [12:34.460 --> 12:39.660] But on the other hand, there aren't really that many pin stacks and that many cut depths. [12:39.840 --> 12:46.300] So the bottom line is that there are somewhere between about 250 and 10 million different keys for a given lock design. [12:46.300 --> 12:54.240] Now, the computer scientist in you would say, yeah, but my Pentium 4 can go through, you know, 10 million keys in, you know, under a second. [12:54.420 --> 12:56.180] So obviously that's insecure. [12:56.400 --> 12:59.720] But remember that you have to try these keys one at a time. [13:00.520 --> 13:05.200] And testing 10 million keys or even only 250 keys is going to take a while. [13:05.340 --> 13:08.560] So that's probably not a very good attack against locks. [13:08.820 --> 13:10.760] So we might have to be a little more clever than that. [13:12.600 --> 13:13.600] So let's see. [13:13.860 --> 13:15.420] Barry will talk about lock picking. [13:20.500 --> 13:23.460] So let's go back to computer science here for a second. [13:24.840 --> 13:35.140] So one of the useful principles from computer science, from computer security, is to separate out thinking about the design from thinking about the implementation. [13:35.320 --> 13:41.580] In other words, you think about what the thing is supposed to be doing and think about whether that's secure. [13:41.940 --> 13:50.260] And if that's not secure, it doesn't matter how good a job the programmer does because even if it's perfect, you're still going to have a weakness. [13:50.620 --> 13:54.220] In fact, if it's imperfect, maybe the imperfection will cancel out the weakness. [13:54.560 --> 14:00.920] So, you know, thinking about the design first is a useful kind of computer science way of thinking about this. [14:01.140 --> 14:15.940] There's another computer science principle, and this is a principle from somewhat advanced cryptography, is to remember that some kinds of security systems are easy to analyze by thinking about some components as what we call oracles. [14:16.340 --> 14:23.680] And basically an oracle is something that you're not allowed to look inside of, but that the attacker is allowed to use through the normal interface. [14:24.120 --> 14:29.000] So there's a user interface, and that will tell you whether you guessed right about something. [14:29.220 --> 14:32.120] And an example of an oracle is like logging in online. [14:32.120 --> 14:35.620] That's an oracle for testing somebody's password, right? [14:35.680 --> 14:41.600] You can log in over the network, try their password, and the computer will act as an oracle, telling you whether or not that was the right password. [14:41.820 --> 14:43.180] Well, a lock is an oracle. [14:43.280 --> 14:45.200] It tells you whether or not you've got the right key. [14:45.680 --> 14:47.920] So maybe we can think about these in those terms. [14:50.040 --> 14:59.560] So a question, as soon as you have a system that has an oracle in it, the computer scientist in you should ask two questions, two really important questions. [14:59.560 --> 15:04.040] First of all, what does it cost the attacker to ask the oracle a question? [15:04.240 --> 15:05.380] How long does it take? [15:05.600 --> 15:08.340] What are the resources for the attacker to ask a question? [15:08.540 --> 15:12.320] So how many questions can you expect the attacker to maybe be able to ask? [15:13.320 --> 15:21.300] And can they structure queries to the oracle in a way that lets them learn something they're not supposed to be able to know, right? [15:21.400 --> 15:31.540] You think the oracle only tells you whether or not one key is valid, but maybe the oracle will tell you something more interesting about the key that you didn't think the attacker should be able to learn. [15:32.520 --> 15:37.380] So here's an example of, you know, again, this is computer science, not locksmithing. [15:37.460 --> 15:40.940] But here's an example of a way of testing whether a password is valid. [15:41.220 --> 15:42.200] So you have a little loop. [15:42.280 --> 15:43.540] This is kind of pseudo C. [15:44.660 --> 15:47.320] So, you know, go up to the length of the password. [15:47.780 --> 15:49.040] Get the next character. [15:49.420 --> 15:51.260] Compare the character to the password. [15:51.260 --> 15:57.060] If the character is the wrong character at that position of the password, return bad password. [15:57.260 --> 16:00.240] Otherwise, get... print out the message bad password. [16:00.400 --> 16:02.240] Otherwise, go and get the next character. [16:02.580 --> 16:04.640] Is this a good way of testing passwords? [16:05.280 --> 16:05.760] No. [16:06.200 --> 16:07.960] Why is it a bad way of testing passwords? [16:09.100 --> 16:10.420] So, what can you do? [16:11.300 --> 16:15.520] Instead of having to test the whole password, you can test the password how? [16:16.880 --> 16:18.380] One character at a time. [16:18.380 --> 16:24.060] So instead of having to submit the whole password, you can find out, is the first character of the password A? [16:24.300 --> 16:25.540] If not, is it B? [16:25.660 --> 16:26.140] Is it C? [16:26.200 --> 16:26.940] Ah, it's C. [16:27.140 --> 16:28.260] What's the next character? [16:28.400 --> 16:29.200] And so on. [16:29.500 --> 16:34.520] So this is a really bad program to write for testing passwords in an online system. [16:34.780 --> 16:39.200] So one question is, you know, what went wrong here? [16:39.400 --> 16:50.200] Well, in more formal terms, right, in kind of mathematical terms, what we'd expect is that the cost of an exhaustive search should be exponential with the length of the password. [16:50.380 --> 16:54.940] It should be the number of characters raised to the power of the length of the password. [16:55.160 --> 17:05.700] But here, it's only the number of characters in the password times the number of possible characters, which is much smaller. [17:06.400 --> 17:24.250] So the standard fix to this problem, right, if, first of all, you'd fire the programmer who wrote that program, you'd fire somebody who would know not to reveal whether the password is right until the person has committed to the entire password, right? [17:24.770 --> 17:27.440] So that's pretty straightforward. [17:27.990 --> 17:29.700] So are locks like this? [17:29.990 --> 17:32.080] Locks are online authentication oracles. [17:32.420 --> 17:33.700] The user presents a key. [17:33.880 --> 17:36.010] The lock reveals if the key is valid or not. [17:36.530 --> 17:40.440] And anyone can ask a question by submitting a key to the lock. [17:40.440 --> 17:48.180] So is it possible to use a small number of queries to reveal information about the key? [17:48.700 --> 17:59.230] And it turns out that at least I can't figure out any obvious way in the standard lock design if the lock is manufactured properly to do that. [17:59.530 --> 18:01.340] The user has to submit the whole key. [18:01.460 --> 18:06.360] You can't submit just part of the key and test some of the tumblers at once in a perfect lock. [18:09.010 --> 18:13.920] But if the lock is perfectly manufactured, you have to test all of the tumblers at once. [18:14.140 --> 18:17.880] And you don't get an answer back that says, ooh, you know that key you sent? [18:17.960 --> 18:19.120] It's really close. [18:20.360 --> 18:26.770] Instead, you get the same answer for a completely wrong key as for an almost right key. [18:26.940 --> 18:34.730] So from this kind of analysis, that perfect lock seems to have the same amount of security that's been advertised. [18:35.140 --> 18:41.290] And this would be good news for lock users who can get these perfect locks that turn out not to actually be made. [18:42.840 --> 18:45.660] But okay, so we've got to move on to something. [18:47.270 --> 18:51.210] Sometimes there's more than one lock that can... more than one key that can operate a lock. [18:51.400 --> 19:00.400] So institutions like to have master keys that can open all of the locks in the system so the janitor doesn't have to walk around with a huge ring of keys. [19:00.880 --> 19:03.640] Now again, here's some locksmithing terminology for you. [19:04.380 --> 19:12.420] The keys that operate just one lock are called change keys for technical locksmith-y reasons. [19:12.680 --> 19:18.710] So if you want to be impressive to a locksmith, you could refer to your key that only opens one lock as a change key. [19:19.250 --> 19:22.550] And then the top master key is the lock that you'd want to get. [19:22.920 --> 19:27.120] That's the lock that opens all of the... the keys that opens all of the locks in the system. [19:27.250 --> 19:37.880] So one question that you might ask is, is it possible to take a change key that change key and convert it into a master key in a perfect lock system? [19:38.100 --> 19:40.360] So let's think about how you might master key locks. [19:40.470 --> 19:42.880] One way you might do it is install two cylinders. [19:43.230 --> 19:45.010] One with the master key, one with the regular key. [19:45.200 --> 19:45.970] No one does that. [19:46.660 --> 19:50.490] There are special lock designs that have more than one shear line. [19:50.600 --> 19:51.400] Nobody uses those. [19:51.710 --> 19:55.100] There are locks that have lots of pins and only uses a subset of them. [19:55.460 --> 19:58.360] Those are required the use of a lot of pins. [19:58.360 --> 20:04.400] But the common technique for master keying is to have more than one cut in each pin position. [20:04.990 --> 20:06.810] And that's what I'm going to talk about here. [20:07.080 --> 20:13.180] So instead, our side view of the lock that's been cut away, instead of one cut, there are two. [20:13.730 --> 20:15.960] One of them corresponds to the change key. [20:16.200 --> 20:17.790] The other is used by the master key. [20:19.880 --> 20:23.990] A key just has to raise one of these two cuts to the shear line. [20:24.940 --> 20:29.010] And the other one will either be above or below. [20:29.200 --> 20:34.710] And in a well-designed system, it's going to be kind of uniformly distributed where it's above and sometimes it will be below. [20:35.620 --> 20:41.730] So the change key is going to lift the change key cuts to a particular height. [20:43.470 --> 20:48.010] So now, I'll talk about some of these issues. [20:48.230 --> 20:58.180] So if you could figure out how to turn your change key that was given to you, say, for your dorm room and for your office into the master key, they might as well just give you the master key. [20:58.270 --> 21:02.860] There's no point in having different keys if it's easy to turn a change key into a master key. [21:03.230 --> 21:06.050] So it would be bad if you can do this. [21:06.050 --> 21:07.550] But it turns out you can. [21:09.340 --> 21:11.680] So let's go back to computer science for a second. [21:11.900 --> 21:15.380] Here's another bad program that somebody wrote. [21:16.440 --> 21:18.270] And it's, again, in pseudo C. [21:18.530 --> 21:23.550] This is for a two-password system where there's a user password and a master password. [21:23.840 --> 21:25.470] And here's the algorithm. [21:25.900 --> 21:30.290] You get the entire password. [21:30.290 --> 21:32.510] So we fixed that first bug. [21:32.510 --> 21:40.180] And now, we go up... and we'll assume the master password and the user password are the same length just to keep the program simple. [21:40.550 --> 21:42.310] We go up to the password length. [21:42.460 --> 21:50.840] If the letter at the particular position is the same as the user password or the master password, we keep going. [21:51.040 --> 21:52.220] Otherwise, we stop. [21:52.580 --> 21:54.940] And at the end, we return good or bad password. [21:55.420 --> 22:01.160] Does this meet the objective of opening with either the user password or the master password? [22:01.980 --> 22:02.740] It does. [22:02.900 --> 22:03.240] Yeah, it does. [22:03.360 --> 22:04.780] But it has another problem. [22:04.980 --> 22:06.740] Does it open with any other passwords? [22:07.260 --> 22:07.740] Yes. [22:08.020 --> 22:12.860] It opens with any password that's a combination of the user password and the master password. [22:13.100 --> 22:25.240] So this might be pretty secure against the outsider, but there are, in fact, a whole lot of passwords, other than the two that it's supposed to accept, that it turns out to accept. [22:25.240 --> 22:40.520] And, in fact, if you know one password, you can very efficiently learn the other, just by changing one character of the password that you know, one at a time, submitting it to the Oracle, and seeing whether or not it works. [22:41.000 --> 22:41.290] Right? [22:41.540 --> 22:46.900] You can see how you would be able to figure out the master password one character at a time. [22:47.680 --> 22:55.160] And that only costs you the size of the alphabet times the number of characters in the password queries to the Oracle. [22:55.440 --> 22:59.200] So, you'd fire the programmer who wrote this program, too. [22:59.740 --> 23:02.420] So, do master keyed locks work this way? [23:02.860 --> 23:03.280] Yes. [23:03.380 --> 23:04.260] So, ah! [23:04.600 --> 23:06.220] Turns out, yes, absolutely. [23:06.860 --> 23:10.780] All you need is a single lock and its change key, plus a few blank keys. [23:11.040 --> 23:12.620] You don't need any special skills. [23:12.620 --> 23:15.290] You can be as old as I am and still have this work. [23:15.290 --> 23:19.790] You don't need any precise hand movement like Bari has. [23:20.960 --> 23:28.740] And you just think of the lock as this password system that's been badly designed, so it checks the passwords one at a time independently. [23:29.220 --> 23:31.480] And the algorithm is very simple. [23:31.860 --> 23:32.940] P is the number of pins. [23:33.100 --> 23:34.100] D is the number of depths. [23:34.420 --> 23:46.760] And for each pin, and for each