[00:00.000 --> 00:00.980] New York. [00:02.260 --> 00:04.060] You've almost made it through the first day. [00:04.300 --> 00:05.740] It'll be dark soon but don't leave. [00:05.900 --> 00:07.660] There's plenty more coming. [00:08.760 --> 00:14.300] You can check out the Robert Steele's books if you'd like at the DVD purchase area. [00:14.320 --> 00:21.540] He's going to be selling them through midnight minus a minute or two tomorrow night when he goes on for his multi-hour spy improv. [00:21.860 --> 00:22.500] That'll be exciting. [00:24.440 --> 00:27.920] Later on tonight we got a couple things in the Zeus room in the fourth track. [00:28.200 --> 00:32.220] We got an extravaganza of film. [00:32.400 --> 00:33.480] All kinds of things going on. [00:33.680 --> 00:35.200] Make sure you plan to hang around. [00:36.180 --> 00:37.840] Up next is understanding. [00:38.960 --> 00:39.440] Complexity. [00:40.500 --> 00:43.860] We're going to see some locks, I think. [00:44.880 --> 00:45.460] This is Mark. [00:45.600 --> 00:46.220] I didn't get your name. [00:47.120 --> 00:47.600] Tomáez. [00:48.220 --> 00:48.900] Tomáez, sorry. [00:49.060 --> 00:50.000] Another Tomáez. [00:50.000 --> 00:50.680] Another, another. [00:51.020 --> 00:51.100] Yeah. [00:51.820 --> 00:52.500] Welcome, everyone. [00:52.680 --> 00:52.960] Thank you. [00:53.580 --> 00:54.400] There you go. [00:54.860 --> 00:55.980] Good afternoon, everybody. [00:56.860 --> 01:01.540] We're going to talk today about undoing complexity and high-security locks. [01:02.080 --> 01:03.760] Great turnout this afternoon. [01:03.940 --> 01:04.700] Thanks for all coming. [01:05.420 --> 01:09.040] We were talking a little while ago about how to start this off. [01:09.380 --> 01:19.900] And we thought we'd start it off the way we started off an 18-month Odyssey research project that ended in the release of a book last week. [01:19.900 --> 01:22.780] on cracking Medico High Security Locks. [01:22.920 --> 01:27.420] Many of you this morning were at John King's lecture on his MediCoder. [01:27.600 --> 01:28.640] And this is a continuation. [01:29.560 --> 01:35.240] And so what we really thought we would do to start the festivities this afternoon. [01:35.240 --> 01:37.720] And let me introduce everybody. [01:37.900 --> 01:42.520] This is Tobias Bluzmanis, my co-author on our Medico book. [01:43.080 --> 01:49.960] Toby is from Venezuela, lives in Miami, and is a locksmith for about, what, 20 years? [01:49.960 --> 01:51.020] 15 years? [01:51.160 --> 01:51.620] Used to be. [01:51.680 --> 01:52.740] Used to be. [01:52.920 --> 01:52.940] Used to be. [01:52.940 --> 01:53.220] Yeah. [01:53.360 --> 01:54.400] He's no longer working. [01:55.300 --> 02:00.660] And worked for a Medico dealer for about 10 years. [02:00.860 --> 02:03.400] And is intimately familiar with Medico. [02:03.920 --> 02:12.600] Had actually contacted me in my capacity as a lawyer a couple years ago on a decoder that he invented for Medico. [02:12.740 --> 02:17.420] And we became really close friends and embarked on our research project. [02:17.420 --> 02:18.460] This is Matt Fiddler. [02:18.600 --> 02:21.560] We've lectured a number of times here before. [02:21.880 --> 02:27.040] And so we're going to talk about the real world of high security and undoing complexity. [02:27.360 --> 02:30.260] What we thought we would do is introduce this. [02:30.660 --> 02:35.460] We have some Medico cylinders here, both profile from Europe and U.S. [02:35.640 --> 02:38.200] These are all six pin Medico locks. [02:38.380 --> 02:39.660] They're all factory standard. [02:40.580 --> 02:42.080] This one's six, actually. [02:42.700 --> 02:45.400] The profile cylinders from Europe are five pin. [02:45.540 --> 02:46.580] The U.S. are six pin. [02:47.260 --> 02:50.720] We've got a deadbolt cylinder. [02:51.020 --> 02:53.200] And we've got a mortise cylinder. [02:53.660 --> 02:55.160] These are both six pin. [02:55.920 --> 02:57.280] We're opening these. [02:57.480 --> 02:57.920] We're bumping. [02:58.000 --> 03:00.380] Now, you have to keep in mind these are bump proof locks. [03:01.180 --> 03:16.820] According to the manufacturer, we're opening these with one of four keys that we derive from our research that will virtually open any biaxial or M3 cylinder in the world that's non-master keyed. [03:18.880 --> 03:20.220] That lock is open. [03:21.600 --> 03:23.980] Now, I want... [03:24.340 --> 03:29.840] This is... and everybody at Medico challenged us and said there's nothing in these locks. [03:31.400 --> 03:37.160] This is the same kind of lock that the 12-year-old girl opened at DEFCON last year when we spoke out there. [03:37.160 --> 03:41.200] This is a high-security Medico cylinder bump proof. [03:42.200 --> 03:42.340] Matt? [03:43.420 --> 03:47.400] And Toby has got a profile cylinder. [03:47.440 --> 03:50.800] And while these guys are opening those, we're going to try to open this one. [03:50.800 --> 03:53.260] And then I'll explain why it's so difficult. [03:54.340 --> 03:55.160] Oh, come on. [03:56.260 --> 03:58.360] And we thought we'd begin this way. [03:58.620 --> 03:59.380] And this one's open. [04:15.820 --> 04:17.580] Toby, here, do this while I'm talking. [04:17.680 --> 04:19.120] And then we'll explain why. [04:20.400 --> 04:23.580] So, that's how this research project began. [04:24.300 --> 04:26.140] I had met with Medico. [04:27.240 --> 04:29.540] We used to be on a really friendly basis. [04:29.800 --> 04:30.780] Long term. [04:31.860 --> 04:33.880] Not anymore, unfortunately. [04:34.400 --> 04:37.200] Not really our desire, but that's the way it turned out. [04:37.440 --> 04:41.140] And so, Toby and I embarked on an 18-month project. [04:41.140 --> 04:57.860] Once we figured out that we could bump open a Medico cylinder, and as we'll go through this, Medico had a press release on August 4th, 2006, after we introduced Jenna Lynn to the world at DEFCON, and Medico announced their locks were bump-proof. [04:59.400 --> 04:59.960] Okay. [05:01.080 --> 05:02.360] Now, let me explain to you. [05:02.560 --> 05:03.860] Toby just opened this lock. [05:04.200 --> 05:07.840] Normally we can do this in about 15 seconds. [05:08.360 --> 05:09.360] I'll try it again. [05:09.660 --> 05:09.920] Okay. [05:10.320 --> 05:12.640] Because I'm a little bit disappointed. [05:12.940 --> 05:14.360] That's our normal time. [05:15.060 --> 05:18.660] The distinguishing feature... How many of you were at John's lecture this morning? [05:19.600 --> 05:19.860] Okay. [05:20.020 --> 05:20.520] Good show. [05:20.660 --> 05:21.180] Good show. [05:22.460 --> 05:25.140] This lock has four ARX pins in it. [05:26.180 --> 05:29.300] These are the ARX pins, and we loaded these. [05:29.440 --> 05:32.840] These were supplied to us from a senior representative at Medico. [05:33.540 --> 05:36.160] This is a brand new profile cylinder. [05:36.760 --> 05:38.060] Four ARX pins. [05:38.240 --> 05:39.220] One would be enough. [05:39.460 --> 05:40.240] There's four of them. [05:40.420 --> 05:42.460] We can routinely open this. [05:42.560 --> 05:44.160] We're not saying we can open all of them. [05:44.320 --> 05:54.720] But if anyone in the security field or that has security responsibility here thinks that ARX pins are the answer, they're really not. [05:54.980 --> 06:00.240] It's the end of the beginning rather than the beginning of the end. [06:00.240 --> 06:02.900] And so it is a problem. [06:02.900 --> 06:05.240] It does not solve all the problems. [06:05.440 --> 06:10.860] And so what we're going to talk about today is reality and high security locks and complexity. [06:11.200 --> 06:11.520] Matt? [06:11.820 --> 06:12.160] All right. [06:12.220 --> 06:13.040] Let's switch this over. [06:13.520 --> 06:16.560] So as Mark said, we're going to go through some background. [06:16.780 --> 06:20.080] We'll try not to duplicate too much that John did through his talk. [06:20.560 --> 06:22.000] But let's get to this. [06:22.100 --> 06:25.560] So mechanical locks are