Defensive Computing

Read all 'lockpicking' posts in Defensive Computing
July 19, 2008 11:39 AM PDT

Hacking Medeco locks

by Michael Horowitz
  • Post a comment

The Last HOPE conference, now being held in New York City, is as much for people interested in hacking the real world as it is for computer techies.

One such real world presentation on Friday was called "Undoing Complexity--From Paper Clips to Ball Point Pens." Despite the title, it was about hacking high-security electronic locks from Medeco. (The paper clip in the title is a reference to using one as a way of bypassing one type of security in Medeco locks.) The presentation was very well attended, SRO in a large room.

The presenters, Matt Fiddler and Marc Tobias, didn't seem to hold a grudge. They said nice things about Medeco and its locks, which they claimed are used to protect the White House and England's royal family, among many other high value targets, such as server farms. But after 18 months of research, they claim to be able to hack into almost any Medeco high-security lock with ease. They also claimed to have had a good relationship with Medeco, until recently. Still, they must be Medeco's worst nightmare.

Much of the technical hacking details went over my head, but one thing came through loud and clear: don't trust the claims of vendors when it comes to the security of their locks. It was fascinating to hear how Medeco initially made a strong claim about its locks ability to resist one particular type of attack, then how it had to re-word that claim when that was proven untrue, and eventually, how it had to re-word the claim yet again to the point where it sounds good but has no real meaning at all.

Tobias was a guest, on the 2600 radio show Off The Hook on WBAI back on May 21. That show, is available for download here. He also spoke on "Lockpicking: Exploits for Mechanical Locks" at the prior HOPE conference. Audio of that talk is also available.

See a summary of all my Defensive Computing postings.

  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Defensive Computing

Michael Horowitz is an independent computer consultant and the author of several classes on Defensive Computing. He views Defensive Computing as taking steps, when things are running well, to avoid or minimize the inevitable problems down the road. It's about educating yourself to the level where you can make your own intelligent decisions about keeping your computers and data happy and healthy. If you depend on computers, yet are on your own, without an IT department or nearby nerd, this blog's for you. His personal web site is michaelhorowitz.com.

He is a member of the CNET Blog Network and is not an employee of CNET.

Disclosure.

Add this feed to your online news reader

Defensive Computing topics

Most Discussed

advertisement

Inside CNET News

Scroll Left Scroll Right