depth, prepare a test key that's the same as your change key, in every position except the one you want to find the master key for. [23:47.540 --> 23:50.900] Submit it to the Oracle and find out whether or not it turns. [23:51.620 --> 23:56.500] If it doesn't turn, you know that the depth you cut that for was not on the master key. [23:56.640 --> 24:04.240] If it does turn, then you've found the master height at that particular position. [24:04.240 --> 24:14.420] You can optimize this to only consume the number of blanks as tumblers by reusing blanks in a slightly cleverer way. [24:15.300 --> 24:22.440] And the bottom line is that for $2 or less, you can compromise virtually any master key system this way. [24:22.600 --> 24:25.740] You can cut the blanks with either a file or a key cutting machine. [24:25.740 --> 24:29.680] You can get blanks for most locks pretty readily available. [24:29.980 --> 24:31.180] You know, the Internet is your friend. [24:32.360 --> 24:34.700] And yeah, it really actually works. [24:35.260 --> 24:41.740] Now, the important thing here is, first of all, this attack is against abstract locks. [24:42.140 --> 24:46.040] Making the lock more precise doesn't fix this. [24:46.280 --> 24:49.960] It's a problem with the design, not the problem with the manufacturer. [24:51.460 --> 25:01.480] So, the countermeasures to this have to either make it impossible for the attacker to get blank keys, which is pretty hard because blank keys are just pieces of metal. [25:02.700 --> 25:10.040] Or, fix the basic weakness that a lock shouldn't open with a combination of cuts for the change key and the master key. [25:10.200 --> 25:13.340] And this standard lock design just doesn't work that way. [25:17.090 --> 25:24.200] So, bottom line is that cryptography can be applied to locks fairly easily. [25:24.960 --> 25:26.740] Can I take about two more minutes? [25:26.920 --> 25:27.020] Sure. [25:27.140 --> 25:27.680] Okay, great. [25:28.580 --> 25:34.550] And, you know, it turns out computer security isn't very successful at protecting computers, as we can see. [25:34.700 --> 25:36.020] There are viruses all over the place. [25:36.120 --> 25:37.310] But it's good for something. [25:37.360 --> 25:39.180] You can at least use it to analyze locks. [25:40.480 --> 25:42.180] So, you know, that makes me feel better. [25:42.180 --> 25:43.780] I'm a computer security person. [25:43.980 --> 25:47.120] I've been a horrible, miserable failure at protecting computer systems. [25:47.260 --> 25:50.580] But at least I can get a job as a locksmith. [25:53.400 --> 25:56.660] Now, I just want to talk for a second about culture clash. [25:57.310 --> 26:03.980] You know, computer security people have traditionally, you know, kind of thought about openness as being really important. [26:04.500 --> 26:07.810] Talking about vulnerabilities is a good way to eliminate them. [26:08.180 --> 26:10.540] That's really in our blood, right? [26:11.280 --> 26:14.100] The scientific method kind of requires that. [26:14.540 --> 26:19.860] You know, you're kind of arguing with Isaac Newton if you say that you shouldn't talk about vulnerabilities. [26:21.500 --> 26:25.900] And basically, this acknowledges that we don't know everything there is to know about security. [26:25.900 --> 26:27.140] We've got a lot more to learn. [26:27.280 --> 26:29.400] The only way we're going to learn it is by being open. [26:30.360 --> 26:38.960] The human scale world, like, for example, locks or physical security or anti-terrorism, often doesn't view things this way. [26:39.550 --> 26:41.640] Security isn't really viewed as a research topic. [26:41.780 --> 26:43.740] It's just viewed as a way of keeping out bad guys. [26:43.920 --> 26:48.460] And people intuitively think that we already know everything there is to know. [26:48.580 --> 26:52.100] The problem is, you know, people just shouldn't think about how to do these things. [26:52.100 --> 26:55.000] Why would somebody think about how to attack systems? [26:55.480 --> 26:57.790] And, you know, you probably get that all the time. [26:57.920 --> 26:58.780] Why are you thinking about this? [26:58.860 --> 26:59.810] You must be a bad guy. [27:00.420 --> 27:06.310] And it's interesting that mechanical locksmithing used to be the way computer scientists thought. [27:07.040 --> 27:10.040] And have kind of slipped into a dark ages. [27:10.460 --> 27:11.780] So I'm going to read you this quote. [27:11.920 --> 27:12.980] It's impossible to read there. [27:13.240 --> 27:14.700] Alfred Hobbes, he's my hero. [27:14.860 --> 27:16.280] He deserves to be your hero. [27:16.860 --> 27:17.980] He was an American. [27:17.980 --> 27:22.880] He went to London and broke all of the major lock systems in use at the time. [27:22.980 --> 27:24.660] He figured out how to pick all these locks. [27:25.140 --> 27:27.760] And he picked the Brahma lock. [27:28.000 --> 27:33.700] That was the thing that really made him famous, which was this unpickable lock that for 50 years they'd had a challenge. [27:33.700 --> 27:36.900] You could win 200 guineas if you could pick the Brahma lock. [27:37.160 --> 27:40.200] 50 years later he went to London and he did it in a couple of days. [27:40.920 --> 27:43.660] And then he picked the Yale lock and the Chubb lock. [27:43.860 --> 27:46.340] And these are all the major lock designs that are still used. [27:46.520 --> 27:48.640] So nobody listened to Hobbes, it turned out. [27:50.280 --> 27:54.000] So he wrote his memoirs and he described how he did all of these things. [27:54.440 --> 28:00.980] And in the preface, he and Tomlinson, the editor of his memoirs, wrote this very eloquent thing. [28:00.980 --> 28:03.540] It could have been written today except for the fact that it's well written. [28:06.020 --> 28:11.440] A commercial and in some respects social doubt has been started within the last year or two. [28:11.600 --> 28:15.840] Whether or not it is right to discuss so openly the security or insecurity of locks. [28:16.420 --> 28:27.700] Many well-meaning persons suppose that the discussion respecting the means for baffling the supposed safety of locks offers a premium for dishonesty by showing others how to be dishonest. [28:27.700 --> 28:29.360] This is a fallacy. [28:30.000 --> 28:36.400] Rogues are very keen in their profession and already know much more than we can teach them, respecting their several kinds of roguery. [28:37.100 --> 28:42.260] Rogues knew a good deal about lockpicking long before locksmiths discussed it among themselves as they've lately done. [28:42.540 --> 28:53.540] If a lock, let it have been made in whatever country or by whatever maker, is not so invaluable as it has hitherto been deemed to be, surely it is in the interest of honest persons to know this fact. [28:53.700 --> 28:58.240] Because the dishonest are tolerably certain to apply the knowledge practically. [28:58.700 --> 29:04.380] And the spread of the knowledge is necessary to give fair play to those who might suffer by ignorance. [29:04.740 --> 29:12.840] It cannot be to earnestly urge that an acquaintance with real facts will in the end be better for all parties. [29:12.840 --> 29:16.240] Now, you know, that's a pretty modern view, right? [29:16.360 --> 29:17.620] And this is 1853. [29:18.460 --> 29:22.360] Now, it turns out that Hobbes was preaching to the choir. [29:22.600 --> 29:26.600] The community that he was in understood that you had to talk about these things. [29:26.620 --> 29:29.680] And he was really just playing with you. [29:30.180 --> 29:34.500] And, you know, giving people ammunition for thinking about what they already knew to be right. [29:34.500 --> 29:39.490] So this was the mainstream of locksmithing openness in 1853. [29:40.440 --> 29:43.580] Somewhere in a hundred years, things just took a turn. [29:44.160 --> 29:49.900] So I'm going to give you a quote from another book, the standard book on opening safes. [29:50.050 --> 29:58.550] The standard book on safe cracking called The Art of Manipulation, written by Lentz and Kenton, published in, a hundred years later, 1953. [29:59.070 --> 30:02.200] And it has a preface, too, in which they talk about openness. [30:02.700 --> 30:12.640] So they say at the beginning of their book, it is extremely important that the information contained in this book be faithfully guarded, so as not to fall into the hands of undesirables. [30:12.840 --> 30:14.080] That, by the way, is you. [30:15.390 --> 30:23.780] We also suggest after you become proficient in the art of manipulation, you destroy this book completely, so as to protect yourself and our craft. [30:24.900 --> 30:27.780] By the way, I got my copy of this out of the library. [30:27.780 --> 30:28.440] So... [30:29.280 --> 30:30.280] What can you do? [30:30.500 --> 30:37.020] Now, 50 years after that, in 2003, a fellow by the name of Billy B. [30:37.200 --> 30:54.400] Edwards, a prominent locksmith expert in master keying, wrote in a guest editorial in the National Locksmith, which I think he didn't realize I subscribed to, a publication for locksmiths, Blaze's master keying paper, the stuff I just described, shouldn't have been published, [30:54.400 --> 30:59.240] because the only people that will educate are the dishonest who will use it to compromise security. [30:59.860 --> 31:01.480] Locksmiths don't have to be surreptitious. [31:01.860 --> 31:07.020] No, we can't call him a moron, because he is obviously intelligent. [31:07.660 --> 31:10.860] After all, he did grasp the concepts of master keying. [31:11.220 --> 31:15.580] We can see, however, that he is an inexperienced amateur when it comes to physical security. [31:15.580 --> 31:20.000] In his computerized world, it's a simple thing to fix a security problem. [31:20.200 --> 31:21.680] You just load new software. [31:23.220 --> 31:31.680] So, the bottom line is that the locksmithing community and the computer science community seem to have different views on the subject of openness. [31:32.160 --> 31:38.580] But, in fact, some of the tools of computer science are probably very useful for thinking about locks. [31:38.580 --> 31:46.200] And with that, I'd like to turn it over to the second most dangerous person I know, Mark Tobias. [31:51.670 --> 31:52.970] Whoa, whoa, whoa, whoa, whoa. [31:53.330 --> 31:54.030] Yeah, wait, wait, wait. [31:54.270 --> 31:55.230] We just had a... [31:55.230 --> 31:58.410] He's loading. [31:58.950 --> 31:59.170] All right. [32:00.110 --> 32:00.250] Yeah. [32:03.120 --> 32:03.380] Problem. [32:03.880 --> 32:04.640] Just going to... [32:04.980 --> 32:06.460] Just a minute, I've got a problem here. [32:06.960 --> 32:08.340] Because it's coming off the... [32:08.340 --> 32:09.100] What did I say here? [32:09.540 --> 32:09.680] Yeah. [32:20.160 --> 32:21.120] It's, um... [32:21.120 --> 32:21.880] It should be... [32:21.880 --> 32:23.400] Yeah, that was the... [32:23.400 --> 32:24.500] You got something... [32:24.500 --> 32:25.480] We can... [32:25.480 --> 32:26.520] No, not for right now. [32:28.680 --> 32:29.120] Um... [32:29.120 --> 32:29.740] Do you have a... [32:29.740 --> 32:30.900] Law of some sort? [32:31.040 --> 32:31.240] No. [32:31.940 --> 32:32.140] Um... [32:32.140 --> 32:34.200] The woman with the baby probably has one, yeah. [32:34.460 --> 32:36.940] Does anybody have an absorbent piece of material? [32:37.780 --> 32:38.060] Or... [32:40.060 --> 32:41.220] Like a paper towel. [32:41.380 --> 32:42.000] Or a diaper. [32:42.360 --> 32:42.580] Or a diaper. [32:42.740 --> 32:44.740] Yeah, we just spilled some water here. [32:46.460 --> 32:47.660] Keyboards absorb water. [32:48.260 --> 32:48.700] Yeah. [32:48.700 --> 32:50.160] Yeah, so do computers. [32:50.560 --> 32:51.260] Hey, hey, hey, hey. [32:54.240 --> 32:54.840] Thank you. [32:54.960 --> 32:55.040] Thank you. [32:55.040 --> 32:55.340] Very kind. [32:55.640 --> 32:56.120] Thank you. [32:56.520 --> 32:56.860] Ah, great. [32:57.040 --> 32:57.180] Thanks. [32:57.300 --> 32:57.920] Thanks very much. [32:58.360 --> 32:58.820] There we go. [32:59.180 --> 32:59.280] Thanks. [32:59.740 --> 33:00.140] Okay. [33:00.320 --> 33:00.940] Yeah, we're all right. [33:00.940 --> 33:01.140] Probably enough. [33:01.340 --> 33:01.440] Yeah. [33:02.760 --> 33:03.160] Okay. [33:03.400 --> 33:05.460] Let's make the overhead work. [33:05.780 --> 33:06.660] So it should be... [33:06.660 --> 33:07.180] It should be up. [33:07.480 --> 33:07.720] Yeah. [33:08.080 --> 33:08.260] Yeah. [33:28.500 --> 33:30.680] What do you want to do here? [33:31.060 --> 33:31.680] Function F7 again. [33:32.160 --> 33:33.020] Function F7? [33:36.220 --> 33:36.620] Wait. [33:36.840 --> 33:37.860] It sometimes takes a second. [33:38.780 --> 33:39.220] Ah, look. [33:39.380 --> 33:39.660] Something... [33:39.660 --> 33:39.740] Yeah. [33:39.800 --> 33:40.160] There you go. [33:40.200 --> 33:40.620] There we go. [33:40.820 --> 33:40.900] Okay. [33:41.660 --> 33:42.020] Okay. [33:42.800 --> 33:43.680] Well, good morning. [33:43.980 --> 33:47.000] We're going to talk about some reality now rather than more theory. [33:47.540 --> 33:47.820] Um... [33:47.820 --> 33:49.060] I deal in the real world. [33:50.260 --> 33:50.660] Um... [33:50.660 --> 33:51.420] Matt more... [33:51.420 --> 33:53.900] Matt more deals than the theoretical world. [33:54.400 --> 33:54.700] Um... [33:54.700 --> 33:55.780] And so the two have merged. [33:55.880 --> 33:59.940] And some of the slides that I've got are going to be duplicates of his so I'll run through them pretty fast. [34:00.940 --> 34:01.540] Um... [34:01.540 --> 34:04.040] I want to talk about, um... [34:04.040 --> 34:08.660] More master keying but in somewhat in more of the real world. [34:09.000 --> 34:09.520] Um... [34:09.520 --> 34:12.220] My background, very briefly, I'm a lawyer. [34:12.460 --> 34:22.400] I specialize in, uh, fraud investigations and bypass of