[00:02.250 --> 00:03.500] Let's see if we can make this work. [00:03.640 --> 00:07.120] So I'm going to talk about... not talk about lock picking. [00:07.580 --> 00:18.040] So the first kind of disappointment is that if you're here to talk about lock picking, you probably have some time to go down to Starbucks and, you know, play with their wireless network or whatever. [00:20.520 --> 00:21.920] I'm getting old. [00:22.180 --> 00:34.820] I mean, this is one of the properties of, you know, being an old school hacker from the old days, is that as you get older, you discover that hacking your body is a little bit harder than hacking computers. [00:35.100 --> 00:39.480] And in particular, I find that I'm getting less and less good at picking locks. [00:40.740 --> 00:44.560] But to make up for that, I've been thinking about locks for a while. [00:44.720 --> 00:55.000] And one of the things that I do in my day job is I'm a cryptographer and computing systems security person. [00:55.600 --> 01:11.740] And one of the things that I thought about a couple of years ago is the question of can you think about locks locks and physical security using the same mindset that we think about computers and cryptography with? [01:11.910 --> 01:13.970] And the answer is you can. [01:14.210 --> 01:28.480] And in fact, you know, the purpose of my talk is that if you are interested in locks and physical security and you're a computer scientist, you actually have a really big advantage compared with thinking about these things in mechanical terms. [01:28.570 --> 01:32.350] So I'm going to talk about picking locks locks using cryptography. [01:34.320 --> 01:41.960] So in particular, one of the things is, you know, we're computer scientists, right? [01:42.040 --> 01:47.840] The kind of core people here got their introduction to technology through computers. [01:48.070 --> 02:00.850] And the question is why should those of us who are really good at thinking about computers waste our time thinking about these little mechanical, very primitive, you know, kind of 19th century technology. [02:01.650 --> 02:01.700] Technology. [02:01.700 --> 02:05.920] And one of the things is that first of all, you can think about them in the same terms. [02:06.240 --> 02:27.730] And over the last hundred years or so, in particular, since they invented computers, the people responsible for thinking about physical security, the locksmiths and the safe manufacturers and so on, have gone from thinking about these things in very scientific open terms to becoming very insular and private. [02:28.000 --> 02:36.510] And in fact, they've stopped being critical about security in the same way that we think about security. [02:37.010 --> 02:39.040] You know, we tend to be very critical. [02:39.200 --> 02:40.820] We say, well, let's look for the flaw. [02:41.380 --> 02:49.720] The physical security community, by and large, says, well, if somebody finds a flaw, the problem is these people trying to find flaws, not the flaw itself. [02:50.380 --> 02:55.940] So, you know, this idea of independent analysis has kind of gone away from the physical security world. [02:56.610 --> 02:58.640] So we all know what physical security is. [02:58.720 --> 02:59.960] We all know what locks are. [03:01.100 --> 03:06.320] Locks are, you know, there are two major categories of locking mechanisms. [03:06.540 --> 03:13.380] There are combination locks, the kind used on cheap padlocks and to protect safes. [03:13.480 --> 03:15.220] I'm not going to be talking about those here. [03:15.500 --> 03:24.160] They're keyed locks, where you take a physical token and put it in the lock, and the physical token kind of convinces the lock to open in some way. [03:24.300 --> 03:25.820] That's the kind that I'm going to talk about. [03:27.040 --> 03:33.380] Now, you know, it's interesting that even this language is something that's familiar to computer scientists, right? [03:33.440 --> 03:37.080] We talk about keys, cryptographic keys, and things like that. [03:37.240 --> 03:40.700] We talk about people who break into computer systems. [03:41.020 --> 03:42.960] We talk about them being intruders. [03:43.110 --> 03:49.100] These are all, you know, they're not breaking into anything, and they're not intruding on anything in any physical sense. [03:49.320 --> 03:54.180] The language of computer science, again, is taken right out