typically the first security barrier. [06:25.560 --> 06:30.700] As John talked about when people ask questions, you know, what locks were on John's house. [06:31.500 --> 06:33.460] Often they're the only security barrier. [06:35.280 --> 06:38.260] And you have to ask yourself, you know, what are you protecting? [06:39.260 --> 06:44.720] And what sort of time and access should be considered to protect an entity? [06:46.140 --> 06:51.640] Most locks do appear secure as you look at these locks, as you look at the profiles, the keyways to them. [06:51.860 --> 06:53.320] They look very, very difficult. [06:53.760 --> 06:54.980] But many are not. [06:55.620 --> 06:57.160] You have to understand the ratings. [06:57.300 --> 07:02.900] And we're going to get into some of the UL 437 and BHMA and ANSI ratings. [07:02.920 --> 07:05.600] And what those mean for high security locks. [07:05.600 --> 07:08.280] And then we'll dive into the layers of security. [07:09.000 --> 07:15.400] Really, the methodology by which we're able to go through and systematically defeat these locks. [07:16.220 --> 07:25.560] We'll talk about disclosure, full disclosure, and, you know, the impact to the manufacturers, to the consumers. [07:26.380 --> 07:31.380] The manufacturers don't often know and often don't disclose these defects. [07:32.940 --> 07:36.940] You know, the question to you is why... someone else just opened one. [07:37.920 --> 07:39.280] Why is this important? [07:39.540 --> 07:41.620] Well, many of you are in IT. [07:42.200 --> 07:50.600] And from an IT security perspective, it's incumbent upon you to protect your information, your server rooms. [07:51.520 --> 07:59.260] So it's important that you realize the risk posed with certain locks, what the standards mean, and what it means to you. [07:59.260 --> 08:04.300] And this is especially important with high security locks because they really are used for critical infrastructure. [08:05.100 --> 08:10.200] White House, Pentagon, Royal Family in the UK, weapons systems. [08:10.440 --> 08:13.640] These locks are relied upon to keep people out. [08:13.900 --> 08:20.680] And so they have profound importance and you really need to understand that everything that glitters may not be gold. [08:20.680 --> 08:27.720] And I think it was Doug Fair today, you know, talked about defense in depth, multiple layers of security. [08:27.720 --> 08:29.860] But security clearly begins with the lock. [08:30.920 --> 08:35.040] So for us, as researchers, we find locks puzzles. [08:35.600 --> 08:40.020] The more complex, the more features, the more difficult they are to open. [08:40.720 --> 08:47.220] But with that comes more complexity, comes more bugs, more vulnerabilities, and more exposures for us to uncover. [08:48.020 --> 08:49.680] All of them are apparently secure. [08:50.080 --> 08:58.840] Many of these 30-year-old designs, to our knowledge, some of these have never been discovered, some of these vulnerabilities. [08:59.220 --> 09:00.520] And I might comment on that. [09:00.620 --> 09:02.960] And actually, Medeco is a 40-year-old design. [09:02.960 --> 09:06.480] It's ostensibly the best in the industry. [09:07.360 --> 09:10.400] And it took us a long time. [09:10.400 --> 09:13.080] But we found a design... [09:13.080 --> 09:14.700] I won't call it a flaw. [09:14.980 --> 09:19.720] It's a design issue that's a vulnerability that had never been exploited before. [09:20.040 --> 09:21.220] And we figured out... [09:21.220 --> 09:24.440] There was 12 steps that we went through to exploit this lock. [09:24.600 --> 09:26.020] And we never thought we could do it. [09:26.280 --> 09:30.140] We actually shared all our results with the company every step of the way. [09:30.280 --> 09:32.100] They never would confirm or deny anything. [09:32.100 --> 09:34.080] So we just kept opening their locks. [09:34.280 --> 09:35.840] And kept proceeding. [09:36.260 --> 09:38.160] And now, of course, it's a big problem. [09:38.400 --> 09:46.140] So, the important thing is, just because everybody tells you it's secure and there's patents, don't believe it. [09:46.280 --> 09:48.140] Always look at it with skepticism. [09:48.300 --> 09:49.920] There's some very good locks out there. [09:50.260 --> 09:55.960] I represent some lock manufacturers here and in Europe that make really, really good locks. [09:56.340 --> 10:00.460] And, you know, we can't find the flaws, but that's not to say they're not there. [10:00.460 --> 10:02.580] But always view with skepticism. [10:02.760 --> 10:03.020] Yeah. [10:03.380 --> 10:04.060] Next slide. [10:04.700 --> 10:12.900] Well, one last point on the last bullet is that, you know, often there's cuts made to costs in implementing these designs. [10:12.900 --> 10:20.800] So, a very expensive lock to manufacture, they may at the last minute implement very inexpensive components. [10:20.800 --> 10:23.680] And, often those are the ones we're able to exploit. [10:23.860 --> 10:24.060] Right. [10:25.280 --> 10:27.140] And, it's not apparent at all. [10:27.360 --> 10:29.180] And, I make one other comment. [10:29.680 --> 10:31.740] If you, probably many of you haven't read it. [10:31.860 --> 10:37.940] On my blog, we posted two editorials about responsible disclosure, which we'll get to in a little while. [10:38.700 --> 10:45.200] But, Medeco has now recognized the locksport community and what John King did. [10:45.600 --> 10:50.080] The editorial that we posted, it's not due to all altruistic motives. [10:50.280 --> 10:51.380] They did it for a reason. [10:51.980 --> 11:03.960] The irony is that many of the locksport enthusiasts and hackers and IT professionals and security people are the ones that have to find the bugs that the manufacturers cannot find. [11:03.960 --> 11:07.160] And, so, it's been a long time coming. [11:07.680 --> 11:16.040] Matt and I gave a lecture four years ago where we proposed a joint partnership between manufacturers, law enforcement, and the hacking and locksport community. [11:16.260 --> 11:17.600] Nobody would buy into it. [11:17.720 --> 11:24.800] So, it's coming of age and we need a lot of diverse, very clever people looking at locks for vulnerabilities. [11:25.440 --> 11:26.900] It's the thing to do. [11:27.280 --> 11:33.120] So, you need to understand the difference between conventional and high security locks and what that means. [11:33.120 --> 11:37.080] Conventional cylinders, obviously, are easy to pick and bump open. [11:37.240 --> 11:43.300] If you go down to the village, you'll see and learn how to pick and bump open many, many conventional cylinders. [11:43.500 --> 11:44.680] There's no key control. [11:44.860 --> 11:47.040] So, there's no patents protecting the key. [11:47.280 --> 11:50.880] There's no proprietary keyways or additional restrictions. [11:51.580 --> 11:53.560] And very limited forced entry. [11:53.960 --> 11:54.080] Yeah. [11:54.240 --> 12:00.820] Conventional locks are everything from quick set to me, arguably, the worst lock in America, but they sell them everywhere. [12:00.820 --> 12:04.420] This is what Jenna Lynn opened two years ago at DEFCON. [12:04.620 --> 12:11.000] To the highest security lock, but the conventional locks have very limited security capabilities and you need to understand that. [12:11.460 --> 12:18.640] And so, we're differentiating them because some of you folks in your job select high security cylinders. [12:18.640 --> 12:24.760] And in many cases, and let me tell you, the next book is about multi-lock. [12:25.300 --> 12:27.340] The first book was about Medeco. [12:27.800 --> 12:32.540] They're not the only high security lock on the block and lots of them have problems. [12:32.860 --> 12:34.920] And so, we're going to talk about them. [12:35.240 --> 12:41.720] And so, the distinction you need to understand is conventional locks can only go so far in protecting you. [12:41.720 --> 12:43.180] And they can be bumped. [12:43.380 --> 12:45.080] There's no key control to speak of. [12:45.580 --> 12:49.640] There's a