high security locks for a variety of clients and analyzing, uh, locks and locking systems for bypass. [34:23.700 --> 34:24.300] Um... [34:24.300 --> 34:29.920] I'm the guy that wrote the eight pound book that's great for, uh, pressing flowers and nighttime reading. [34:30.640 --> 34:31.200] Uh... [34:31.200 --> 34:39.640] And also the multi... the multimedia edition of that book, uh, which is up to 14 volumes of CD and about 60 hours of audio and video. [34:40.420 --> 34:43.640] And, uh, which... part of it's available. [34:44.140 --> 34:46.140] Barry, uh, contacted me. [34:46.260 --> 34:51.320] I see Barry, uh, sort of frequently in Amsterdam for dinner, um, when I'm in Europe. [34:51.320 --> 35:03.380] And, uh, we decided that for you guys that are getting into lock picking, um, we would run a special, um, set of picks to commemorate the conference here. [35:03.560 --> 35:07.900] And so we did that and, uh, actually some of those are still left. [35:08.260 --> 35:14.780] Um, if you really want to get into it, um, this is... this is how you start and... and with some reference materials. [35:14.780 --> 35:21.200] Um, so I'm gonna talk about a variety of issues, uh, in the very few minutes left to me. [35:22.040 --> 35:24.780] Um, and... no... [35:25.340 --> 35:25.780] Thank you. [35:26.380 --> 35:32.940] Um, and so first I'm gonna talk about Master King and security issues and the reality side of this. [35:33.560 --> 35:39.160] Um, Matt caused quite a stir in the industry, um, that I'm sort of part of. [35:39.160 --> 35:46.720] Um, uh, in January of 03 in the New York Times, um, when he was with AT&T Labs. [35:47.100 --> 35:55.640] Um, in exposing a vulnerability in Master Key Systems that, um, some locksmiths were aware of. [35:55.980 --> 35:58.660] Almost none of their clients were aware of. [35:58.760 --> 36:05.900] And from the legal standpoint, um, my interest in it as a lawyer is the liability issue to start with. [36:05.900 --> 36:15.820] And the problem is that virtually every building in the world, other than some military installations, are Master Keyed. [36:16.000 --> 36:22.860] And generally, there's a top-level Master Key that we abbreviate TMK. [36:22.980 --> 36:26.880] Um, that will open every lock in the facility. [36:27.240 --> 36:35.160] And so, obviously, if you can break that top-level Master Key, you own the facility. [36:35.980 --> 36:37.600] And therein lies the problem. [36:37.740 --> 36:43.900] And I also have to tell you guys, um, I was listening to the, uh, the panel before us on phone phreaking. [36:44.420 --> 36:50.300] And, uh, I can tell you if they had computers when I was in high school and college, I would still be locked up. [36:51.960 --> 36:52.360] Uh... [36:53.040 --> 36:59.740] And also, I can tell you that because the statute of limitations is run on phone phreaking, I can admit to doing a lot of it. [37:01.040 --> 37:05.020] Especially when Teltone came out with their chip to make it really easy to do. [37:05.860 --> 37:12.540] Uh, and as a matter of fact, uh, a case I was working about ten years ago, one of the email addresses I have. [37:12.660 --> 37:15.040] And I have two of them that you guys can write down. [37:15.360 --> 37:20.120] And if you have any feedback or information that you'd like to share with me, it'd be great. [37:20.120 --> 37:25.560] Uh, my primary address is MWTobias at security.org. [37:26.040 --> 37:30.460] And my second one is Multifreak at security.org. [37:30.760 --> 37:34.420] And for you guys that have been around, you know exactly what that means. [37:34.420 --> 37:42.360] Okay, so master keying, um, we're gonna talk about master keying, high security locks. [37:42.660 --> 37:53.740] Uh, there are two of them in the world that can essentially, um, combat the issue that Matt Blaze brought to a blazing public light. [37:54.120 --> 38:01.480] And much to everybody's chagrin in the locksmith profession, um, they all actually think this is still secret information. [38:01.480 --> 38:03.440] They obviously haven't gone on the Internet. [38:04.480 --> 38:08.440] And, uh, there, there essentially are no secrets in the industry. [38:09.360 --> 38:15.960] Um, and there are ways of protecting master key systems that I'll briefly touch on this morning. [38:16.780 --> 38:20.740] Um, and, uh, and two in particular. [38:21.400 --> 38:25.840] I'll also touch on a couple issues that, uh, you probably would find of interest. [38:26.180 --> 38:32.480] There's been a lot of talk lately about the 999 or the bump key or the percussion key, as they're calling it in the UK. [38:32.980 --> 38:36.560] And this is a method that was developed in Denmark. [38:36.900 --> 38:45.200] Um, that will allow you to open a lot of cylinders instantly by wrapping on them with a specially designed key that you insert into the lock. [38:45.400 --> 38:47.620] And by the way, uh, Matt mentioned... [38:47.620 --> 38:52.360] Oh, okay, so Barry's got one to show you, which actually we talked about last night. [38:52.360 --> 38:56.620] And, and so I had forgotten at this point, but it's very simple. [38:56.620 --> 39:00.680] And there's a video that you can look at offline, uh, after the panel, if you'd like. [39:00.800 --> 39:02.500] It was done by Hiles Miles... [39:02.500 --> 39:11.780] Um, Hans Miles Heda in Denmark that I shot as part of my CD-ROM series that shows in about two minutes how to go click, click, and the cylinder's open. [39:11.780 --> 39:14.400] And I'm sure Barry will demonstrate that for you. [39:14.500 --> 39:15.480] It's actually very clever. [39:15.780 --> 39:23.840] Um, and it's based on the old impact, uh, picking principle, uh, with a pick gun or a snap gun that I'll also show you very briefly. [39:24.600 --> 39:35.500] Um, also, I wanted to make a note about the Schlage Everest lock, which is a, uh, very clever lock that Schlage sort of represents as a high-security cylinder. [39:35.500 --> 39:37.260] Um, it is not. [39:37.660 --> 39:47.820] And, uh, their, their lawyers sent me the appropriate threatening letter, um, because I was teaching at a LOA last summer in a covert entry course and they didn't like it. [39:48.140 --> 39:56.600] And I suggested that maybe they get John Ashcroft to modify the PATRIOT Act to prevent, uh, teaching or documentation of lock picking or bypass. [39:56.920 --> 40:02.520] And they, they didn't find that too humorous and ended up sending me a apology letter. [40:02.520 --> 40:07.000] Um, and so I'm, um, helping them out a little bit. [40:07.660 --> 40:16.600] And, but anyway, the Schlage Everest lock and, um, actually, uh, I think Matt brought a, uh, dome lock that's, uh, based on the same principle. [40:17.380 --> 40:21.060] Um, you probably, you won't be able to see this, but Barry, why don't you hold that up? [40:21.480 --> 40:23.940] Okay, but maybe we, we, we could try to... [40:23.940 --> 40:24.600] We can show it. [40:24.800 --> 40:27.380] Basically, the bottom line is, and I'll show you a macro photograph. [40:27.380 --> 40:34.540] There's an undercut on the, uh, key that makes the key blank extremely difficult to replicate. [40:35.140 --> 40:36.880] Uh, you can't do it in a normal key machine. [40:37.060 --> 40:38.760] Basically, the blanks come from the factory. [40:39.080 --> 40:41.400] Also, I'll make a couple impressioning notes. [40:41.540 --> 40:56.300] And the reason for that is that one of the conference participants that's registered on our website came up to me yesterday and presented me with the, uh, computer lock made by Kensington, which is probably the best one in the country, and probably also the most effective. [40:57.580 --> 41:02.320] Um, and, uh, my newfound friends at Kensington, I'm sure I'll be hearing from them. [41:02.940 --> 41:07.800] Um, this, uh, this is an axial pin tumbler lock that you're all familiar with. [41:08.280 --> 41:13.640] Um, unfortunately, you can stick a ballpoint pen into it and impression it in about 10 seconds and open it. [41:13.640 --> 41:25.180] Um, and, uh, so I'll show you the other side of that is a foil impressioning system that was developed by John Fall, one of my associates in England, uh, who's probably the top guy in the world. [41:25.360 --> 41:29.840] But it turns out that a little paper mate pen, you just stick it in the key way and go click, click, and it's open. [41:30.460 --> 41:49.960] And, and finally, if, if at the end of this panel we have any time, um, I'd like to summarize for you a burglary investigation that I was privileged to review a part of in Antwerp a few months ago in Belgium involving the theft of a hundred million dollars worth of diamonds, [41:50.320 --> 41:53.020] essentially none of which have been recovered. [41:53.460 --> 41:56.120] Seven career criminals from Italy were involved. [41:56.340 --> 42:09.760] Um, the burglary occurred essentially out of, uh, negligence and aptness and stupidity on the part of building owners, um, at the diamond exchange in Antwerp where 85% of the world's uncut diamonds are processed. [42:10.140 --> 42:22.620] Uh, they sent me one of their threatening letters a couple months ago, um, telling me that if I represented that they were in any way negligent that they would go after me and I sent them an appropriate letter in response. [42:23.360 --> 42:28.740] And, um, the, the lawyers have the right to do that. [42:28.740 --> 42:36.280] And, uh, the bottom line is, one, I haven't heard from them, and two, they haven't recovered the hundred million dollars in diamonds. [42:36.620 --> 42:38.500] And so, with that, let's move on. [42:38.720 --> 42:46.760] Okay, Master King Theory, and as I said, um, some of these slides are the same as Matt used, so I, I won't go through them, uh, in detail. [42:47.260 --> 42:51.240] We're basically talking about conventional pin tumbler locks. [42:51.420 --> 42:55.980] There are essentially two kinds of basic pin tumbler locks. [42:55.980 --> 43:00.940] Um, one uses conventional keys, as Matt showed you. [43:01.200 --> 43:08.060] The other type use a master keying system called positional master keying, and Barry's got some of these. [43:08.520 --> 43:10.260] Uh, basically they're dimple locks. [43:10.440 --> 43:26.820] And dimple locks vastly differ from conventional pin tumbler locks, um, in that they're, the, the secret to opening a dimple lock is, A, to know where the dimples are, because they're moved around as far as tumbler positions. [43:27.100 --> 43:34.180] And they're pin tumbler locks, but they, the, the keys have holes in them, rather than a normal bidding surface. [43:34.640 --> 43:37.520] And so, we, we, and Barry is showing you one. [43:37.760 --> 43:41.860] And so, there's a number of high security manufacturers that make these. [43:41.860 --> 43:54.100] Uh, however, most of them can be, uh, opened and decoded rather instantly with a foil impressioning system, where the foil actually impressions the lock. [43:54.900 --> 44:08.380] Um, and there's, there's several very high tech tools to do this, but the bottom line is, a popsicle stick soaked in alcohol, or a, a little carrier with aluminum foil, with special aluminum foil will open them. [44:08.380 --> 44:14.640] Uh, so, Matt showed this, uh, basically inside the pin tumbler lock, we have what are called pin stacks. [44:14.980 --> 44:20.820] And there's a pin stack comprised of a top pin, a bottom pin, uh, in this lock. [44:21.000 --> 44:22.960] This lock is not master keyed. [44:23.080 --> 44:28.200] And so, we only have what's called one shear line. [44:28.380 --> 44:39.400] That is when all the bottom pins line up, um, at the edge or circumference, uh, the inner circumference of the plug, then the plug can rotate. [44:39.700 --> 44:45.340] So, what we're talking about is a shear line, as you can see here, lined up and it can rotate. [44:45.780 --> 44:53.920] When the correct key is inserted as shown, the shear line is lined up, so the plug forms a continuous surface and it can rotate. [44:54.240 --> 45:05.060] When the incorrect key is inserted, then one or more pin tumblers, and all it takes is a couple thousandths of an inch difference, uh, the plug is blocked from rotation. [45:05.060 --> 45:11.120] So, here, this is... and all of these photographs, by the way, are contained, um, in my book and CD. [45:11.340 --> 45:13.780] There's a lot of information that we're all covering today. [45:14.060 --> 45:18.080] If you want to do more reading about it, uh, that's one of the places to go. [45:18.720 --> 45:24.000] Um, so, this is a plug that cannot turn, as you can see, because the blue top pin is blocking it. [45:24.960 --> 45:32.380] Here, the pin is... the pins are at shear lines, so they're split between what's indicated by the red pin and the blue pin. [45:32.380 --> 45:34.380] And there, the plug is turned. [45:34.960 --> 45:37.700] Okay, so, master keying, why is it important? [45:37.980 --> 45:45.100] Because every large facility is master keyed, and a compromise of the top-level master key, you'll own the facility. [45:45.560 --> 45:50.100] Basically, to compromise a master key system, there's no risk involved. [45:50.320 --> 45:51.780] You get all the locks. [45:51.980 --> 45:54.060] It's absolute access. [45:54.500 --> 45:56.180] There's no high-tech involved. [45:56.180 --> 45:59.080] There's no forensic trace that can be found. [45:59.480 --> 46:02.520] And there's no time limit to break the system. [46:02.820 --> 46:04.400] So, what is master keying? [46:04.500 --> 46:07.980] As Matt told you, we have change keys, and we have a top-level master key. [46:08.200 --> 46:11.460] We also have what's called incidental master keys. [46:11.820 --> 46:22.480] And incidental master keys are composite combinations of pins, bottom pins and middle pins, that'll also allow that lock to be open. [46:23.380 --> 46:25.280] So, master key security design. [46:25.420 --> 46:27.740] What makes a