• On MovieTome: HARRY POTTER gets a new trailer!
July 21, 2008 8:40 AM PDT

For the love of lock picking

NEW YORK--I feel much less secure after attending the Last HOPE conference this weekend.

Not only is my personal information at risk every time I log onto the Internet and use a cell phone headset or passport, but even my gym locker, bike, and home can easily be accessed with the proper tools and manual dexterity.

Tools of the lock picking trade.

(Credit: Elinor Mills/CNET News)

In the popular Lockpicking Village area at Last HOPE (Hackers on Planet), I watched guys twirl little pins in all types of locking devices. For some, it took less than a minute to get the locks to snap open. One lock picker even showed how to open an ordinary padlock with just a piece of aluminum from a beer can. (See video demo below.)

If I'm worried, how do they feel at the Pentagon and the White House?

Medeco, the lock that secures the doors in those two places and at high-security agencies around the world, had been un-crackable for 40 years--until last year. And now there's a book about the lock's shortcomings called Open in Thirty Seconds.

Marc Weber Tobias, co-author of Open in Thirty Seconds gets freed from a pair of prison transport handcuffs without a key.

(Credit: Elinor Mills/CNET News)

"This is all about liability and responsible disclosure," said Marc Weber Tobias, a co-author on the book. "People need to know they are vulnerable, and the manufacturer says it can't be done."

The book doesn't reveal the codes needed to open the locks, he noted.

"The goal is to help people understand how we did it," said Tobias, who has a physical security consultancy called Security.org. "As a lawyer, I believe in full disclosure and I believe manufacturers ought to disclose the vulnerabilities in their products."

Like with software vulnerabilities, manufacturers don't want to acknowledge security flaws, he said. But the difference between software and old-fashioned hardware is that software can be easily upgraded over the Internet while locks must be replaced.

Below is a video that demonstrates just how easy it is to pick a deadbolt lock. "Steve," a member of the Toool Open Organisation of Lockpickers, uses a small tension wrench to hold the pins in place while he jiggles a lock pick tool to set the pins to "open."

Credit: Elinor Mills/CNET News

Below in this video, "Deviant" shows how to pick an ordinary combination padlock by shimmying the shackle open with a small, folded piece of aluminum or metal.

Credit: Elinor Mills/CNET News

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 and previously covered search, online advertising, and portals. E-mail Elinor.
Recent posts from News - Security
World Bank under cyberattack?
Apple's October update fixes 20 security flaws
Microsoft to issue 11 security patches on Tuesday
Parity provides free online identity management
Symantec eyes pay-per-use software
Add a Comment (Log in or register) 13 comments
by Missing_dc July 21, 2008 9:32 AM PDT
For those of us in the know, lockpicking is generally easy, it's just illegal unless you are a bonded locksmith. That means don't get caught with your picks or shims.

I've heard it said that locks exist to keep an honest person honest, but an intent person will find a way.
Reply to this comment
by Squelchtone July 21, 2008 8:35 PM PDT
Missing_dc, please don't spread misinformation around if you aren't really "in the know". lock picking is generally easy if you practice enough, and of course it depends on which lock you are trying to pick. The lockpickers, such as myself who attended The Last HOPE, and who are members of TOOOL or Locksport International pick locks for fun and because we like a good challenge. Also, I have to expand on what you said about lockpicking being illegal. It is not illegal, nor is owning a set of lock picks illegal unless you are in a state or city which specifically states that possession is illegal unless you are a locksmith, tow truck driver, or a police officer. Washington DC is the only place I know that specifically says lockpicks are illegal. Other states have different varying laws which usually state that lockpick tools are only illegal if there is clear intent that you are breaking in somewhere. So if you own picks and pick for fun and pick your own collection of locks thats just fine in most states. If you are picking at 3am in a dark alley and have a police scanner and you're picking the door to a store or bank or some lock that isnt yours, thats illegal. possession without intent is just fine. Also, bonded locksmith only means that the locksmith has insurance in case he breaks something while installing a lock in your nice door, what you meant to say is licensed locksmith.