lot of problems, but they're more... they're less expensive. [12:50.020 --> 12:52.780] So, I threw up on the screen this mortise cylinder. [12:52.920 --> 12:59.440] This mortise cylinder, and I don't know if you can make it out right on the tip of my finger here, is a UL with a little circle around it. [12:59.560 --> 13:01.860] This is a UL 437 rated lock. [13:01.860 --> 13:06.320] And what that means is there's high tolerances to it. [13:06.440 --> 13:08.540] There's resistance to forced entry. [13:08.740 --> 13:10.440] There's certain security pins in it. [13:10.580 --> 13:12.580] Certain hardened anti-drill pins. [13:13.520 --> 13:18.460] It must resist forced and covert and surreptitious entry for a period of time. [13:18.680 --> 13:20.900] And there's key control requirements against that. [13:21.000 --> 13:25.960] But as you can see when we began this presentation, we're pretty easily compromised. [13:26.800 --> 13:28.700] Yeah, that's a couple seconds to bump open. [13:28.840 --> 13:30.220] Now, again, that's not all of them. [13:30.820 --> 13:41.080] And that particular lock, which happens to be a mortise cylinder, we're going to disclose next month a very serious issue that will allow that to be opened very easily. [13:41.400 --> 13:41.960] Next slide. [13:42.700 --> 13:43.600] Oh, go ahead. [13:43.800 --> 13:45.360] So, layers of security. [13:45.360 --> 13:56.900] And this is really critical to understand the layers of security, the layers inherent in Medeco, and how we're able to expose and tear down those layers, much like you would in software, and exploit them. [13:57.400 --> 13:59.620] Obviously, each one is a separate point of failure. [13:59.620 --> 14:03.380] They add additional complexity, and with that comes additional vulnerability. [14:04.440 --> 14:13.440] We're going to show some pictures here of different layers of security or components inherent within high security and conventional security locks. [14:13.660 --> 14:16.020] Sliders, sidebars, check pins. [14:16.240 --> 14:23.980] There's a whole host of additional components that can be added to high security cylinders to increase their resistance to attack. [14:27.420 --> 14:28.320] So, go ahead. [14:28.620 --> 14:28.740] All right. [14:28.940 --> 14:38.360] Well, from an engineering standpoint, when we look at layers of security, when we want to attack a lock, and when we started with our project, we looked at a number of parameters. [14:38.360 --> 14:48.560] And, obviously, we want to know how many layers and the ability to exploit each design feature, and if they're integrated layers of security, or are they separate? [14:48.820 --> 14:49.920] How do they work? [14:50.020 --> 14:54.480] In the Primus, for example, there's two independent layers of security. [14:55.260 --> 14:56.280] This is the... [14:56.280 --> 14:58.480] Can somebody turn up this audio just a little bit? [14:59.460 --> 15:00.180] There you go. [15:00.320 --> 15:00.580] Thank you. [15:01.340 --> 15:09.220] In the Schlage Primus and ASSA locks, there's separate layers of security with the side bit milling. [15:09.380 --> 15:09.820] There you go. [15:09.820 --> 15:13.180] So, the key is very different than Medeco. [15:13.480 --> 15:20.100] In Medeco, everything... the cuts are both angled and vertical in one combined cut. [15:20.340 --> 15:24.600] In the ASSAs and Abloys and some other locks, they're separate functions. [15:24.980 --> 15:36.860] We went through a really detailed analysis when we prepared our book to tell everybody the difference so you understand the pluses and minuses of four different kinds of high security locks. [15:36.860 --> 15:41.280] So, when we got into Medeco, you'd understand what's good, what's bad. [15:42.500 --> 15:42.600] Okay. [15:43.140 --> 15:45.900] So, convention layers of security, there's really one. [15:46.100 --> 15:51.600] And we don't need to dwell on this slide, but it's the shear line. [15:51.780 --> 15:52.980] And that's it. [15:53.260 --> 15:58.160] You can't do any more with a conventional pin tumbler lock than make a shear line. [15:58.300 --> 16:04.020] So, you can put mushroom and security tumblers like you see on the left-hand slide, the green lock. [16:04.780 --> 16:07.700] That's a mushroom pin to make picking more difficult. [16:08.020 --> 16:15.520] These locks that we've opened today by bumping all have at least two or three mushroom pins in them. [16:16.320 --> 16:25.900] And so, we've... and I might tell you that Toby's best time at lock picking, a six-pin Medeco cylinder is 27 seconds. [16:25.900 --> 16:28.240] Mine is about two minutes. [16:28.600 --> 16:31.160] But I don't pick locks as much as Toby does. [16:31.400 --> 16:33.300] I bump a lot of them, but I don't pick them. [16:33.600 --> 16:39.860] So, the bottom line is on conventional layers of security, there's really just one that you have to understand. [16:40.060 --> 16:41.480] And that's why they could be bumped open. [16:42.020 --> 16:44.360] Now, more layers of security. [16:44.700 --> 16:49.320] These five pins on top are ARX pins, which we just bumped open. [16:49.320 --> 16:53.500] These are Medeco's answer to high, high security. [16:54.240 --> 17:07.220] And these, as a point of history, were created about 1993, 1994, in response to a very sophisticated attack that came from Europe using wire probes. [17:07.440 --> 17:14.660] So, these pins, again though, it's another layer of security, but sort of, but not exactly. [17:14.660 --> 17:21.320] The other layer of security in the Medeco M3, you see at the bottom, which is the step on the side of the key. [17:21.580 --> 17:26.860] It does not, it's listed in their patent as providing another level of security, it does not. [17:27.260 --> 17:35.640] A paper clip or a piece of wire that offsets the slider 40 thousandths of an inch, it's, that layer of security is gone. [17:36.440 --> 17:42.580] And here's an image of the paper clip inserted into the Medeco cylinder by passing the slider. [17:42.600 --> 17:42.980] Yeah, very, very high tech. [17:42.980 --> 17:44.580] No, that doesn't open the lock. [17:44.880 --> 17:47.220] Now, the paper clip doesn't open the lock. [17:47.380 --> 17:51.460] The paper clip neutralizes that particular layer of security. [17:51.820 --> 17:52.620] Okay, next slide, Matt. [17:53.440 --> 17:54.640] Okay, let's go back. [17:56.400 --> 18:01.560] Okay, so again, why are high security locks important to a lot of you folks? [18:01.560 --> 18:14.360] Because you have critical infrastructure that needs protecting assets, people, and you need to rely on them when you do not want somebody to enter. [18:14.640 --> 18:15.900] That's the bottom line. [18:16.140 --> 18:24.120] They can hack into your systems all they want, but if they can enter into your server room, or your credit card room, or your cash vault, or whatever, it's over. [18:24.120 --> 18:37.060] And so, high security locks, you specify because of the standards that UL and the Builders Hardware Manufacturers Association promulgate, because you don't have the ability to test your own locks. [18:37.200 --> 18:40.260] So, they do it for you and publish standards. [18:40.260 --> 18:46.760] The problem is, as we very well document, the standards don't address all the issues. [18:46.960 --> 18:49.600] And that really is a primary problem. [18:49.980 --> 18:56.080] Unless you attack the lock the way the standards address it, they won't even look at the method of attack. [18:56.520 --> 19:03.220] When we broke the Medeco deadbolt last year with a $2 screwdriver, we filed a complaint with UL. [19:03.340 --> 19:04.380] They wouldn't even address it. [19:04.440 --> 19:06.240] They said, it's not in the standard. [19:06.420 --> 19:07.660] Don't talk to us about it. [19:07.660 --> 19:10.180] Change the standard before we look at the lock. [19:10.520 --> 19:12.680] And so, it's a perfect catch-22. [19:13.160 --> 19:13.260] Next. [19:14.100 --> 19:15.980] Okay, so critical design issues. [19:16.340 --> 19:18.480] Again, there's