• On TV.com: TOP 10 Shows CANCELED Too Soon
August 8, 2008 3:00 PM PDT

Lock picking with a credit card, a photocopier, and some luck

by Elinor Mills

Security experts Tobias Bluzmanis, Marc Weber Tobias, and Matt Fiddler speak at Defcon about creating fake keys to high-security locks with credit cards.

(Credit: CNET News.com/Declan McCullagh)

LAS VEGAS--Don't have special lock-picking skills or equipment but want to pick a high-security lock?

A security researcher explained at the Defcon hacker conference here how to make a fake key out of a credit card that can open certain types of Medeco M3 locks used in the White House, Pentagon, and high-security areas around the world.

You need to make a picture of a legitimate key to have an image to transpose onto the plastic, which means an insider or someone with access to the key would need to cooperate, said Marc Weber Tobias, a lawyer who has written a book about breaking into high-security Medeco locks called Open in Thirty Seconds.

Basically, someone could grab an image of the key with a camera, cell phone, copy machine or scanner, print the image on a label or sheet of plastic, and cut along the outline with an X-Acto knife.

"Everybody has known about this forever with conventional locks, like Kwikset," Tobias said. "But high-security locks advertise that they have key control, especially Medeco."

Medeco claims they have key control for the high-security locks, which means control of the ability to duplicate or simulate keys with blanks, and only authorized locksmiths are supposed to be able to make duplicates, he said. "We've shown that's all out the window," he said.

More complex cylinder configurations in the Medeco locks will require extra steps, he said.

"So we've demonstrated the ability to simply make keys for this particular high-security lock," Tobias said of a recent live demonstration. "We didn't have to break the cylinder; we were able to look at pictures that were e-mailed to us and determine the angles on the key."

Potentially millions of high-security locks are at risk, according to Tobias. The technique does not work on other types of high-security locks; Medeco locks have an integrated design that makes the technique relatively easy, he said.

A Medeco spokesman did not return an e-mail seeking comment.

Medeco executives have previously complained about Tobias disclosing vulnerabilities with the locks to the public, even though Tobias had contacted the company as well. Tobias and other security researchers defend their actions in publicly disclosing flaws, saying that if they didn't do so the vendors wouldn't fix the products.

Tobias, and the Lock Picking Village organizers, were also showing their skills at the Last HOPE hacker conference in New York last month.

During the first part of the presentation, the panelists criticized the standards that apply to high-security locks, saying that they were not broad enough to encompass the range of possible picking and breaking attacks. In other words, a lock could be perfectly standards-compliant--but able to be bypassed in under a minute.

Click here for more coverage from Defcon.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by Michichael August 8, 2008 4:36 PM PDT
Nice....
Reply to this comment
by weeblnbob August 8, 2008 4:42 PM PDT
Now THAT's funny! It only reinforces the old saying: "Locks only keep the honest folks out."
Reply to this comment
by lockguy81 August 9, 2008 9:25 AM PDT
I'm a locksmith and yes locks do only keep the honest people out but as with most ways of getting past locks in my mind they take to long. If I were breaking into a place I would break a window, get in, and get out. I'm sure the government locations with these locks also have other forms of security. Like the big guys with guns.
Reply to this comment
by The_Decider August 11, 2008 5:32 PM PDT
"Big guys with guns" aren't necessarily guarding the entrances and cabinets these supposed lock protect. Furthermore, they probably won't know if a person is authorized access.
by benjaminstraight August 10, 2008 3:14 PM PDT
Great. More worries. Informative article.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right