master key system secure? [46:28.220 --> 46:32.980] Well, essentially, it's how difficult is the blank to replicate. [46:33.280 --> 46:35.680] That's really what it all comes down to. [46:36.000 --> 46:43.660] The rest of this, it's okay, but the bottom line is, if you can't replicate the blank, you're not gonna break the system. [46:45.080 --> 46:48.240] A number of different locks can be master keyed. [46:48.420 --> 46:51.540] There's lever locks, wafer locks, and pin tumbler locks. [46:51.680 --> 46:59.260] But the bottom line is, we're talking about pin tumbler locks because there's billions of them in the world, and that's what's really out there. [46:59.520 --> 47:07.380] So, again, in the master keyed environment, we have two lower pins that comprise the pin stack plus a top pin. [47:07.380 --> 47:15.860] And so, what we're doing is, we're creating a composite, and then we're sampling the cylinder at each position. [47:16.280 --> 47:25.560] So, what I've called in my book, this process, is called extrapolation of the top-level master key. [47:25.840 --> 47:35.420] And basically, what we're doing, as Matt told you, is we're testing a sample lock, which is not going to be your target lock. [47:35.420 --> 47:42.020] We're testing that lock for every pin segment in every position. [47:42.360 --> 47:47.240] It's simple, it's easy, there's been a lot of publicity about it. [47:47.360 --> 47:50.140] It is a serious threat to security. [47:50.400 --> 47:55.240] And as Matt said, there's no special tools involved, no expertise is really required. [47:55.520 --> 47:58.400] All you need is a file, and it's basically covert. [47:59.040 --> 48:10.160] And so, and basically, all you need is one change key to target a lock, to test it, to open a lock to generate the top-level master key. [48:10.360 --> 48:13.100] So, as Matt told you, we're reading the lock. [48:13.540 --> 48:15.540] An attack can cost less than $2. [48:17.020 --> 48:21.240] A blank can be cut with a handheld punch, a file or a key machine. [48:22.100 --> 48:24.740] Blanks are available for most locks. [48:25.180 --> 48:30.300] Now, the trick is, some locks, some high security locks, have restricted keyways. [48:30.460 --> 48:37.940] And we're going to talk about that in a minute, because there's a neat little machine made in Germany, called the Easy Entry. [48:38.040 --> 48:43.040] It's a profile milling machine that will replicate almost every blank. [48:43.040 --> 48:49.960] So, basically, what are we going to do when we go to break a master key system? [48:50.540 --> 48:53.360] Basically, what you're going to do is you're going to set up... [48:53.360 --> 48:55.780] Let's just say it's a five pin lock. [48:56.000 --> 49:08.260] We're going to pre-cut, if we really want to do this quickly and rapidly, we're going to pre-cut five blanks with the same key code as on the change key that you have. [49:08.260 --> 49:14.300] But we're going to alter one position to begin at the top, either a zero or a one. [49:14.900 --> 49:22.920] And then we're going to file down or cut down each one of those positions in sequence until we derive the top-level master key code. [49:23.160 --> 49:32.660] And when I was interviewed by the New York Times as part of Matt's article, they said, well, bring this down to real reality here. [49:32.760 --> 49:34.960] And I said, well, let's take New York. [49:34.960 --> 49:38.640] All the restrooms in public buildings are generally locked. [49:39.260 --> 49:47.300] And so when you go to an office for a visit, if you want to use the restroom, you ask the receptionist for a key to the restroom. [49:47.440 --> 49:48.880] And, of course, they'll oblige you. [49:49.120 --> 50:02.000] Once you have that key to that restroom, if that restroom cylinder is on the top-level master key, which in most places it is because this is called convenience, you own the system. [50:02.000 --> 50:08.960] Because all you have to do is decode that key or make a silicone impression or copy it. [50:09.480 --> 50:16.680] And then at will, over your convenience, you can go sample that restroom lock for the top-level master key. [50:16.900 --> 50:20.780] And, as I said, when you get that, then you walk into anywhere in the building. [50:21.600 --> 50:27.080] So the decoding process, as Matt referred to, you can do it in one session. [50:27.080 --> 50:29.220] You can do it in multiple sessions. [50:29.700 --> 50:31.260] There's no forensic trace. [50:31.440 --> 50:32.380] This is the problem. [50:32.920 --> 50:34.460] And you walk up to a lock. [50:34.620 --> 50:35.400] You stick a key in it. [50:35.460 --> 50:39.200] If it opens it, you know that you've decoded another position. [50:39.200 --> 50:43.060] If it doesn't, you go back or, you know, you go wherever. [50:43.100 --> 50:47.340] You file it down to the next tumbler position and you test it again. [50:47.340 --> 50:52.360] So what I've done is a graphic representation of each chamber position. [50:54.520 --> 50:57.440] And, basically, you're testing each chamber. [50:57.680 --> 51:01.100] And, actually, a five tumbler lock, you can do it. [51:01.120 --> 51:04.080] I calculate it in four keys if you're really lucky. [51:04.220 --> 51:05.450] It depends on the bidding combination. [51:06.160 --> 51:09.740] So, how do we make master key systems more secure? [51:09.740 --> 51:21.100] Well, the real way to do it and the only way to do it, one, as Matt suggested, you can add additional pins in the pin stack. [51:21.720 --> 51:26.800] That's true, but it lessens the security of the lock because it becomes a lot easier to pick. [51:27.020 --> 51:29.640] So, it's not an acceptable alternative. [51:30.280 --> 51:34.960] Theoretically, yeah, it'll make it more difficult because you have to decode more permutations. [51:34.960 --> 51:37.280] But, at the end of the day, it's not the way to do it. [51:38.200 --> 51:43.140] You can use what's called a Corbin master ring, which is about a 75-year-old technique. [51:43.220 --> 51:45.400] Actually, it was invented over 100 years ago. [51:45.680 --> 51:47.680] There aren't very many of those systems around. [51:48.440 --> 51:52.380] And, it's also a way to do it, but they also have their own security problems. [51:52.760 --> 52:02.840] So, basically, the real way to protect these master key systems, because everybody asked me after Matt's article came out, well, okay, Matt's come out with a problem, what's the solution? [52:02.840 --> 52:05.540] Well, in fact, there is a solution. [52:05.820 --> 52:11.900] The solution is Medeco and ASA with multiple sidebar codes. [52:12.080 --> 52:15.080] And, what I mean by that is the Medeco lock... [52:15.080 --> 52:16.320] How many of you are familiar with Medeco? [52:17.160 --> 52:18.700] Okay, everybody's heard of Medeco. [52:18.840 --> 52:21.460] Medeco probably owns the high security market in America. [52:21.700 --> 52:23.500] They really are, in my view, the best. [52:23.720 --> 52:30.720] So, the bottom line is the Medeco locks, you not only raise the tumblers with the bidding on the keys, but you twist them. [52:30.720 --> 52:41.260] Both actions occur simultaneously, and when you twist the tumblers, a secondary sidebar drops into the plug to allow it to rotate. [52:41.560 --> 52:51.580] So, if either the vertical biddings are incorrect, or the sidebar cuts are incorrect, the rotation is incorrect, the lock won't open. [52:51.580 --> 52:55.320] So, you're really running two kinds of master key systems at once. [52:55.540 --> 53:05.880] You're running a conventional master key system, and you're also running a positional master key system with regard to the location of the rotating tumblers. [53:05.880 --> 53:23.740] So, these systems, although they can be defeated, it's a lot more difficult, and if you walk up to a lock without a change key, it's very, very difficult to obtain the top-level master key. [53:23.740 --> 53:37.800] And we're talking now about the Medeco biaxial, which has double the number of rotating positions that the original Medeco did, and there's a representation here in the color diagram. [53:37.800 --> 53:43.020] There's four and aft positions, and there's left, center, and right rotation. [53:43.320 --> 53:56.840] And so, this is a very clever design, and Medeco has made it possible to have different sidebar codes for different groups of locks. [53:57.100 --> 54:06.360] So, if you're targeting a lock that isn't in the same sidebar code group, you have a serious problem to decode that lock. [54:06.360 --> 54:10.360] And here's a graphic representation of a Medeco biaxial lock. [54:10.780 --> 54:24.140] And essentially, what Medeco is doing for the top-level master key is double cutting the master key, the top-level master key, to accommodate a matrix of all the individual sidebar code groups. [54:24.380 --> 54:29.280] The other lock that will prevent the problem is made by ASSA. [54:29.560 --> 54:33.960] And it's the ASSA V10, which we don't see in America very much. [54:33.960 --> 54:43.840] It's only in three very high security installations in America, one of which doesn't exist anymore, because Al Qaeda took care of it in 2001. [54:44.340 --> 54:48.100] But there's two other major, major facilities in the country where this is used. [54:48.340 --> 54:56.400] And it's essentially the same as the Medeco approach, only it depends on sidebar millings as shown on these keys. [54:56.400 --> 55:02.740] And so if you don't have this right sidebar milling, you have a serious problem decoding this lock. [55:02.980 --> 55:13.640] And so basically what ASSA has done is take the pins and they look at either the left or the right hand side of the key for contact points, as you can see here. [55:16.660 --> 55:24.120] So the next level, Medeco just came out with the first of the year that some of you may have heard about. [55:24.300 --> 55:25.600] It's called the M3. [55:26.160 --> 55:42.400] This is a Medeco lock with a third level of security that has a protruding side pin that activates a slider mechanism that has to interface with the side bar that makes this lock extremely secure. [55:42.680 --> 55:46.940] I'm not telling you it can't be decoded, but it's very, very difficult. [55:47.340 --> 55:50.740] These photographs show what the sliders look like. [55:50.940 --> 55:54.460] There's over 25 positions that this slider can assume. [55:54.740 --> 56:02.040] And the locks can further be subdivided for master key only, change key only, or change key and master key access. [56:02.700 --> 56:05.620] And so it's a pretty slick deal. [56:06.880 --> 56:10.060] As I said, Barry's going to talk about a bump key. [56:10.420 --> 56:14.960] And this is the...it's a result of impact picking. [56:16.100 --> 56:20.940] Such as the electoral pick that's made in Germany, which is...this is actually one of the better ones. [56:22.120 --> 56:24.880] It's essentially Newton's third law of motion. [56:25.180 --> 56:27.760] For every action, there's an equal and opposite reaction. [56:27.760 --> 56:39.840] And so when you bounce the tumblers, and this is especially appropriate for picking mushroom pin tumbler locks, you bounce the pins and in two seconds you can buzz open the lock if you're really good at it. [56:40.360 --> 56:42.800] This is what a bump key looks like. [56:42.920 --> 56:54.900] And basically it's called a 999 key in Denmark because all the cuts are cut all the way down to the lowest code number that's available or the deepest cut on the lock. [56:55.060 --> 56:59.380] And Barry will explain a little more to you how that works shortly. [57:00.160 --> 57:01.560] There's also comb picking. [57:01.620 --> 57:02.440] Are you going to talk about that? [57:02.860 --> 57:05.320] I wanted to, but if you can show it, it's better. [57:05.540 --> 57:05.860] Okay. [57:06.120 --> 57:07.620] This is a comb pick. [57:07.980 --> 57:10.100] This is actually made by John Fall. [57:10.540 --> 57:15.660] Believe it or not, a lot of the manufacturers today still don't get this concept. [57:16.560 --> 57:24.600] All of the pin stack, the length of the top pin and the bottom pin in each pin stack have to be constant. [57:25.140 --> 57:32.180] In the old days, all of the top pins, which were then called drivers when I grew up, were of the same length. [57:32.400 --> 57:42.180] The problem with that theory is that you can take a comb, which is shown on the left-hand side, and you can essentially create your own shear line. [57:42.740 --> 57:46.500] So, Matt, let me have your laser pointer. [57:47.660 --> 57:48.280] Okay. [57:53.170 --> 58:07.330] We actually create our own shear line by sticking this, we replicate the key, and then we lift that so we actually push all the lower tumblers up above into the top chamber area, and then the lock opens, no problem. [58:07.790 --> 58:11.770] And you can still do this with a lot of locks today, unbelievable as it is. [58:12.990 --> 58:13.250] Okay. [58:13.610 --> 58:28.510] Then we have the Schlage Everest, which I referred to before, and the Schlage Everest has got an undercut, which I've denoted in blue, and what this does is it raises a little check pin, so unless that check pin is raised, the plug cannot rotate. [58:28.910 --> 58:33.690] It's actually a very clever design, but it's very easy to knock off with a profile milling machine. [58:33.690 --> 58:35.670] This is a patented key way. [58:36.290 --> 58:44.690] So, of course, Schlage said, Mr. Tobias, you can't talk about that, that's a felony, because you're showing how to infringe on our patent. [58:44.870 --> 58:47.510] Well, unfortunately for Schlage, not quite. [58:49.050 --> 58:54.810] Because what the easy entry does is it draws around the key way, so it creates a different profile. [58:55.370 --> 59:09.510] One of my friends, they actually, the company that made the picks that we have here for you guys, also make this