multiple security layers. [19:18.640 --> 19:22.280] The question is, is there more than one point of failure? [19:22.280 --> 19:27.800] And this is really critical, because each security layer must be independent. [19:28.260 --> 19:33.460] The security layers all operate in parallel, so if one fails, you still can't open the lock. [19:33.460 --> 19:37.960] So, in Medeco's case, there's three security layers in their latest generation. [19:38.780 --> 19:40.720] We've neutralized two out of the three. [19:40.920 --> 19:45.700] Pick the third like a conventional pin tumbler lock, or we neutralize all three. [19:46.260 --> 19:46.600] Next. [19:47.600 --> 19:48.780] Three design factors. [19:49.780 --> 19:54.060] The standards require three design parameters for high security. [19:54.060 --> 19:58.340] This is what you guys were relying upon. [19:58.560 --> 20:08.980] And that's their resistance to forced entry, their resistance to covert and surreptitious entry, and their key control, or as we prefer to call it, key security. [20:08.980 --> 20:17.680] And key security means you can't knock off the blanks, you can't replicate the keys, you can't duplicate them, and you can't simulate them. [20:17.800 --> 20:30.300] So, when you're handed a key as an employee of a high security facility, the assumption is that you can't go down to the local locksmith or hardware store or Home Depot and duplicate that key. [20:30.300 --> 20:32.600] Well, that's a real problem. [20:32.860 --> 20:34.220] So, Matt, bring up the... [20:35.920 --> 20:44.020] This is a Medeco deadbolt cylinder with a paper clip in it and a simulated key that we show you how to do for a dollar. [20:44.980 --> 20:50.200] This will bypass any Medeco M3 keyway. [20:50.480 --> 20:59.560] Even the most restricted keyways that you guys think are proprietary, restricted, nobody can get, are factory controlled, don't believe it. [20:59.560 --> 21:05.140] The problem is there are layers of complexity when they came out with this lock in 2003. [21:05.660 --> 21:09.720] They widened the keyway by seven thousandths of an inch. [21:09.920 --> 21:11.780] What does seven thousandths mean? [21:12.240 --> 21:24.620] Well, not much to you guys, but it meant a lot to us because we could stick our little simulated key in and actually duplicate a working key like it's in that lock and bypass every keyway. [21:24.720 --> 21:31.140] Which means we can make bump keys, we can make code setting keys, we can make the actual key for the lock, no key control. [21:31.700 --> 21:33.020] Major, major problem. [21:33.140 --> 21:41.160] As we note, the fastest way to open a lock is obviously with a key, whether it's replicated, simulated, or duplicated. [21:41.860 --> 21:42.000] Matt? [21:42.160 --> 21:43.580] So, this slide is pretty interesting. [21:43.740 --> 21:49.520] And we gave a talk last year or the year before on standards, UL and BHMA. [21:49.520 --> 22:00.980] And we detailed and provide matrices that depict the time, the certain tools that are required to, or that are accepted by the standards. [22:01.580 --> 22:08.720] So, for forced entry, well, for covert entry, it's ten or fifteen minutes depending which standard. [22:09.620 --> 22:12.580] But they do restrict the types of tools that can be used. [22:12.580 --> 22:24.000] So, as Mark said, the two dollar screwdriver that was fashioned for the, for the deadbolt attack, was not considered to be acceptable because it wasn't in the list of tools. [22:24.300 --> 22:34.080] And UL does have a requirement that all the criminals sign a form that they will follow the mandated tool requirements for breaking into locks, so that I guess you don't have to worry about it. [22:34.080 --> 22:39.380] And in regards to bumping, the standards don't contemplate future attacks. [22:39.500 --> 22:43.400] So, as far as zero-day attacks, they don't exist in the standards perspective. [22:43.980 --> 22:50.720] It has to meet that matrix, has to meet the time criteria, the certain tools, and method by which they, they apply those. [22:51.000 --> 22:53.400] Otherwise, it doesn't apply. [22:55.680 --> 22:57.620] Okay, so attack methodology. [22:57.900 --> 23:00.460] Here's what you all ought to come away with from this standpoint. [23:00.460 --> 23:03.820] Don't assume or believe anything. [23:04.160 --> 23:10.720] When a manufacturer tells you their locks are bump proof, don't believe it. [23:11.080 --> 23:13.640] If they're pick resistant, pick proof. [23:13.960 --> 23:15.900] Take it with skepticism. [23:16.220 --> 23:19.340] It's not that it may not be true in certain instances. [23:19.720 --> 23:27.140] The problem is that a lot of manufacturers, a lot of high-security manufacturers cannot open their own locks. [23:27.680 --> 23:28.800] They make them. [23:29.000 --> 23:29.980] They design them. [23:30.140 --> 23:31.680] They all went to engineering school. [23:32.300 --> 23:34.840] They make things work really well. [23:35.060 --> 23:36.740] And these are very high-tolerance locks. [23:36.900 --> 23:38.480] These are not simple locks. [23:38.960 --> 23:41.800] But they didn't grow up breaking things. [23:42.020 --> 23:50.380] And that has to be an embedded thought process, as lots of you guys know, in order to be able to crack locks. [23:50.560 --> 23:51.360] They're puzzles. [23:51.360 --> 23:56.820] And they don't hire design engineers, for the most part, that know how to do this. [23:57.920 --> 23:58.920] Here's the theory. [23:59.380 --> 24:02.820] Medeco does not know how to bump open their own locks. [24:02.980 --> 24:04.260] That's where this all started. [24:04.460 --> 24:11.000] And it was suggested to some of their senior technical people, watch the video of Jenna Lynn, the 12-year-old. [24:11.180 --> 24:13.080] She figured out how to do it. [24:13.080 --> 24:14.320] They haven't. [24:14.460 --> 24:17.120] And this is the problem, and it's putting everybody at risk. [24:18.060 --> 24:18.400] Okay. [24:18.760 --> 24:22.200] So, here's really our primary rule. [24:22.540 --> 24:25.220] The key never unlocks the lock. [24:25.420 --> 24:27.440] And everybody says, what does that mean? [24:27.720 --> 24:29.480] The key doesn't unlock the lock. [24:29.680 --> 24:34.220] The key actuates the mechanism that controls the bolt or latch. [24:34.220 --> 24:41.200] If you can get to that and circumvent the actual internal locking mechanism, you're going to open the lock. [24:41.360 --> 24:42.820] We call that mechanical bypass. [24:43.240 --> 24:52.320] And that is what we did in the Medeco deadbolt attack, that they had to urgently change the design of their locks, not once, but twice. [24:52.640 --> 24:55.020] And before they got it sort of right. [24:55.500 --> 24:58.340] And so, the lock never unlocks the lock. [24:58.420 --> 25:05.960] And if you can feel any of the internal components moving against other internal components, you're going to open the lock eventually. [25:06.440 --> 25:07.440] And that was Alfred C. [25:07.560 --> 25:12.280] Hobbs, the famous American locksmith 150 years ago, that figured out that program. [25:13.880 --> 25:14.220] Okay. [25:14.520 --> 25:19.560] So, very quickly, Medeco is the dominant high-security lock manufacturer in the U.S. [25:19.600 --> 25:21.160] They started 40 years ago. [25:21.680 --> 25:27.040] They own 70-plus percent of the high-security market in this country. [25:27.260 --> 25:30.520] They also sell all over the world, and mainly in the U.K. [25:30.660 --> 25:36.640] and France, South America, and really they're relied upon, this is the prize. [25:36.840 --> 25:44.260] This is absolutely the prize that everybody's been trying to go after, because it presents such a problem to covert entry teams. [25:44.460 --> 25:47.660] So, that is one of the reasons we went after it. [25:48.340 --> 25:50.620] Really, it's because they told us we couldn't do it. [25:50.620 --> 25:57.380] And they really were good friends of mine, and they said, you can't do this. [25:58.400 --> 25:58.920] Okay. [25:58.920 --> 26:00.460] So, we went and did it. [26:00.540 --> 26:03.140] And we kept doing it, and we kept getting more and more sophisticated. [26:03.600 --> 26:07.980] But the Medeco history, from our standpoint, is only part of the issue. [26:08.320 --> 26:13.900] What you guys really need to be concerned about is the methodology of how we did it. [26:13.900 --> 26:15.760] And that's really what we outlined. [26:16.100 --> 26:20.460] It's where we started, and how we worked our way through the problems. [26:20.600 --> 26:22.120] Because we had to crack their codes. [26:22.400 --> 26:24.980] We had to overcome a lot of difficulties. [26:25.860 --> 26:31.060] In order to come up with four keys that would open all their locks, we had to crack their codes. [26:31.060 --> 26:35.740] To figure out how to make four keys do 46,000 different combinations. [26:36.340 --> 26:42.420] And so, we figured it out, because there was all kinds of design issues that we figured out how to exploit. [26:42.700 --> 26:47.720] So, the bottom line is, Medeco came out with their original lock in 1970. [26:47.720 --> 26:51.900] Their second generation in about 85, called the Biaxial. [26:52.320 --> 27:00.500] The third and current generation came out in 2003, which is called the M3, which has the little slider, which we bypassed with the paper clip. [27:00.940 --> 27:04.160] In 2006, bumping was introduced to America. [27:05.100 --> 27:07.240] They announced their locks were bump proof. [27:07.600 --> 27:11.500] In 2007, it was revised to virtually bump proof. [27:11.920 --> 27:14.380] Now, it's virtually resistant. [27:17.140 --> 27:22.240] And, you know, actually, Matt said we should raffle off one of the copies of my book. [27:22.400 --> 27:27.040] If somebody would really come up with the best definition of virtually resistant, you get the book. [27:27.680 --> 27:30.840] And our last slide, we'll show you how we're going to do that. [27:30.840 --> 27:36.800] And, by the way, Medeco has made no public statements at all since we started this. [27:37.220 --> 27:37.680] Go. [27:38.500 --> 27:41.200] So, deconstructing lessons of security. [27:41.200 --> 27:45.170] What did we learn from this 18-month odyssey? [27:46.370 --> 27:48.470] We discovered serious vulnerabilities. [27:49.050 --> 27:55.950] As I said, what we really learned and confirmed is don't believe anything anybody tells you about high security locks. [27:56.570 --> 28:01.290] And there's serious potential security issues. [28:01.750 --> 28:09.870] And it really... and it resulted, of course, in us sitting down and really developing how to do this and writing about it. [28:09.870 --> 28:10.390] Go. [28:10.850 --> 28:11.390] Go ahead. [28:11.610 --> 28:13.650] So, why is this important? [28:14.030 --> 28:21.770] You know, as we said, the methodology, the approach by which you can go ahead and look at something that someone tells you is not possible, is not doable. [28:22.770 --> 28:25.790] Clearly, the appearance of security versus the real world. [28:26.630 --> 28:33.270] Medeco claims that these locks are bump proof, ultimately changing several iterations. [28:35.670 --> 28:42.210] Their knowledge and representations of what these locks can do is critical to how you assess these. [28:42.630 --> 28:47.890] Many people rely on a manufacturer's claims and, again, rely on those standards. [28:47.890 --> 28:50.210] And we're here to tell you that's not true. [28:50.210 --> 28:53.050] Again, we wanted to demonstrate our methodology. [28:53.050 --> 28:55.970] We'll go into the four components of that coming soon. [28:56.230 --> 28:59.690] And, obviously, advocating more secure lock designs. [29:00.730 --> 29:02.910] Medeco made many, many mistakes. [29:03.190 --> 29:04.050] They failed to listen. [29:05.210 --> 29:15.730] We believe, and as John spoke about this morning, and we further talked about with the ARX pins, that there's been embedded problems for many, many years. [29:17.230 --> 29:25.490] The problems got compounded, as we said, as additional features and functionality to extend patents and to increase security, and their locks were added. [29:25.870 --> 29:27.830] Additional vulnerabilities were added, as well. [29:28.350 --> 29:29.850] They failed to connect the dots. [29:30.030 --> 29:34.050] They weren't able to duplicate, you know, throughout this exercise over the last 18 months. [29:34.230 --> 29:35.270] They've been briefed. [29:35.290 --> 29:35.950] They've been notified. [29:36.150 --> 29:36.990] They've been contacted. [29:37.210 --> 29:43.010] They've been provided all the details of our findings, and they couldn't connect the dots. [29:43.010 --> 29:46.730] Yeah, and this is the best in the industry, honestly. [29:47.130 --> 29:50.210] And they're a really good company, but they didn't listen. [29:50.370 --> 29:50.870] It's arrogance. [29:51.350 --> 29:55.890] And they thought they knew everything, and they thought this was impossible, and that we were crazy. [29:56.410 --> 30:00.790] And, you know, and I kept telling them, that may be a separate incident, but we're still opening your locks. [30:04.460 --> 30:05.980] Okay, so here's how... [30:05.980 --> 30:10.700] We always did maintain our sense of humor throughout this project, even if they didn't. [30:11.820 --> 30:13.580] Medeco invented the twisting pin. [30:13.840 --> 30:15.080] It is a brilliant design. [30:15.440 --> 30:19.460] It was one of two that I think is the most innovative in this century in lock design. [30:19.740 --> 30:24.240] And this is just a photograph of a biaxial key showing the angled cuts. [30:24.480 --> 30:26.500] And the cylinder at the bottom... [30:26.500 --> 30:29.660] This is a video that we did on the multimedia edition of our book. [30:29.880 --> 30:38.640] It shows how we set the sidebar code and the little red angles on a key next to it correspond to how the angles are set to open the lock. [30:39.360 --> 30:44.760] Okay, so again, there's three layers of security in a Medeco lock because it is high security. [30:45.520 --> 30:46.840] One is the shear line. [30:47.020 --> 30:54.360] Two is the sidebar, which must be retracted and is controlled by the angular cuts on the pins. [30:54.620 --> 30:55.800] And three is the slider. [30:56.020 --> 31:01.810] And as we showed, although they claim in their patent the slider is a security layer, that's theoretically true. [31:02.730 --> 31:08.630] But it can be bypassed with a piece of wire 40 thousandths inch thick, which just happens to be the normal paper clip. [31:08.930 --> 31:10.530] There's also ARX pins. [31:10.710 --> 31:12.030] So how do you open a Medeco lock? [31:12.050 --> 31:12.930] You lift the pins. [31:13.110 --> 31:14.290] You rotate the pins. [31:14.430 --> 31:15.670] You push the slider in. [31:15.750 --> 31:16.470] The lock opens. [31:16.690 --> 31:17.590] Very, very simple. [31:18.870 --> 31:22.510] So this is a cutaway that Toby produced. [31:22.750 --> 31:24.390] We shot a macro of it. [31:24.390 --> 31:27.030] This is a biaxial showing. [31:27.370 --> 31:29.230] And zoom in on the channels, Matt, real quickly. [31:31.010 --> 31:41.450] Okay, so you can see number four, the lavender arrow, is the channel in the pins that actually John is probing with his pick. [31:41.450 --> 31:48.630] And the sidebar leg, which is the yellow arrow number three, goes into that channel. [31:48.790 --> 31:54.110] When they all go into the channel, the sidebar retracts and the plug can turn. [31:55.730 --> 31:58.530] Okay, and this PowerPoint will be available. [31:58.690 --> 32:00.250] We don't expect you to follow all of it. [32:00.310 --> 32:03.210] But we use it really for lecturing and you guys can have it. [32:03.810 --> 32:08.490] So, and we just need to say the sidebar is Medeco security. [32:08.490 --> 32:12.290] So, if you defeat the sidebar, you defeat the lock. [32:12.570 --> 32:15.430] And so, that's really what we concentrated on. [32:15.590 --> 32:17.510] It was a very complicated problem. [32:17.710 --> 32:24.770] If you guys like really intellectual puzzles that have real world security implications, you'll love what we've done. [32:25.670 --> 32:30.230] We had to crack the sidebar and how to get the sidebar code. [32:30.450 --> 32:35.210] Because we can walk up to a lock and open it with no prior intelligence. [32:35.210 --> 32:36.930] We can pick it. [32:37.130 --> 32:38.050] We can bump it. [32:38.210 --> 32:50.090] We can create a special code setting key for which we've applied for several patents that one of these four keys will virtually open every Medeco lock in the world. [32:50.330 --> 32:51.750] That's their favorite term. [32:52.450 --> 32:57.010] So, that's... the sidebar is their security. [32:57.270 --> 33:02.690] And it's a 40-year-old design that really has not been changed in 40 years. [33:02.690 --> 33:12.110] And I got to tell you for one minute, when I went to Medeco as a lawyer to talk to him about Toby's decoder that he had invented before I met him... [33:12.110 --> 33:12.850] You like that. [33:12.910 --> 33:14.150] Yeah, I do like that. [33:14.310 --> 33:17.470] And their senior technical guy looked at me. [33:17.630 --> 33:20.970] We were having coffee at a locksmith convention. [33:20.970 --> 33:25.750] And he says, you mean that crackpot from Miami? [33:26.630 --> 33:28.210] He doesn't know anything. [33:28.450 --> 33:32.550] He's used a 30-year-old technology of wires to probe our lock. [33:32.770 --> 33:34.390] We're not dealing with him. [33:34.570 --> 33:40.270] And so, any of you need to get a hold of Toby, his email address is crackpot at security.org. [33:43.340 --> 33:45.280] That's all that works, but... [33:45.280 --> 33:45.320] Yeah. [33:45.640 --> 33:45.950] Yeah. [33:46.540 --> 33:47.190] Okay, next slide. [33:48.100 --> 33:51.080] Okay, so this is how the plug and sidebar... [33:51.080 --> 33:52.580] These are all the pins that are aligned. [33:53.170 --> 33:53.600] And... [33:53.600 --> 33:55.140] I think we've got to zoom in. [33:55.220 --> 33:55.670] There you go. [33:55.960 --> 33:56.410] Okay. [33:56.710 --> 34:02.450] So, this is what a Medeco lock plug looks like that is capable of being opened. [34:02.690 --> 34:05.520] The pins are all aligned at shearline, as you can see. [34:05.670 --> 34:08.960] And all the gates are aligned with the legs of the sidebar. [34:08.960 --> 34:13.520] So, the sidebar is being pushed in by one of our thumbs, so that that plug can turn. [34:13.960 --> 34:14.360] Next slide. [34:14.580 --> 34:17.000] This slide is locked. [34:17.380 --> 34:20.360] The pins are up and down, which would be in the plug and the shell. [34:20.880 --> 34:24.100] And, as you can see, the channels are not aligned. [34:24.220 --> 34:27.390] The pins are all twisted, so that this lock cannot be opened. [34:28.100 --> 34:28.620] Go ahead. [34:29.330 --> 34:33.790] So, again, we'll go through the different attacks, the exploit vulnerabilities. [34:34.640 --> 34:36.460] Reverse engineering, as Mark spoke about. [34:36.580 --> 34:37.560] The details are on the book. [34:37.560 --> 34:39.560] I'm not trying to plug the book, although I am. [34:41.140 --> 34:43.000] But, there's a lot of detail there. [34:43.100 --> 34:49.080] We don't have enough time to talk about how the sidebar code enumeration and code setting keys were created. [34:51.600 --> 34:52.700] What else we got here? [34:53.320 --> 34:57.950] Design enhancements for generations of lock by Axial and M3 and their new bi-level lock. [34:57.950 --> 35:11.180] So, again, and I'm beating this to death, but the introduction of additional features and functionality to add layers of security or to extend patents exposes and creates vulnerabilities. [35:11.180 --> 35:11.560] It can cause you a lot of trouble. [35:11.660 --> 35:12.960] And I might make one other comment. [35:12.960 --> 35:31.640] If any of you have integrated their new bi-level lock, which is their cheapened Medeco clone that has a sidebar that isn't one, you need to really understand that the implementation of bi-level in an M3 system can lead to the compromise of your entire facility. [35:31.640 --> 35:44.100] Because there's some design parameters that we discuss, we won't do it online, that compromise the security because they can be visually decoded with a little boroscope that we show you how to do that in a video. [35:45.040 --> 35:52.580] And so, the problem is, every time you do a new iteration of a lock to extend your patents, you can cause yourself a lot of trouble. [35:52.870 --> 35:52.980] Next. [35:53.790 --> 35:56.450] Okay, so we exploited all the design features. [35:57.060 --> 36:13.430] Basically, we coded the design, the code progression, how the geniuses at Medeco in the 1980s figured out the code progression, all the crypto boys, and the key bidding design tolerances, and all the keying rules. [36:13.680 --> 36:19.930] We took all this data, we mixed it all together in our heads, and we figured out how to use it against them. [36:20.140 --> 36:25.580] And we opened their locks by exploiting their best design features. [36:25.580 --> 36:26.260] Next. [36:27.310 --> 36:29.740] Okay, so the results of our project. [36:29.960 --> 36:31.000] Here's the payoff. [36:31.370 --> 36:31.930] Go ahead. [36:32.200 --> 36:35.870] So the payoff is, the title of the book, Open in 30 Seconds. [36:36.160 --> 36:42.330] Covert and surreptitious entry in as little as 30 seconds, or for Toby, 27 seconds. [36:42.830 --> 36:48.740] Forced entry, multiple techniques, 30 seconds, some much less than that. [36:48.740 --> 36:52.500] And it does truly affect millions and millions of locks. [36:52.700 --> 36:56.100] And complete, total ownage of key control. [36:56.330 --> 36:57.450] Is that a word, ownage? [36:57.620 --> 36:58.600] Yeah, it is a word. [36:59.850 --> 37:02.060] He's from Connecticut, you have to understand that. [37:03.520 --> 37:06.520] All right, so this is a picture of the four code setting keys. [37:06.520 --> 37:09.290] These are the four keys to the kingdom, as we call them. [37:09.870 --> 37:18.310] And these will, and you'll notice there's a specific lack of code detail on these keys, so you guys can't take these images and replicate them so easily. [37:19.240 --> 37:26.200] These keys, as I said, will virtually open every one of their non-master keyed cylinders that were produced according to the code book. [37:26.200 --> 37:30.310] There's one code book worldwide, pre-December 2007. [37:32.290 --> 37:36.850] So, we demonstrated early in the beginning the results of the project with bumping. [37:37.040 --> 37:41.580] We can reliably bump open virtually all biaxial and M3 locks. [37:42.600 --> 37:47.430] Produce bump keys on Medeco blanks, and simulated blanks. [37:47.500 --> 37:48.430] So, do you have that one, Toby? [37:48.980 --> 37:50.240] And that's really the problem. [37:50.240 --> 37:57.830] Because we have the capability of creating any blank for any Medeco M3 and lots of biaxial locks, we don't have any restrictions. [37:57.830 --> 38:02.220] We can also go extrapolate the top-level master key to own a system. [38:02.460 --> 38:07.600] And in a restricted keyway or proprietary keyway system, this is a big problem. [38:07.790 --> 38:15.020] Because if you've got access to keys, it's a primary requirement to crack the master key levels, the top-level master. [38:15.220 --> 38:19.160] And as you all know, if you have the TMK, you own the system. [38:19.370 --> 38:22.240] So, the first rule is you have to be able to get the blanks. [38:23.000 --> 38:25.600] Okay, and this is what a Medeco bump key looks like. [38:25.720 --> 38:26.980] It's a very complex key. [38:27.390 --> 38:31.640] You guys can come up here afterwards, or I think we've got a signing in the back. [38:31.850 --> 38:38.000] So, we'll show you the locks, or we're going to be in the lockpicking village all weekend if you have any questions, but this is what the key looks like. [38:38.450 --> 38:52.640] So, this was Jenna Lynn last year at