Squelchtone
TOOOL.US
Reply to this comment
by unknown_user July 22, 2008 5:25 PM PDT
An extra note: Even where it's not illegal to have a lockpick, I've seen law enforcement and professional locksmiths freak out if they see or hear of people possessing them. Regardless of the law, you're generally better off being discreet about having them and knowing how to use them.
Reply to this comment
by dirty55409 July 22, 2008 7:33 PM PDT
lol yeah this is great, we'll have all these kids picking up lock picking tools... oh yeah you're really cool. Now try and pick a lock without going to jail or getting arrested. lol silly article that does nothing to benefit society.
Reply to this comment
by harrytan July 22, 2008 9:42 PM PDT
Can any of the experts here advise which padlocks or door locks generally are harder to pick or even safe (presuming that they are all vulnerable)?

Thanks.
Reply to this comment
by d.gallea July 23, 2008 7:37 AM PDT
Do others see the videos? Mine are blank.
Reply to this comment
by jdport July 23, 2008 8:31 AM PDT
As a licensed and bonded locksmith, this is something I know a little something about. If you want real security, be prepared to pay real money for it. Schlage Primus is good. Even though Marc Tobias has cracked the Medeco, I can tell you it is highly unusual even for experienced locksmiths to crack these. There are new "bump resistant" and "bump-proof" locks entering the market because of the concerns of bumping and picking. Master has a bump-proof deadbolt and I'm sure Schlage has a few. Arrow is a name most consumers are not aware of because they are sold only through locksmith dealers. For real security I recommend most any lock utilizing a restricted keyway. This means the key blanks are not readily available and possibly sold only by your local locksmith. You won't find them in the hardware store kiosks. Check with your local locksmith dealer and ask for a lock with a restricted keyway. But be prepared for sticker shock. The solutions are there, they just cost more.
Reply to this comment
by dickalmighty July 24, 2008 10:18 AM PDT
Fantastic article! Attention getting commentary! No freaking videos! Anybody picks my locks while I'm home gets shot before the door opens anyway. Anything taken if I'm not here is not worth much anyway and cracheads and meth people are too shaky to do the locks. No personal attacks intended.
Reply to this comment
by Robb Lawrence July 24, 2008 8:49 PM PDT
why broadcast that lock-picking can be done so easily? are there companies working on fool-proofing locks or is there no such thing? what about combination locks - is the formula for cracking those codes
equally as simple as picking regular types of locks?
Reply to this comment
by Robb Lawrence July 24, 2008 8:52 PM PDT
why broadcast that lock-picking can be done so easily? are there companies working on fool-proofing locks or is there no such thing? what about combination locks - is the formula for cracking those codes
equally as simple as picking regular types of locks?
Reply to this comment
by glenm812944 July 25, 2008 6:27 AM PDT
Being a former locksmith and now in a IT Department I've seen those key locks on dell servers are so easy to pick and just take a hard drive, but you have to have the the restricted key to get into the front door and then you have punch in your pass code number to get into a second door into the data room then whip out your picks, pick the lock, steal the hard drive, which will trip a fault light on the server plus the audiable ear pearsing sound from the server, which our operations guys would get an instant massenge right next door to see what the problem is and maybe get caught? I wouldn't take a chance at it. I would have a better chance at picking you car lock out in the parking lot and stealing your car.
Reply to this comment
by dickalmighty August 2, 2008 12:11 PM PDT
Are the videos ever going to be put back on? That's the reason I went to the site and ..........................
Reply to this comment
by brucerobb August 6, 2008 12:27 PM PDT
If you're trying to watch at work, your employer (like mine) may have blocked videos.
Reply to this comment
Powered by Jive Software
advertisement
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About News - Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

News - Security topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right