pick, or tension wrench, that lifts the check pin, so if you put that into the Schlage Everest, it's a conventional lock to pick it. [59:09.990 --> 59:12.790] I think Barry's also going to talk about the Sputnik. [59:13.290 --> 59:14.190] Yeah, I brought one. [59:14.310 --> 59:14.570] Okay. [59:15.470 --> 59:21.650] The Sputnik is a very clever design that's made in Germany, sold by MSC. [59:22.330 --> 59:34.990] And it's actually got, you can actually manipulate each tumbler individually and at the same time with a series of fine wires that are pushed so you raise each tumbler to shear line. [59:35.190 --> 59:41.350] It's sort of like picking an axial pin tumbler lock, because you have access to all the tumblers at the same time. [59:44.750 --> 59:48.610] And this is, how do we, okay, let me get back to, [59:52.660 --> 59:56.700] how do we get back to, okay, alright. [59:57.000 --> 01:00:06.740] So, as we can see on this macro, from the area in my CD on this, it shows how each of these wires can control a pin. [01:00:07.620 --> 01:00:10.400] Okay, the Easy Entry Profile Milling Machine. [01:00:10.640 --> 01:00:12.820] This is really a slick box. [01:00:12.820 --> 01:00:15.320] This is a little 20 pound box. [01:00:15.600 --> 01:00:16.960] Runs on 24 volts. [01:00:17.540 --> 01:00:22.700] It'll replicate almost any key way in about five minutes. [01:00:23.020 --> 01:00:26.300] In Germany, it was developed because there are all the blanks. [01:00:26.580 --> 01:00:28.520] It's driven either in German or English. [01:00:28.820 --> 01:00:30.140] You stick the blank in. [01:00:30.340 --> 01:00:32.180] It samples the blank. [01:00:33.220 --> 01:00:35.580] It actually reads the blank. [01:00:36.360 --> 01:00:40.700] It measures it with a little probe that goes on both sides of the blank. [01:00:40.700 --> 01:00:43.320] And then, it actually mills it. [01:00:44.060 --> 01:00:46.940] And I think Barry's got one of those to show you. [01:00:48.740 --> 01:00:49.780] Well, I... [00:02.350 --> 00:06.670] Okay, so what happens is this is a two-step process. [00:06.910 --> 00:13.830] First we measure the blank and we can store the profile for later replication in a database in the computer. [00:14.130 --> 00:16.710] And then we can tell it to mill the blank. [00:16.850 --> 00:21.570] There's about five different sizes of blanks to basically do any key. [00:21.950 --> 00:27.170] And so a little milling head comes out and it laterally mills the blank. [00:28.450 --> 00:34.030] Most profiles can be copied unless they're square cut profiles as shown on the right hand side. [00:34.210 --> 00:35.170] It won't do squares. [00:36.450 --> 00:38.250] And it won't do protrusions. [00:38.450 --> 00:43.910] Now the cool thing about this machine is that you can take a change key. [00:44.650 --> 00:49.330] Now think about this in the master key environment when you can't get the blanks. [00:49.390 --> 00:51.250] This is the problem with this machine. [00:51.830 --> 01:04.670] If you have access to the machine and you have access to a change key, but not a blank key, this machine will replicate the change key and change it into a blank key. [01:05.030 --> 01:08.330] So you have no access problems for the blank keys. [01:08.490 --> 01:11.790] This is why this whole master keying issue has become so critical. [01:12.110 --> 01:17.570] And again, here's what the blanks look like and here's what the cut keys look like. [01:17.570 --> 01:28.030] And what it does is it actually samples and approximates the words in the lock so it doesn't absolutely precisely represent the key. [01:28.330 --> 01:33.110] Now, what's really cool about this machine, I've been working with the manufacturer in Germany. [01:33.430 --> 01:39.530] There's now software out for this machine that you can take a photograph of a keyway. [01:39.530 --> 01:41.930] You've got to love science. [01:49.140 --> 02:06.660] Okay, so we take a picture of the keyway, import it into Adobe Photoshop, size it, import it into the easy entry, and what you do, I don't know if you can see a little bit, you actually draw the keyway. [02:07.460 --> 02:10.060] You draw it the way you want it to be. [02:10.540 --> 02:14.800] And then you store it in a database and you replicate the keyway. [02:17.940 --> 02:21.240] Now you have a blank key that fits the lock. [02:21.600 --> 02:24.300] Now you may have some special requirements. [02:24.560 --> 02:26.740] Let's talk about our friends at Schlage. [02:27.300 --> 02:32.020] Now this is the database, how you store the profile and then you can modify it. [02:32.040 --> 02:41.580] You can make it thinner, you can make it thicker, you can chop pieces off, you can add pieces, you can change sectional keyways in high security environments, you can do whatever you want. [02:41.960 --> 02:44.120] So here's our friend Mr. Everest. [02:44.660 --> 02:47.800] This is an original Everest profile. [02:48.120 --> 02:57.260] And you can see how the undercut would prevent a standard blank from entering that keyway, which is a very clever design and patented. [02:57.880 --> 03:02.860] And if you're not able to have that undercut, you aren't getting into that keyway. [03:02.860 --> 03:06.940] Now comes the modified profile. [03:07.180 --> 03:11.560] And as you can see, what I did was I drew around the undercut. [03:11.800 --> 03:14.800] So this is now not a Schlage Everest blank. [03:15.080 --> 03:17.020] This is one that will open this lock. [03:17.020 --> 03:26.940] And then my friend Ken Pearson at Peterson Manufacturing that makes the lock picks, he made a little pin that inserts into the lock and raises the check pin. [03:27.800 --> 03:29.500] So it's very clever. [03:30.060 --> 03:33.280] So that's basically the machine. [03:33.600 --> 03:38.700] They have a website, easyentry.de, if you want more information on it. [03:39.620 --> 03:49.140] Impressioning notes, as I said, you can open, as I found, with a ballpoint pen, the locks for the computers. [03:49.440 --> 03:53.980] Thank God nobody steals computers today, or that wouldn't have much effect. [03:54.340 --> 03:58.500] This is a foil impressioning system that's made by John Fall, as I mentioned. [03:59.000 --> 04:07.700] And basically, you stick an aluminum foil carrier into the lock, and in 30 seconds, this is a Schlage 923C, which Matt talked about. [04:07.700 --> 04:08.640] It's open. [04:08.820 --> 04:19.160] And by the way, the two books that Matt talked about, written by Hobbs, and then there's another one written by George Price, and Art of Manipulation are all in the CD. [04:20.000 --> 04:20.400] Yep, okay. [04:21.280 --> 04:25.160] And this is what the foil carrier looks like after its impression. [04:25.460 --> 04:26.320] It's very clever. [04:26.500 --> 04:30.920] And you can actually decode that foil carrier and come up with a code number for the key. [04:32.020 --> 04:39.060] This is another method of opening foil, aluminum foil, with the dimple keys, like Barry's gonna show you. [04:39.340 --> 04:46.000] And I'll turn it over now to Mark, and if we have time at the end, we'll talk about Antwerp a little more. [04:46.220 --> 04:46.540] Thank you. [04:47.640 --> 04:48.320] Appreciate it. [04:55.250 --> 04:56.030] Don't you do it. [04:56.070 --> 04:56.610] Don't go off. [04:57.090 --> 04:58.030] No, I know you're a button. [05:37.800 --> 05:39.440] It sometimes takes a little. [05:54.150 --> 05:54.870] Can't you get it? [05:54.870 --> 05:55.890] Yeah, sometimes takes a little. [05:57.430 --> 05:58.430] Oh, let's see. [05:58.510 --> 05:59.210] How do you do that one? [06:00.990 --> 06:02.670] I had this problem in Germany. [06:04.970 --> 06:05.670] There we go. [06:06.330 --> 06:06.830] There we go. [06:07.610 --> 06:07.890] Yep. [06:08.610 --> 06:08.870] Okay. [06:08.970 --> 06:09.290] You got it. [06:09.390 --> 06:09.550] Okay. [06:10.950 --> 06:11.610] Hi there. [06:13.890 --> 06:17.470] My name's Mark Seiden, and I do physical security for a living. [06:17.610 --> 06:20.650] I break into things always when authorized. [06:20.650 --> 06:23.850] I usually require written permission. [06:26.890 --> 06:30.290] So I'm not going to repeat the stuff that these other fine people have said. [06:30.410 --> 06:31.210] I'll try to skip over. [06:31.410 --> 06:34.350] I have way too many slides because I was invited only yesterday. [06:35.870 --> 06:43.370] I'd like to step back a bit, though, and look at the bigger picture here, which is not focusing on locks, but focusing on the system issues. [06:43.810 --> 06:50.770] Locks are just one component which fit in into a gestalt, which most manufacturers don't even bother to understand. [06:50.770 --> 06:59.410] The users who install also don't bother to understand the context in which the lock or the things around it are installed. [06:59.710 --> 07:10.750] So this fits in a much bigger context of physical security, which has been getting smaller and smaller since 9-11. [07:12.430 --> 07:25.070] And a number of features in the enterprise environment and the business environment have been reducing physical security, specifically, for example, reliance on external parties, outsourcing, and offshore development. [07:25.270 --> 07:27.930] That means you're depending on all these... and co-location sites. [07:28.210 --> 07:33.270] This means you're depending on all these external people to do the security for you, rather than doing it yourself. [07:35.150 --> 07:45.230] Even in the enterprise, if you work in a business, you'll discover there's fragmented responsibility and authority between sysadmin and networking and legal and facilities. [07:45.650 --> 07:51.190] And often there are multiple sites, so there are different people in different locations that have responsibility for stuff. [07:51.370 --> 07:57.950] And there's a lot of gaps between these competing parties, so stuff will just fall into the cracks. [07:59.090 --> 08:06.290] There's very little budget for a mediation of older facilities, problems with older facilities, like locks that were installed 35 years ago. [08:07.890 --> 08:10.790] Mostly the risk management mindset is insurance-oriented. [08:11.070 --> 08:12.490] You know, what do we stand to lose? [08:12.570 --> 08:16.730] How do we buy insurance to pay us for the loss, to cover us for the loss? [08:17.290 --> 08:25.710] Another problem is that the facilities people who have lots of functional power, they have this key ring, which can open anything, have very little status. [08:25.710 --> 08:29.390] So they might be in a cube instead of in a locked office. [08:31.250 --> 08:40.070] Moreover, they have very little training in how to make buying decisions, so the vendors sell them snake oil or products that don't work very well. [08:42.630 --> 08:44.730] Meanwhile, almost no solutions are open source. [08:44.890 --> 08:50.910] It's really hard to evaluate what the vendor products are unless you're somebody like Mark Tobias or you buy his book. [08:52.430 --> 08:54.590] See, I'm even plugging his book. [08:55.410 --> 09:00.450] So the other problem, as Matt has pointed out, is that they strongly believe in security through obscurity. [09:03.330 --> 09:17.590] Their common cop-outs, rationalizations, excuses are, that's not my job, it's my vendor's problem, I don't consider that a plausible threat, we just have to do a little bit better than locks and keys, or we have to raise the bar just a few inches so they'll go to our neighbors. [09:21.750 --> 09:26.010] In a campus or a building, there's a lot of legacy to deal with. [09:26.190 --> 09:39.070] For example, partial height walls, hung ceiling, raised floor, wiring rooms in the wrong places like in the hallways, wire runs through public areas, doors that were installed 30 years ago, locks that are misinstalled. [09:39.390 --> 09:43.810] Now, at least you can ask yourself in the physical security world, is there a perimeter? [09:43.810 --> 09:48.110] You can't ask that in the networking context anymore because of wireless. [09:53.020 --> 10:01.620] Then there are, in the physical security world, there are also these back doors, and I don't mean the physical back door to the plant where the people go outside and smoke, but that is one of them. [10:02.310 --> 10:04.000] There's also the Knox box. [10:04.220 --> 10:19.170] It's this little box that sits on the side of your building and has the keys inside it, and there's a single key that all the firefighters and police officers have that opens that Knox box, and they take out the key ring, which opens the inside. [10:19.460 --> 10:23.050] So, if they need to get in in case of emergency, they have... [10:23.050 --> 10:26.460] That's what you call, in computer science, a single point of failure. [10:27.210 --> 10:31.140] The Knox box is usually protected by a Medeco cabinet lock. [10:32.810 --> 10:38.570] Another physical security problem in campuses or buildings is the local operating networks. [10:38.570 --> 10:41.760] That is, the building control is on a network itself. [10:42.100 --> 10:47.960] Usually it runs on power line or some other kind of network, and often these things are connected with the enterprise network. [10:48.500 --> 10:51.140] Sometimes these things also control the doors and the alarms. [10:52.520 --> 11:05.840] Multi-tenant buildings are a special problem because they have shared infrastructure, and there's a lowest common denominator factor that comes in because the weakest tenant security policy probably is your de facto security policy. [11:05.840 --> 11:09.320] If they let anybody in, anybody can walk up to your front door. [11:10.680 --> 11:13.200] So, co-location facilities are one of my favorites. [11:13.560 --> 11:16.400] I'm often hired to test the security of colos. [11:16.560 --> 11:23.380] And these are like gated communities, except when the motorcycle gang moves in down the street, you've lost