DEFCON when this little 12-year-old, who had become a star at 11, she opened the Medeco cylinder several times at DEFCON last year. [38:52.760 --> 38:54.430] Medeco said, no way. [38:54.450 --> 38:56.140] This is a phony lock. [38:56.290 --> 38:57.540] This is a phony demonstration. [38:57.830 --> 39:07.330] So, we sealed the locks an hour after we did this, sent them to some forensic experts, and they validated this was an off-the-shelf standard lock. [39:07.450 --> 39:09.620] Toby had pinned it to Medeco codes. [39:09.620 --> 39:10.330] No problem. [39:11.460 --> 39:12.160] Go ahead. [39:12.290 --> 39:16.040] So, key control and key security, as we said, a total compromise of key security. [39:16.220 --> 39:22.390] Duplicate, replicate, simulate keys for virtually all M3s and some biaxial keyways. [39:23.140 --> 39:24.260] Restricted, proprietary. [39:24.640 --> 39:33.040] We talked about the widening of the M3 keyway that allows us to introduce many other keys or blanks. [39:33.240 --> 39:36.060] We could produce bump keys and code-setting keys. [39:36.180 --> 39:38.830] So, this is a critical picture here. [39:38.830 --> 39:46.850] And you can see in this cylinder the red line indicating how we're able to broach and breach that keyway. [39:47.040 --> 39:52.410] The interesting thing about this picture is the standards mandate paracentric keys or keyways. [39:52.640 --> 39:56.950] That means the wards cross the center line at least twice so you can't move a pick up and down. [39:57.180 --> 40:00.120] And so, we don't know how they're meeting that standard. [40:00.120 --> 40:01.850] We're addressing that right now. [40:02.020 --> 40:07.160] But this keyway, we can stick our simulated blank in no problem. [40:07.160 --> 40:08.460] It works like a factory original. [40:10.140 --> 40:13.330] Okay, and this is a simulated blank and an M3. [40:13.540 --> 40:14.890] This is what our keys look like. [40:15.040 --> 40:17.260] When we simulate them, it's a dollar blank. [40:17.640 --> 40:19.330] We go all through this. [40:19.600 --> 40:20.480] Piece of cake. [40:20.790 --> 40:21.930] No problem. [40:21.930 --> 40:30.180] And again, even with the reduced width on the simulated blank, it still maintains the rotational angle, able to rotate the pins and open up the lock. [40:31.560 --> 40:32.000] Whoops. [40:32.240 --> 40:32.390] Oops. [40:33.120 --> 40:33.640] Got my... [40:33.640 --> 40:34.760] I ruined it. [40:35.020 --> 40:37.720] So, we showed the paper clip. [40:37.950 --> 40:39.260] I had to explain this to Mark. [40:39.390 --> 40:40.890] He had no clue who MacGyver was. [40:40.890 --> 40:44.640] But this is truly the security of the M3. [40:45.910 --> 40:47.060] Who is MacGyver? [40:47.310 --> 40:47.410] Yeah. [40:48.310 --> 40:48.600] Again? [40:48.910 --> 40:49.350] I don't know. [40:49.500 --> 40:49.600] Okay. [40:49.790 --> 40:50.350] So, picking. [40:51.040 --> 40:54.740] Again, in as little as 27 seconds for a six pin lock. [40:56.200 --> 40:58.830] This does not meet high security standards. [40:59.060 --> 41:00.830] Now, again, this is not every lock. [41:00.950 --> 41:03.000] These are very, very good locks. [41:03.000 --> 41:04.870] But we can open them. [41:05.040 --> 41:08.160] And we can pick individual pins without upsetting other pins. [41:08.760 --> 41:12.310] We basically figured out how to do whatever we wanted with these locks. [41:12.620 --> 41:16.120] And the real problem that you folks... [41:16.120 --> 41:31.080] There's a vulnerability that we discuss at length that will affect every system that has Medeco where you have a problem with an employee that may breach the security within a secure area. [41:31.080 --> 41:37.350] They can take their office key and go use it to pick open another office. [41:37.960 --> 41:41.890] And this is a very, very serious vulnerability. [41:42.220 --> 41:43.580] Most attacks come from within. [41:43.870 --> 41:45.620] I work a lot of investigations. [41:46.040 --> 41:47.260] It's from within. [41:47.640 --> 41:56.200] And so, the ability once you're inside to go open an area or access an area where you don't have authority to be is a real problem if you know how to pick locks. [41:56.370 --> 41:58.180] And this is not a problem. [41:58.180 --> 42:14.450] I can tell you that Toby was recently at a facility, a very high security facility, took the director of security's change key, went into from another office and opened his in 35 seconds. [42:14.910 --> 42:16.700] Now, can he do that with every lock? [42:16.810 --> 42:17.020] No. [42:17.290 --> 42:18.000] Can I do that? [42:18.140 --> 42:18.390] No. [42:18.560 --> 42:24.290] But it is a serious, serious threat that you all need to understand and be educated about. [42:25.390 --> 42:30.020] So, this is one of the locks that was used in the video demonstrations in the book and CD. [42:30.330 --> 42:33.390] And clearly, Toby spent way too much time because it's really damaged. [42:33.870 --> 42:34.060] Yeah. [42:34.580 --> 42:39.290] I hope the rating still applies. [42:40.080 --> 42:40.310] Yeah. [42:40.370 --> 42:41.810] We hope the rating still applies. [42:41.810 --> 42:45.410] We pick medical locks with standard picks. [42:46.390 --> 42:47.160] Nothing special. [42:47.350 --> 42:48.830] No sophisticated decoders. [42:49.080 --> 42:49.330] Nothing. [42:49.520 --> 42:50.580] We just open them. [42:50.890 --> 42:51.290] Go ahead. [42:51.950 --> 42:57.020] So, we talked about the top-level master key and pwnage was something else I had to explain to Mark. [42:57.020 --> 43:00.460] But it's total ownage of the system. [43:01.040 --> 43:06.330] You can determine the sidebar code where multiple sidebar codes are employed as Mark said. [43:06.330 --> 43:08.460] Use a change key from one facility. [43:09.480 --> 43:10.930] Totally own the system. [43:11.720 --> 43:12.740] Forced entry techniques. [43:12.960 --> 43:17.200] A lot of these aren't necessarily provided in detail in the book. [43:17.370 --> 43:18.810] They are available on the government CD. [43:19.450 --> 43:27.060] But we have released information on the vulnerabilities inherent with the deadbolt 30-second bypass. [43:27.060 --> 43:30.330] And there's multiple hybrid techniques. [43:30.660 --> 43:33.180] One that Toby developed was a reverse picking technique. [43:33.850 --> 43:36.450] Mortise and rim and interchangeable core locks. [43:36.600 --> 43:43.290] As Mark described, in a month we're going to be releasing a very, very serious vulnerability that affects millions and millions of locks. [43:43.290 --> 43:47.820] Millions and millions and millions of locks and can be carried out ultimately in about 10 seconds. [43:48.940 --> 43:54.660] So, this is the deadbolt that we open with a $2 screwdriver and 25 cents worth of materials. [43:55.250 --> 43:55.800] Priceless. [43:56.000 --> 43:56.800] Priceless, yeah. [43:58.900 --> 44:00.260] Only with MasterCard. [44:01.020 --> 44:04.920] This is a mortise cylinder and this is what we're going to be talking about next month. [44:05.460 --> 44:08.340] And like I said, ultimately in about 10 seconds this lock is open. [44:09.960 --> 44:14.680] And so, again, patents...here's really the rule. [44:14.800 --> 44:16.000] Patents don't mean anything. [44:16.260 --> 44:20.580] The patent office does not issue a patent based on security or insecurity of a lock. [44:20.800 --> 44:26.320] They issue it on non-obviousness, on utility, and that it hasn't been done before. [44:26.320 --> 44:29.840] And so, it doesn't have anything to do with security. [44:30.040 --> 44:31.420] That's what the manufacturers claim. [44:31.600 --> 44:35.020] So, you need to understand apparent versus actual security. [44:35.300 --> 44:38.320] So, 40 years of invincibility doesn't mean a lot. [44:38.460 --> 44:39.080] Go to the next slide. [44:39.480 --> 44:50.640] So, let's talk a couple minutes and we would urge you to read the editorials about responsible disclosure versus what we call irresponsible non-disclosure. [44:51.320 --> 45:00.880] We think that the lock manufacturers, all of them, that do high security locks especially, have a duty to tell you if there's a problem as a customer. [45:01.260 --> 45:03.980] And as a locksmith and as a dealer. [45:04.290 --> 45:06.560] It's your security, it's not theirs. [45:06.840 --> 45:15.340] So, we're really pushing this concept and making it incumbent upon the manufacturer to tell you what the problem is and to fix it. [45:15.340 --> 45:28.640] So, if Medeco releases their ARX pins in all of their locks, what about the millions of locks that are out there that they knew about this problem since 1994 when they started selling ARX pins? [45:28.900 --> 45:31.160] What about all those locks? [45:31.360 --> 45:35.660] Why did they wait 15 years honestly to fix the problem? [45:35.660 --> 45:38.740] If, in fact, they're going to fix it, which is our information. [45:39.040 --> 45:47.100] So, we think there may be responsible disclosure on your part if you find a flaw or vulnerability in a new lock. [45:47.260 --> 45:54.940] We don't think it has anything to do with anything in locks that are out there already unless they're going to go pay to fix them. [45:55.290 --> 46:01.040] It doesn't help you to tell the manufacturer about the problem if you've already got the locks installed. [46:02.140 --> 46:02.720] Go ahead. [46:04.700 --> 46:07.400] So, again, we think they have a duty to customer. [46:07.660 --> 46:11.380] We covered it in two very detailed editorials, so we won't do it now. [46:11.560 --> 46:13.060] So, we can take a couple questions. [46:13.400 --> 46:15.920] And this is the last frontier. [46:16.220 --> 46:17.860] This is what I alluded to earlier. [46:18.800 --> 46:29.020] The last thing that we have to crack, and we're going to use maybe the Enigma code machine to do it, is to figure out what virtually resistant security means. [46:29.020 --> 46:37.720] Now, we think it might take a couple years to work our way through that because, unfortunately, my brother lawyers were involved in drafting this meaningless language. [46:37.980 --> 46:41.290] So, if any of you have any suggestions, please email us. [46:41.500 --> 46:42.380] Take questions. [46:42.700 --> 46:47.980] And so, we'd be glad to take some questions for maybe six, seven minutes. [46:48.700 --> 46:49.940] Anybody have any questions? [46:51.860 --> 46:52.620] Thank you. [46:59.010 --> 47:00.810] Mark, Matt, thank you. [47:00.910 --> 47:05.530] No one ever likes to boil it down to a specific lock or a specific brand. [47:05.810 --> 47:14.410] But for people who are really not in the industry, do you think the promise lies with next generation medicos? [47:14.670 --> 47:15.230] Will they evolve? [47:15.230 --> 47:20.250] Or for that one, like your, no one ever likes to say the favorite lock. [47:20.430 --> 47:24.010] But are we talking an MCS, ThroneTech, Primus? [47:24.370 --> 47:27.230] What would be, at this point, your favorite lock? [47:27.230 --> 47:36.330] My favorite locks are, I like Primus, I like Abloy, and I love Eva MCS from Austria. [47:36.330 --> 47:42.090] The magnetic code system, we used it as the model in our book. [47:42.490 --> 47:45.310] Because it is absolute key control. [47:45.510 --> 47:48.990] If you don't have the key to that lock, you are not going to open it. [47:49.090 --> 47:49.670] End of story. [47:49.990 --> 47:53.090] There's four embedded magnets, eight rotors, two sidebars. [47:53.350 --> 47:58.190] It took ten years of joint engineering with two universities in Austria to make the lock. [47:58.430 --> 48:01.490] They're not available in America yet, we're working on it. [48:01.650 --> 48:03.290] They're a terrific lock. [48:03.750 --> 48:05.110] Exactly, virtually resistant. [48:06.450 --> 48:08.070] Yeah, they're virtually resistant. [48:08.250 --> 48:12.490] But to answer your question, first of all, I don't know where Medeco is going to go with mechanical locks. [48:12.610 --> 48:15.650] And I really want to stress, I've always loved their company. [48:15.790 --> 48:18.810] I think they've got great technology, but they did not listen. [48:18.950 --> 48:20.450] And it's a 40-year-old lock. [48:20.590 --> 48:22.450] I don't know mechanically where they're going. [48:22.890 --> 48:25.710] Frankly, I don't know where any mechanical manufacturer is really going. [48:26.070 --> 48:27.050] We've got two minutes to questions. [48:27.050 --> 48:28.070] Go ahead, next question. [48:29.010 --> 48:33.570] Well, obviously, over the past decade, there's been a rise in electronic access control systems. [48:33.570 --> 48:41.210] And I was wondering if, in your experience, there's been a... if hardware mechanical systems have had a decrease in importance. [48:41.510 --> 48:44.030] And how you think the industry will look in another 20 years? [48:44.330 --> 48:45.670] It's going to look really different. [48:45.670 --> 48:48.710] Let me just address one thing, and maybe I can talk to you offline. [48:49.430 --> 48:57.610] For most of these electronic access control systems, there's mechanical cylinders as a bypass, because everybody's afraid of electronic failure. [48:57.810 --> 49:00.930] So what are... you know, and there's no audit trail on the mechanical locks. [49:01.270 --> 49:02.230] So what are you gaining? [49:02.830 --> 49:04.750] 20 years, it's going to look a lot different. [49:05.770 --> 49:06.250] Next. [49:06.910 --> 49:12.430] You mentioned that the rotating pins was one of two of the greatest innovations, in your opinion. [49:12.430 --> 49:13.630] What was the other one? [49:13.750 --> 49:16.630] Moz Hamilton, the X07, X08, X09. [49:16.990 --> 49:17.790] Okay, thank you. [49:18.010 --> 49:18.650] A great lock. [49:19.050 --> 49:19.770] Alright, last question. [49:20.090 --> 49:20.730] Last question. [49:20.870 --> 49:21.090] Sorry. [49:23.770 --> 49:34.750] For those of us who acquired M3 cylinders before December 2007, would re-keying them solve the problem? [49:34.950 --> 49:35.710] At least in part. [49:37.210 --> 49:38.690] Can you solve the problem? [49:39.330 --> 49:40.450] Is that your question? [49:40.450 --> 49:41.970] By re-keying... [49:41.970 --> 49:44.410] If the code book prior to December of 2007 was cracked... [49:44.410 --> 49:48.110] Well, let me tell you, first of all, we can crack their locks after December of 2007. [49:48.270 --> 49:50.870] It just takes us a little more work, but not much. [49:51.070 --> 49:56.210] It's 16 keys, but we whittle that down with intelligence gathering up to two keys. [49:56.390 --> 49:58.590] And so the problem has not gone away. [49:58.830 --> 49:59.930] If they implement... [49:59.930 --> 50:00.750] If you put AR... [50:00.750 --> 50:01.410] There's two answers. [50:01.410 --> 50:09.290] Put in ARX pins, and we have a list of safe sidebar codes that we've put out. [50:10.130 --> 50:14.850] Now, they may violate Medeco's rules, but we can't open them. [50:15.350 --> 50:18.190] And so that we felt we had a duty to do that. [50:18.430 --> 50:20.050] If Medeco wouldn't do it, we did it. [50:20.170 --> 50:22.350] Most importantly, do you know why you can't open them? [50:22.550 --> 50:23.270] Do I know what? [50:23.530 --> 50:25.170] Why you can't open those ones. [50:25.170 --> 50:25.770] Oh, yeah. [50:26.330 --> 50:26.510] Okay. [50:26.770 --> 50:27.970] Yeah, we know exactly why. [50:28.130 --> 50:28.390] Okay. [50:28.490 --> 50:28.930] Why is it? [50:29.610 --> 50:29.890] Okay. [50:30.490 --> 50:30.910] Why is that? [50:31.550 --> 50:34.970] Because our code setting keys won't set the proper sidebar code. [50:35.050 --> 50:40.390] We can pick them, but it may take us more time rather than walking up with a key and picking it. [50:40.730 --> 50:41.050] Thank you. [50:41.470 --> 50:41.710] Yep. [50:42.310 --> 50:43.470] Thank you all very much. [50:43.550 --> 50:45.330] We'll be offline, and we'll be here all weekend. [50:45.930 --> 50:46.430] Thank you. [50:48.470 --> 50:48.870] Pleasure. [50:49.550 --> 50:49.950] Thank you.