all your security. [11:23.700 --> 11:27.560] Your co-tenant's weakest visitor and vendor policy puts you at risk. [11:30.200 --> 11:31.960] So, let's get down to components now. [11:32.100 --> 11:35.040] There are things like doors, which are made of what? [11:35.380 --> 11:36.720] Are they single or double doors? [11:36.880 --> 11:37.420] Where are the hinges? [11:37.580 --> 11:38.580] Sometimes they're on the outside. [11:38.760 --> 11:40.620] Sometimes you can just take hinge pins off the doors. [11:41.360 --> 11:41.980] Then there are locks. [11:42.300 --> 11:43.900] Pardon the ends. [11:44.080 --> 11:46.340] This is a PowerPoint wonderfulness. [11:46.790 --> 11:48.380] All these guys talk about locks. [11:48.380 --> 11:57.940] A few amusing problems with locks are that the best-selling tubular locks, Schlage, have deadlockers which are rendered ineffective by the biggest-selling electric strikes. [11:58.290 --> 12:04.400] These are often installed together and the deadlocker just slips into the gap behind the electric strike. [12:04.640 --> 12:07.480] So you can just push back the bolt. [12:07.640 --> 12:09.240] The deadlocker doesn't work. [12:09.240 --> 12:14.380] I frequently see exposed electric strike wiring outside the protected area. [12:14.760 --> 12:19.120] Magnetic strikes, which are those things with the big magnets, not on uninterruptible power. [12:20.000 --> 12:30.060] And it's little realized that adhesive tape on the magnetic strike or any kind of coating reduces the holding strength dramatically according to an inverse cube law. [12:30.740 --> 12:33.320] Matt had some mathematics, so I have to have some mathematics too. [12:34.380 --> 12:40.220] Now, so keyed locks are often installed even on doors controlled by badge access control. [12:40.400 --> 12:43.960] So you have a parallel, weaker system by which you can get through. [12:44.540 --> 12:48.720] And often nobody knows who has the key to the keyed locks on the magnetic... [12:50.020 --> 12:53.100] on the doors controlled by the badge access system. [12:53.300 --> 13:00.760] So I won't talk about any of these lock cylinder issues because everybody else has, except for interchangeable core cylinders. [13:01.770 --> 13:09.420] Interchangeable core cylinders have a special key called a control key, which you can use to remove the core and replace it with a different core. [13:09.600 --> 13:12.180] In other words, re-key the lock quickly. [13:12.440 --> 13:17.520] The problem is that the control key is often even more universal than any master key. [13:18.000 --> 13:20.340] There's one control key for the whole system. [13:20.680 --> 13:24.320] And you can make a control key with one instance of a lock. [13:24.320 --> 13:40.400] One comment on Mark's description of systems that avoid the master key vulnerability that Matt described is that you can still take apart any instance of any of these locks and figure out what the sidebar combination is. [13:40.880 --> 13:42.440] So, I mean, it leaves a trace. [13:42.580 --> 13:43.670] There's a hole in the door. [13:43.800 --> 13:45.220] Some lock has disappeared. [13:45.480 --> 13:47.260] Maybe a padlock has walked off. [13:47.260 --> 13:52.260] But you still only need one lock to reverse engineer the entire system. [13:52.340 --> 13:52.700] Mark? [13:53.340 --> 13:54.440] Let me just... [13:54.440 --> 13:54.800] Go ahead. [13:55.000 --> 13:56.420] Let me just make one comment. [13:56.860 --> 14:00.840] That's true if one sidebar code is used in the whole system. [14:00.840 --> 14:12.480] That is not true, as I said, if there's multiple sidebar codes that Medeco and ASSA have the capability of developing or generating, which no other system does. [14:12.790 --> 14:19.040] If you take a target lock with a different sidebar code than what you're going after, you aren't going to open it. [14:19.170 --> 14:19.360] Okay. [14:19.480 --> 14:20.170] That's the problem. [14:20.300 --> 14:20.560] Thank you. [14:20.900 --> 14:26.200] The real problem with physical locks is that revocation of rights is unacceptably difficult and expensive. [14:26.780 --> 14:27.500] I went... [14:27.500 --> 14:31.920] I learned to pick locks at Columbia University in the 1960s so that... [14:31.920 --> 14:40.340] I worked for the radio station there, and we wanted to report on kids getting beat up by cops on campus, and we didn't want to get beaten up or tear-gassed ourselves. [14:40.540 --> 14:47.400] So I made keys to the tunnels under the campus and the buildings so we, the radio station, could report on what was going on. [14:47.700 --> 14:50.200] I went back for my 25th college reunion... [14:50.200 --> 14:51.980] So, in other words, you are a terrorist. [14:52.240 --> 14:52.600] That's right. [14:52.740 --> 14:53.600] I was a terrorist. [14:53.940 --> 14:55.300] Sounds like Les Miserables. [14:55.300 --> 14:56.540] Mommy, grandpa, terrorist. [14:57.640 --> 14:58.020] So... [14:58.840 --> 15:01.480] When I went back for my 25th reunion, guess what? [15:01.620 --> 15:05.020] My tunnel keys and my front door keys to the building still worked. [15:05.640 --> 15:06.980] 25 years later. [15:11.210 --> 15:15.830] So this is just a demonstration that revocation of rights is seldom, if ever, done. [15:16.010 --> 15:17.330] Because it's enormously expensive. [15:17.630 --> 15:18.810] So what do we use instead? [15:19.130 --> 15:21.650] We use computer access badge systems. [15:21.970 --> 15:24.250] So there's a computer and a database involved. [15:24.250 --> 15:26.230] I can hear you saying, uh-oh. [15:26.510 --> 15:31.550] It's wired somehow to microcomputer-based panels with local caches of access rights. [15:31.750 --> 15:35.410] And these things used to be connected on local wiring, point-to-point wiring. [15:35.710 --> 15:37.770] But now they've networked it all. [15:37.890 --> 15:38.850] And how have they networked it? [15:38.910 --> 15:41.930] They put these Lantronics terminal controllers in front of it. [15:42.050 --> 15:45.210] They use bogus proprietary protocols. [15:45.210 --> 15:49.270] They seldom use mutual authentication of the counterparties in any transaction. [15:49.830 --> 15:51.050] So you can do man-in-the-middle attacks. [15:51.270 --> 15:52.230] You can do sniffing attacks. [15:52.490 --> 15:56.210] And these are the things that open the doors, that control the doors. [15:56.670 --> 16:00.830] If they're on your enterprise network, you've basically lost the game. [16:01.830 --> 16:06.630] The manufacturers leave in back doors for the installers and the maintainers, and maybe others. [16:06.930 --> 16:08.430] And they don't document any of them. [16:08.610 --> 16:11.190] The only way you could find these back doors is by reverse engineering. [16:12.270 --> 16:14.290] And then there are these cards, which let you in. [16:14.390 --> 16:15.090] Prox cards. [16:15.510 --> 16:17.530] An early example of RFID tags. [16:17.770 --> 16:21.210] They have a short number, which is sent by RF to the reader. [16:21.470 --> 16:23.570] And these can be read remotely by an attacker. [16:23.730 --> 16:28.270] While you're in the elevator, somebody can walk up to you with a battery-powered reader and read the card in your wallet. [16:28.650 --> 16:30.330] Maybe if you have two, it would be difficult. [16:30.590 --> 16:32.730] But if you only have one card in your wallet, they can read them. [16:32.910 --> 16:35.790] Some of these are field programmable, so you can generate your own cards. [16:36.190 --> 16:38.670] The low card numbers have problems in brute force attacks. [16:38.670 --> 16:39.830] Are possible? [16:40.130 --> 16:42.750] Although I don't know of a brute forcing machine yet. [16:43.110 --> 16:44.470] Are these more secure than keys? [16:44.710 --> 16:45.030] Maybe. [16:47.110 --> 16:56.430] So here's a case study that I did with Mark Chen at a financial institution where we decided it would be fun to break into the badging system, which would gain us access to everything else. [16:56.430 --> 17:00.010] I won't name the vendor on the tape. [17:00.950 --> 17:06.830] But this system was running SCO UnIX on a PC with basically all the services turned on. [17:06.970 --> 17:08.570] Serial wiring to guard stations. [17:08.870 --> 17:12.090] A root password was published in the user manual, R00T. [17:13.670 --> 17:17.710] When we called tech support and said, why did you publish your root password? [17:17.830 --> 17:20.010] They said, oh, you don't want to change that, you know. [17:20.250 --> 17:23.890] That could create big service problems for us. [17:23.890 --> 17:24.830] We couldn't support you. [17:25.410 --> 17:28.190] Dial-up modems, which they also recommended always be left on. [17:28.750 --> 17:31.350] So of course I logged on as root and started poking around. [17:32.790 --> 17:35.810] It was listening for TCP connections on 21 ports. [17:37.250 --> 17:38.690] The source was on the machine. [17:38.810 --> 17:41.390] It was open source, but not because they believed in open source. [17:41.510 --> 17:42.830] It was for their convenience. [17:43.130 --> 17:44.850] So they could compile in features. [17:44.850 --> 17:48.450] And so I was looking at IFDEF Jetway, IFDEF U.S. House. [17:50.130 --> 17:52.090] I was starting to get alarmed. [17:53.490 --> 17:55.890] Other IFDEFs included LDS Church. [17:57.070 --> 18:01.490] GE King of Prussia, which I think makes nuclear gadgets or jet engines or something. [18:02.170 --> 18:03.890] University of Washington Corning. [18:04.410 --> 18:05.030] U.S. Senate. [18:05.930 --> 18:07.410] University of Southern California. [18:07.710 --> 18:09.310] Yale University Medical Center. [18:09.310 --> 18:11.350] And five airports by name. [18:11.730 --> 18:13.050] All the British airports. [18:13.830 --> 18:19.490] And their customers included 50 airports, prisons, all the state correctional institutions in Pennsylvania. [18:19.610 --> 18:21.770] I was visualizing musical cells. [18:22.870 --> 18:26.270] At midnight we'll just open all the cell doors and see what happens. [18:27.150 --> 18:30.370] So, looking at the database schema was really instructive. [18:30.490 --> 18:32.970] Because the system has this concept of pass key, a magic word. [18:33.190 --> 18:36.350] You type at the guard terminal and it conveys various privileges. [18:36.350 --> 18:38.050] It's like a password but without a login. [18:38.350 --> 18:41.330] And all these things were in a database table, lightly obfuscated. [18:41.530 --> 18:44.050] So, of course, we extracted the passwords. [18:44.390 --> 18:48.310] And we noticed there was a special pass key, a magic function of the date. [18:48.530 --> 18:52.670] Which conveyed system manager privilege to anyone who knew how to compute it. [18:52.910 --> 18:56.550] So, you could just type in this number and boom, you were the super user. [18:56.810 --> 18:58.010] This was not documented. [18:59.950 --> 19:03.290] So, of course, an attacker could do anything including musical cells. [19:03.290 --> 19:11.470] Create stealth badges, alter code, disable the logging mechanism, remove or alter the log records. [19:11.870 --> 19:14.510] There are general problems with sensors and alarms. [19:16.370 --> 19:19.870] Which I don't have time to talk about or Bari won't have time to demo. [19:22.570 --> 19:25.770] I won't talk about video, but video has its pluses and minuses. [19:25.770 --> 19:37.750] Particularly, you may discover this when the pin of your ATM card is sniffed by someone who has installed a surreptitious video camera pointed at the keyboard and has put an overlay card reader on the ATM. [19:38.890 --> 19:41.390] I'll just talk about this co-location case study. [19:41.550 --> 19:45.090] I was hired to test security at a big colo. [19:45.970 --> 19:52.030] One run by a publicly held company with vaults, they called them vaults, cages and cabinets on a raised floor. [19:52.310 --> 20:00.210] But the raised floor was the plenum for the cool air which would flow through the raised floor, go through vents in the vault, and go up into the ceiling. [20:00.510 --> 20:05.970] So basically, this was just an enclosed area with an open floor and an open ceiling. [20:08.230 --> 20:11.150] Naturally, you could go over the ceiling or under the floor. [20:11.450 --> 20:16.010] But they said, we have passive infrared sensors. [20:16.170 --> 20:18.890] We are protected by motion sensors in our vault. [20:19.050 --> 20:20.590] So I decided to test it. [20:20.930 --> 20:24.750] I submarined under the floor, popped up, waved at the motion sensor. [20:25.190 --> 20:27.330] Twenty minutes later, nothing had happened. [20:29.730 --> 20:38.370] So I walked out of the door, and I waved at the camera, put up a sign saying, bust me, nothing happened. [20:39.150 --> 20:41.030] I walked out the door with a PC. [20:42.390 --> 20:43.850] How did I get in in the first place? [20:43.870 --> 20:49.170] I walked in the back door, and they buzzed me in because I had a legitimate looking badge, which I had forged. [20:53.110 --> 20:57.130] So, of course, what you find out is that the motion sensor is for their convenience. [20:57.350 --> 20:59.270] It's a request to exit sensor. [20:59.270 --> 21:04.610] It shunts the switch on the door that enables you to leave without setting off the alarm. [21:04.790 --> 21:07.850] If you force the door on the way in, it would set off the alarm. [21:08.030 --> 21:11.030] But if you're walking out, no alarm. [21:11.490 --> 21:17.270] So, they didn't ask themselves the question, how could somebody get in the space when nobody entered? [21:18.250 --> 21:21.970] There's been nobody in the space for 48 hours, but suddenly there's movement in the space. [21:22.110 --> 21:23.090] Isn't that abnormal? [21:23.590 --> 21:28.990] Well, no, because they have no integration between the motion sensing and the access control and the alarm. [21:29.210 --> 21:31.030] They're all disintegrated systems. [21:33.730 --> 21:34.210] Identity. [21:34.510 --> 21:38.810] I'll just leave you with one thought question, which is the last bullet here. [21:39.010 --> 21:49.050] Is it better for your colo to accept your driver's license or to issue you their own credential containing a shared secret or to check your face in a database? [21:50.470 --> 21:57.650] And my claim is that private credentials are much better these days because anybody can make driver's licenses. [21:58.950 --> 22:03.290] Like this guy who forged the identity... [22:03.290 --> 22:15.370] This is Abraham Abdallah who pled guilty to some large number of counts of forging the identities of 211 of the Fortune 400 richest people a few years ago. [22:16.410 --> 22:20.410] The U.S. GAO also has been doing experiments on phony driver's licenses. [22:20.810 --> 22:26.230] They determined that if you filled out this form, which asks you questions like, are you a fugitive from justice? [22:27.810 --> 22:32.730] Are you subject to a court order restraining you from harassing, stalking, or threatening? [22:33.410 --> 22:36.670] Or have you ever been adjudicated mentally defective? [22:37.570 --> 22:42.230] If you answer any of these questions, yes, well, then you can't get it. [22:42.230 --> 22:54.430] But if you answer them all no, and you have a driver's license, or you have something that looks like a valid driver's license, which you can make using stuff on eBay, you can buy stuff like this in the five states with minimum Brady law enforcement. [22:54.710 --> 22:58.330] The reason why is they look up your driver's license in a database. [22:58.810 --> 23:01.690] And if they don't get a hit, then you must be a good guy. [23:05.950 --> 23:08.790] They don't look up the driver's license to determine if it's valid. [23:08.790 --> 23:11.970] They look it up to determine if it has the name of a known criminal. [23:12.850 --> 23:14.050] What's wrong with this picture? [23:15.370 --> 23:19.730] Here are just two more scary devices which will underscore why physical security is important. [23:19.870 --> 23:20.910] They're keystroke sniffers. [23:21.090 --> 23:24.730] You can buy them for under $100 out of catalogs or on the Internet. [23:25.030 --> 23:28.030] And they store about half a megabyte of keystrokes. [23:28.450 --> 23:34.550] This is why passwords are completely obsolete technology, and people should not use them for high-value transactions. [23:36.170 --> 23:37.430] I'm way out of time. [23:38.210 --> 23:38.390] Bari? [23:39.310 --> 23:39.670] Okay. [23:50.790 --> 24:00.070] Okay, then for the last 30 minutes, I'm going to do some demos, and then hopefully some people can ask questions as well. [24:01.550 --> 24:07.550] As many people of you know, I'm chairman of the Dutch Sport Group TOOOL, which is spelled with three O's. [24:07.730 --> 24:10.290] It stands for the Open Organization of Lockpickers. [24:11.170 --> 24:19.010] And we kiddingly say that the three O's stand for you have to practice over and over and over again to become any good at lockpicking. [24:19.790 --> 24:20.970] Which really is true. [24:21.210 --> 24:25.890] I mean, at this moment, I'm very, very busy with my business, which is the crypto phone. [24:26.350 --> 24:31.550] That's where I spend most of my time designing a secure phone, [24:35.540 --> 24:38.360] which looks like this. [24:39.560 --> 24:43.360] It's an open... or the source code is available of this phone. [24:43.520 --> 24:49.300] We try to make a phone that is untappable and as secure as possible by publishing the source. [24:49.480 --> 24:51.480] And this really takes up a lot of my time. [24:51.680 --> 24:58.640] So, unfortunately, I've not been involved in lockpicking for the last two years as much as I would like to. [24:59.760 --> 25:07.040] Fortunately, a lot of people from Germany and even some from France have helped me collect some nice tricks for you to show. [25:07.680 --> 25:10.180] And actually, it's a follow-up of what I did two years ago. [25:10.180 --> 25:19.220] The video that I did two years ago with Mike, who's sitting over there, is still available online. [25:19.440 --> 25:20.600] It's being downloaded a lot. [25:20.880 --> 25:22.280] It's downloadable for free. [25:22.440 --> 25:36.000] If you go to our website www.toool.nl, with three O's, T-O-O-O-L.nl, you'll find a link to the free download of all the things that we did last year. [25:36.000 --> 25:42.160] And that included the Electropick, that included the Foiled Nimple impression, that included a lot of things. [25:42.780 --> 25:46.200] So, I'll now focus to some other things that we've been up to. [25:46.920 --> 25:55.180] One of the things is that we're being recognized more and more as a serious party, as a serious player by the lock industry. [25:55.680 --> 26:03.200] For instance, we have found a severe, very extreme severe vulnerability in a lock that I will demonstrate now. [26:04.520 --> 26:11.420] I promised the guys that made the lock, the manufacturer, that I would put a little tape over their brand name. [26:16.670 --> 26:20.730] Because there are still a few, a small number of these locks around. [26:21.450 --> 26:33.730] But what actually happened is that somebody came into the TOOOL Sport evening and said, Well, you know, here's this nice lock and here's the key. [26:34.510 --> 26:37.110] And, well, this of course works and it operates. [26:38.530 --> 26:53.150] But he found that if you insert a blank key and you turn it into, you put it into the lock, you put pressure on it, you take it out, but you leave the tip in, wiggle it a little bit, it's open. [27:01.060 --> 27:08.740] Now, this happened at an evening that Mr. Tobias was visiting us and doing a lecture on master keying. [27:09.390 --> 27:17.280] And, you know, we all looked at each other and he said, Well, you know, this is just a lucky combination of pins and it's a one thing go. [27:17.280 --> 27:25.100] But then we thought about it some more and we discovered that it actually was a vulnerability that applied to all the locks. [27:25.360 --> 27:27.780] The complete series of locks ever made in this series. [27:28.300 --> 27:30.160] And we figured out what happened. [27:31.910 --> 27:37.220] The factory that manufactures these locks actually didn't manufacture all of it. [27:37.220 --> 27:39.020] They only did a part of it. [27:39.180 --> 27:43.000] What happened is that they bought the locks from a cheaper manufacturer. [27:43.620 --> 27:46.760] And when they got the locks, they were completely assembled. [27:47.060 --> 27:50.620] But they were filled with all the combination pins three. [27:50.890 --> 27:53.080] So the pins would be all at the same length. [27:53.300 --> 27:54.260] Three, three, three, three, three. [27:54.640 --> 27:58.500] And they would have a blank key that looks like, that's cut a little bit deeper. [27:59.540 --> 28:03.540] There would be a whole line of ladies sitting there with a pinning kit. [28:04.500 --> 28:08.980] They would insert the key, they would insert the blank with the three. [28:09.720 --> 28:12.980] Turn the plug 180 degrees. [28:13.480 --> 28:14.620] Remove the plug. [28:15.560 --> 28:19.260] Re-key the pins with a new combination. [28:19.480 --> 28:21.660] For instance, one, five, seven, five, three. [28:22.410 --> 28:23.660] And put it back in. [28:23.960 --> 28:25.980] Now, so far there is no vulnerability. [28:25.980 --> 28:33.980] But what happened is that the factory that sold the locks used pins, the top pins of a diameter of 2.2 millimeters. [28:34.890 --> 28:42.120] And they replaced the low pins with pins of 2.0 millimeters, which means that they are actually more thin. [28:42.890 --> 28:49.520] So the pins that the key touches are more thin than the pins that are on top of it. [28:49.660 --> 28:59.800] So if you turn it a little bit, if you put a little tension on it, the gap that normally is 2.3 millimeters goes to 2.0 millimeters. [29:00.080 --> 29:04.120] And the pin that's 2.3 millimeters cannot fall down anymore. [29:04.640 --> 29:09.180] So I phoned the factory and I said, well, you know, you have a serious problem. [29:09.620 --> 29:10.960] And they couldn't believe it. [29:11.060 --> 29:18.840] They said, well, you know, it cannot be that with a blank, everybody can open this key within two seconds without any training. [29:18.840 --> 29:22.580] And remember, no physical evidence is there. [29:22.740 --> 29:25.480] I mean, when I pick a lock, I make scratches in the lock. [29:25.600 --> 29:38.720] And if you send a pick lock to a forensic laboratory, which the German sport group has got some experience with, the German forensic laboratory asked if they could pick some locks and examine them. [29:38.720 --> 29:44.140] And they could actually quite detailed explain this lock has picked with an electro pick. [29:44.300 --> 29:45.360] This is done by hand. [29:45.480 --> 29:46.620] This isn't being picked at all. [29:47.300 --> 29:50.430] But with this technique, nobody would ever find out. [29:50.560 --> 29:52.560] So somebody could rob your complete house. [29:53.450 --> 30:01.060] And, you know, you really have tough lock because there's nobody who can prove that you didn't lose a key or problems like that. [30:01.060 --> 30:06.180] So that gave us quite some credit to the industry, especially since we came to them. [30:06.430 --> 30:10.450] You know, we could have gone to the eight o'clock news or whatever and make a big fuss out of it. [30:10.580 --> 30:11.640] But we didn't do that. [30:11.910 --> 30:13.450] We tried to be the good guys. [30:13.660 --> 30:18.180] This is such a serious vulnerability that, you know, we tried to... [30:18.700 --> 30:26.000] And they immediately closed the factory and it took them three days and a weekend to think what was the best strategy. [30:26.000 --> 30:29.410] And they got all the locks back from the shop and et cetera. [30:29.640 --> 30:30.740] And, you know, they... [30:30.740 --> 30:31.890] Yeah, it's... [30:31.890 --> 30:33.460] They handled it well. [30:35.390 --> 30:35.860] Okay. [30:36.020 --> 30:37.860] Then about the lock picking itself. [30:39.200 --> 30:41.700] I could explain how lock picking works. [30:41.890 --> 30:43.300] I don't know if there's a need for that. [30:43.430 --> 30:49.120] How many people would like me to explain in detail why lock picking is possible and how it can be done. [30:49.260 --> 30:51.560] Because it's been told many, many times before. [30:51.560 --> 30:55.740] And I will be downstairs at the second floor between two and five. [30:56.300 --> 31:00.560] I shall be there three hours teaching everybody who wants to pick locks. [31:01.160 --> 31:05.640] As Mark said, we have designed a special... [31:05.640 --> 31:08.450] It's already a collector's item, a special pick set. [31:09.120 --> 31:18.200] Normally, the pick sets that people carry, you know, are extremely full with all sorts of impressive looking tools. [31:18.200 --> 31:23.780] But the thing is, for lock picking, you only need actually one tool or two. [31:24.000 --> 31:27.800] You always need a tensioner and something called the finger or the lifter. [31:28.390 --> 31:33.220] And this specific one we made has got two different ends. [31:33.220 --> 31:39.300] And this will open... If you spend enough time practicing, this will help you open... [31:40.120 --> 31:42.410] I don't dare to say exactly how many percent. [31:42.560 --> 31:46.960] But I would say 80% of the locks around you without any problem. [31:47.180 --> 31:48.280] As long as you practice. [31:48.620 --> 31:50.980] Because the tools don't open the locks. [31:51.240 --> 31:51.620] You do. [31:51.820 --> 31:52.640] You open the lock. [31:54.140 --> 31:58.960] Okay, so if you want to learn to pick locks, just come downstairs between two and five. [31:58.960 --> 32:01.720] Tomorrow morning, there's going to be a lock pick championship. [32:02.480 --> 32:05.220] We'll put a nice reward on that. [32:05.360 --> 32:06.450] We'll put a nice prize on that. [32:09.680 --> 32:10.580] Okay, what's that? [32:11.320 --> 32:13.340] I'm not exactly sure about the time yet. [32:14.460 --> 32:14.860] So... [32:16.280 --> 32:17.700] Okay, we've got 15 minutes. [32:17.860 --> 32:18.080] Okay. [32:19.000 --> 32:21.220] Well, I brought a whole lot of things to demonstrate. [32:22.100 --> 32:25.700] But since we're running a little bit out of time, I will go into the bump key. [32:26.220 --> 32:33.450] The bump key, as Mark already explained, is a key that is cut to its lowest position. [32:34.140 --> 32:37.520] Sometimes it's even cut a little bit below its lowest position. [32:38.390 --> 32:41.980] And what happens is that if you insert it into the lock... [32:46.150 --> 32:51.860] If you insert it into the lock, of course it will not turn because the pins are not in the right position. [32:52.400 --> 32:59.300] What you do is you take out one click, so you remove it a little bit, and then you hit it. [33:00.950 --> 33:03.060] I'm not sure if I can do this on camera. [33:15.890 --> 33:16.650] Demonstration effect. [33:26.750 --> 33:27.210] Open. [33:28.010 --> 33:28.470] Okay. [33:36.260 --> 33:38.020] Now, I was first shown... [33:38.020 --> 33:45.920] This technique was first shown to me actually with a key and a lock in Germany by some of my good friends at the Sportfreunde Despert Technique. [33:47.380 --> 33:49.900] And they've become really good at it. [33:50.120 --> 33:55.140] And the nice thing about this technique is that it can be used on locks like this one. [33:58.240 --> 33:59.540] I'm not sure if you can see. [33:59.740 --> 34:03.540] But the key way of this lock, it's an EVA lock, is extremely narrow. [34:03.920 --> 34:09.560] It's almost impossible to even get a tool in because it's warded all over the place. [34:09.700 --> 34:10.580] It's going zig-zag. [34:10.920 --> 34:12.760] It's really extremely difficult. [34:13.540 --> 34:17.140] But luckily, with the bump key, you know, it's no problem at all. [34:17.220 --> 34:20.760] Or at least it takes a few blows to open it. [34:20.960 --> 34:22.460] If it blows in two times. [34:22.980 --> 34:23.460] Yeah, it's open. [34:23.460 --> 34:28.580] So, it just takes a little practice to do it. [34:28.720 --> 34:30.980] And as I told you, I didn't have much time to practice. [34:33.060 --> 34:39.580] Now, my good friend Oliver Diedrichsen from Germany explained to me that this could also be done with dimple keys. [34:39.860 --> 34:42.720] With the high secure locks. [34:43.620 --> 34:50.460] But he also found that if you pull back one full notch, that it doesn't work well. [34:50.460 --> 34:58.360] So, what he does is, he cuts the keys, or he cuts the cuts in the key a little bit more to the tip of the key. [34:59.940 --> 35:01.800] And this will give you more space. [35:02.720 --> 35:11.140] And he made, with a hot glue stick from a glue gun, he made what he calls a buffer. [35:11.600 --> 35:16.060] And what happens is, you insert it in the lock, and you have a little bit of play. [35:16.060 --> 35:17.900] But you cannot push it in... [35:19.220 --> 35:21.640] You cannot push it in too deep. [35:21.800 --> 35:24.420] You can only push it in a little bit. [35:24.960 --> 35:26.980] And I'll see if I can open this one. [35:38.260 --> 35:39.620] Making dance in the table. [35:40.200 --> 35:40.280] Ow. [36:08.050 --> 36:08.870] Okay, it's open. [36:15.880 --> 36:18.780] Now, but this is what I mean with... [36:18.780 --> 36:25.500] If it wasn't with the help from some of my friends of Germany and France, I wouldn't be able to show you all these tricks. [36:25.640 --> 36:32.620] Because I really don't have that much time to really go into, you know, nights and nights of playing with all these things. [36:33.600 --> 36:38.040] I hope to do it a better prepared job, maybe next time. [36:39.060 --> 36:40.480] Some trick from France, then. [36:42.280 --> 36:44.740] There is a Bricar lock. [36:45.120 --> 36:46.740] And the Bricar lock is special. [36:47.100 --> 36:53.560] That the key itself has got two rows of pins next to each other. [36:53.720 --> 36:54.860] I don't know if you can see it. [36:55.280 --> 36:57.540] But it's a very sophisticated system. [36:57.900 --> 37:00.980] And, of course, you will probably never see a Bricar lock. [37:00.980 --> 37:02.940] Because it's French and... [37:02.940 --> 37:03.560] Yeah. [37:03.940 --> 37:05.040] But in... [37:06.200 --> 37:11.680] But in France, you know, this is really a very expensive, high security lock. [37:11.880 --> 37:14.700] And to pick it, it's almost virtually impossible. [37:14.700 --> 37:16.560] Because of these two rows of pins. [37:16.680 --> 37:17.460] And it's very difficult. [37:17.740 --> 37:25.880] But my good friend, Jimé, Jean-Marie, he's thinking a lot about lock security. [37:25.880 --> 37:30.960] And he thought, well, it must be possible to make some sort of impressioning system. [37:31.320 --> 37:36.980] And as Mark already put out, with foil tape, you can make some impressioning systems. [37:37.160 --> 37:39.200] But with this lock, that seemed not to work. [37:39.400 --> 37:42.520] So what he did was he used packaging material. [37:42.780 --> 37:44.780] This foamy-like stuff. [37:44.780 --> 37:46.980] And he made a blank. [37:47.400 --> 37:50.300] Which is made out of two parts, actually. [37:51.480 --> 37:52.840] This is it uncut. [37:53.020 --> 37:54.420] So you can move the parts. [37:54.760 --> 37:58.400] And he sticks in this packaging material. [37:58.700 --> 38:00.280] And it's really amazing. [38:00.580 --> 38:02.220] But it really works. [38:02.480 --> 38:03.780] At least I hope it does now. [38:03.780 --> 38:03.800] No. [38:11.870 --> 38:12.350] No. [38:25.650 --> 38:26.370] Mm-hmm. [38:27.650 --> 38:29.170] Demonstration effect kicking in. [38:31.090 --> 38:31.910] Ten minutes. [38:33.570 --> 38:34.530] Ten minutes. [38:34.650 --> 38:34.970] No. [38:35.330 --> 38:35.430] Okay. [38:36.270 --> 38:36.750] But... [38:37.630 --> 38:38.110] Okay. [38:38.210 --> 38:39.590] I'm gonna remove it from the camera. [38:39.870 --> 38:42.590] Do you want people to queue up for questions while he's demoing? [38:42.650 --> 38:42.910] Yes. [38:43.350 --> 38:43.830] Okay. [38:44.330 --> 38:46.390] So while you're doing that, I have a quick question. [38:46.590 --> 38:48.530] What kind of lock do you have on your door? [38:50.810 --> 38:51.290] Okay. [38:51.290 --> 38:53.090] The reason... [38:53.910 --> 39:01.730] What is also my daytime job is making sure the physical security of the space around the crypto phone area. [39:02.290 --> 39:05.990] I mean, we're making secure phones to keep the bad guys out. [39:06.110 --> 39:08.370] But these bad guys have almost unlimited resources. [39:09.090 --> 39:22.010] So the thing is, I need to be at the state of the art level of making sure that nobody enters our building without them compromising our computers or the systems that we work on. [39:23.430 --> 39:24.670] So I'm not gonna tell you. [39:27.130 --> 39:27.670] Okay. [39:27.790 --> 39:28.190] It's open. [39:28.870 --> 39:29.570] It's open. [39:30.210 --> 39:30.970] It's turning. [39:32.870 --> 39:37.790] But I can tell you that a lot of computer security is involved. [39:37.910 --> 39:39.930] It's not only a mechanical system we use. [39:39.930 --> 39:42.010] I can tell a little bit. [39:42.490 --> 39:43.890] It's funny that... [39:44.530 --> 39:44.970] Oh. [39:47.850 --> 39:54.530] By the way, if you want to harass us with questions, please queue up at the microphone in the center. [39:54.610 --> 39:56.150] We only have a few minutes left. [39:56.410 --> 40:01.890] But if you want to yell at us with questions or just say harassing comments... [40:01.890 --> 40:06.770] Yeah, one real good secure lock system is by Abloy. [40:09.910 --> 40:11.790] It works with disks. [40:12.130 --> 40:17.650] And I did open a couple of disk locks the last time from Abus. [40:18.050 --> 40:20.330] But this is actually much more sophisticated. [40:20.650 --> 40:22.250] It's got a double locking bar. [40:22.250 --> 40:31.090] And if I was to recommend locks, it would probably be the Medeco M3, the ASSA V10, and the Abloy systems. [40:31.090 --> 40:34.650] Because these are really the high secure systems. [40:36.350 --> 40:36.950] Okay. [40:37.130 --> 40:37.830] If you have a question. [40:38.570 --> 40:40.970] Yeah, I have a question about the bump key method. [40:41.230 --> 40:42.730] Does that work on the majority of locks? [40:42.970 --> 40:43.150] Yeah. [40:43.330 --> 40:46.290] It works on an amazingly amount of locks. [40:46.710 --> 40:49.670] The only thing is you need time to practice. [40:49.670 --> 40:50.690] You really... [40:50.690 --> 40:56.270] You know, if you think you can open any lock with three strikes with the first time you try it, you're wrong. [40:56.650 --> 41:01.190] But if you practice with it, you can open a large amount of locks. [41:01.750 --> 41:03.650] It works the same as a pick gun. [41:03.750 --> 41:05.250] It elevates the pins up. [41:05.370 --> 41:07.550] And it's a timing matter as well. [41:07.790 --> 41:11.610] So you need to strike, wait a fraction of a second, and then turn. [41:11.870 --> 41:15.590] If you turn at the moment that you strike, you're not going to open it. [41:15.850 --> 41:17.450] It's really a timing matter. [41:17.450 --> 41:19.530] It's really something... [41:19.530 --> 41:23.610] And are there any locks that that method doesn't really tend to work on? [41:23.750 --> 41:25.110] Or because of the style of the lock? [41:25.790 --> 41:35.130] Well, as I said, the Medecos, the Asafi 10, the lock with the sidebar, and the Abloy, they're completely resistant against it. [41:35.310 --> 41:36.970] It works on a variety of locks. [41:37.190 --> 41:38.090] It works on padlocks. [41:38.210 --> 41:39.170] It works on door locks. [41:39.510 --> 41:41.730] It works on an amazing amount of locks. [41:41.730 --> 41:42.450] Thank you. [41:42.570 --> 41:42.870] You're welcome. [41:45.250 --> 41:46.030] My friend, Mike. [41:46.610 --> 41:47.150] Hi, Barry. [41:49.750 --> 41:51.470] First off, great presentation, guys. [41:51.750 --> 42:05.190] But the one thing that I think Mr. Tobias, if that's the right name, he was the only one really touched on, the fact that locks are one of the weakest links in all of security, and that you can cut through the drywall or go over the walls or under, as he said. [42:06.690 --> 42:09.050] And just that, in the general feeling of that. [42:09.230 --> 42:20.790] Now, considering that, when we talk about this lock has a terrible weakness here and that lock has a terrible weakness there, as a whole security-wide thing, do you really feel the lock is that important to the security chain? [42:21.230 --> 42:21.990] Yes, it is. [42:22.370 --> 42:22.790] Yeah. [42:22.910 --> 42:23.110] Okay. [42:23.310 --> 42:23.750] It is. [42:23.750 --> 42:25.470] It still is a point of attack. [42:25.930 --> 42:26.070] Sure. [42:26.630 --> 42:33.770] I think one advantage is that, from the attacker's point of view, if you attack the lock, you often leave very little forensic evidence. [42:33.770 --> 42:41.390] So, one property of the lock, as opposed to punching a hole through the drywall, is that you don't discover the attack until much later. [42:42.110 --> 42:46.070] And so, you know, that's one reason that locks are important to study in and of themselves. [42:46.330 --> 42:49.110] But it's absolutely true that these are just part of a larger system. [42:49.410 --> 42:52.170] And if you're concerned with securing something, you have to look at everything. [42:52.690 --> 42:57.950] Yeah, you really want defense in depth, which means locks, alarms, video, everything. [42:58.670 --> 43:00.750] The key distribution is often a problem. [43:00.750 --> 43:08.690] If you can find the facilities guy who's left the key in the coffee cup, well, and then you impression it, then you have forever entry. [43:09.290 --> 43:11.130] So, it's not the lock that's the problem. [43:11.150 --> 43:12.590] It's the way the keys are stored. [43:13.790 --> 43:14.430] Okay. [43:15.790 --> 43:16.430] Hi. [43:16.810 --> 43:26.850] One of the questions that I have focuses more on the kind of like some of the automotive cars where you have the microchip embedded within the key system. [43:27.390 --> 43:36.210] Now, as far as the additional spin regarding like tumblers or if there's something else needed to activate the chip so that the lock turns. [43:37.990 --> 43:40.150] There are a bunch of different kinds of those. [43:40.490 --> 43:42.190] Some of them are really unsophisticated. [43:42.290 --> 43:46.530] Some of the earlier ones, that computer chip turned out to just be a resistor. [43:48.070 --> 43:51.690] And with 15 or 16 different values. [43:51.890 --> 43:53.630] Actually, that was pretty... [43:53.630 --> 43:56.330] It's a pretty good system that's still out there because it's easy. [43:56.530 --> 43:56.850] Right. [43:56.850 --> 43:57.890] And it works. [43:58.970 --> 44:01.310] But some of them have challenge response these days. [44:01.950 --> 44:05.310] So, they're really transponders with RFID challenge response. [44:05.470 --> 44:06.170] It's very sophisticated. [44:06.550 --> 44:08.390] So, the problem is you can't tell what it is. [44:08.570 --> 44:10.550] By the way, why do you want to steal cars? [44:11.750 --> 44:15.970] Actually, something about a friend of mine who had misplaced one of his keys. [44:16.590 --> 44:18.470] And since it cost about four or five... [44:18.470 --> 44:19.050] Good story. [44:19.710 --> 44:22.290] Well, 500 bucks for a replacement key from GM. [44:22.290 --> 44:23.030] I mean... [44:25.010 --> 44:25.450] Yeah. [44:26.470 --> 44:26.910] Well... [44:26.910 --> 44:31.930] I'm not sure why you want to deprive those good people at GM of their $500 for your replacement fee. [44:32.250 --> 44:32.990] I don't know. [44:33.250 --> 44:34.130] We have a couple minutes. [44:34.370 --> 44:35.250] So, please... [44:35.250 --> 44:35.490] Okay. [44:36.230 --> 44:37.270] Can we take one more question? [44:37.410 --> 44:37.510] Yeah. [44:37.750 --> 44:42.910] Actually, in addition to his, that's the Texas Instruments TIRIS system that they're using. [44:43.090 --> 44:45.030] Challenge response based RFID. [44:45.190 --> 44:46.690] I was actually about to ask you about that. [44:46.810 --> 44:47.510] Last question. [44:48.030 --> 44:49.490] Because we have to be out of here, unfortunately. [44:49.490 --> 44:52.570] The SpeedPass system uses the exact same technology. [44:52.570 --> 44:55.470] Have any of you gone into any sort of analysis of this? [44:56.690 --> 44:58.590] You can look at Dave Farber's list. [44:58.770 --> 45:00.070] Interesting people. [45:00.750 --> 45:05.510] There has recently been a thread on EasyPass, FastPass, how it works. [45:05.650 --> 45:07.550] It's basically a very simple RFID. [45:07.550 --> 45:09.670] I have the equipment to read them down in my room right now. [45:09.770 --> 45:10.170] Say that again? [45:10.230 --> 45:12.350] I have the equipment to read them down in my room right now. [45:12.530 --> 45:12.610] Very good. [45:12.790 --> 45:13.930] Send me an email, would you? [45:14.030 --> 45:14.270] Yes. [45:14.790 --> 45:15.290] No problem. [45:15.630 --> 45:16.030] Please. [45:16.030 --> 45:18.750] Let's each take a parting, one sentence parting shot. [45:19.410 --> 45:22.410] Just to, since we have to be out of here right now. [45:22.810 --> 45:23.010] Okay. [45:23.210 --> 45:24.330] Well, thank you very much. [45:24.330 --> 45:29.130] And I hope to see you at the second floor between 2 and 5 today and tomorrow. [45:29.370 --> 45:30.270] Thank you very much.