of that physical locksmithing world. [03:55.940 --> 04:00.460] So, it's also possible that we can learn something by studying these things a little more. [04:02.500 --> 04:02.940] Okay. [04:03.320 --> 04:08.500] So, the kind of lock that's most familiar to everybody is called the pin tumbler lock. [04:08.640 --> 04:11.980] Now, this is the picture of the user interface of a pin tumbler lock. [04:12.110 --> 04:13.900] How many of you have ever operated a door? [04:14.520 --> 04:14.900] Okay. [04:15.520 --> 04:25.270] So, this user interface is fairly familiar, even though, you know, on it itself, from the way a computer scientist would look at this, they'd say, this is a terrible user interface. [04:25.440 --> 04:26.680] There are no pop-up windows. [04:27.670 --> 04:28.530] Nothing's labeled. [04:28.740 --> 04:29.420] There's no help. [04:30.060 --> 04:35.590] So, the components of this user interface are really three important parts. [04:35.740 --> 04:41.270] There's the shell, which is the part of the lock that's fixed to the door or the container. [04:41.560 --> 04:46.150] The plug, which is the part that rotates and that operates the locking mechanism. [04:46.330 --> 04:52.320] And the keyway slot, and that's kind of the user interface for the lock where you insert the key. [04:52.520 --> 04:56.300] And if you kind of look through the user interface, you don't really see much. [04:56.440 --> 05:04.820] You might be able to see a little pin there, but you don't get too much of a hint as to what's actually going on inside the lock. [05:05.860 --> 05:09.520] So, what's going on inside is kind of the interesting question. [05:09.970 --> 05:21.270] The boundary between the shell, the part that's fixed to the door, and the plug, the part that rotates, is called the shear line for the shear force that's created. [05:21.460 --> 05:24.680] And that's really where all the action is from a security point of view. [05:25.350 --> 05:28.460] So, what keeps the plug from rotating when there's no key in? [05:28.720 --> 05:40.460] Well, there's a set of pins, or more properly, they're called pin stacks, that protrude out of holes in the shell and go into holes in the plug that keep the plug from rotating. [05:40.720 --> 05:47.400] What the key does is lifts those pins to a particular height where the pin is cut. [05:47.580 --> 05:52.640] And if the key lifts all of the cuts up to the shear line, then the plug can rotate. [05:52.880 --> 05:54.620] So, it's a little mechanical computer. [05:54.680 --> 06:02.080] that tests keys to see whether or not the key knows the secret height to lift each of the pins to. [06:02.360 --> 06:07.520] So, if we took a lock and looked at it from the side and cut it apart with a milling machine. [06:07.680 --> 06:09.080] How many of you have a milling machine? [06:09.760 --> 06:10.240] Okay. [06:10.340 --> 06:15.620] More of you should have a milling machine, particularly if you're interested in physical security hacking. [06:15.800 --> 06:18.760] So, now we're looking at that lock cylinder from the side. [06:18.760 --> 06:21.560] You can see this has six little pin stacks. [06:22.420 --> 06:23.600] Here's the shell. [06:23.740 --> 06:24.520] Here's the plug. [06:24.680 --> 06:26.940] This boundary here is the shear line. [06:27.500 --> 06:28.800] And these are the pins. [06:29.040 --> 06:31.380] And each of these pins, you can see, has a little cut in it. [06:31.600 --> 06:38.900] The key goes in from the front and the little wobbly pieces on the key lift these cuts up. [06:39.000 --> 06:42.820] If it's a correct key, all of them to the shear line and it lets the plug rotate. [06:43.100 --> 06:49.220] So, that's how this little analog mechanical computer works to test keys. [06:50.780 --> 06:55.200] And, you know, again, I'm talking about this in kind of computing terms. [06:55.420 --> 06:59.680] I'm thinking of the function of a lock is as a little key testing machine. [07:00.480 --> 07:01.960] So, how do the keys work? [07:02.120 --> 07:09.400] So, here's some locksmithing terminology if you want to impress a locksmith or more likely make a locksmith really suspicious of your intentions. [07:11.260 --> 07:22.980] The surface of the key where the little notches are cut that lift the pins up to a particular height is called the bidding surface or the bidding of the key. [07:23.540 --> 07:31.420] And the notch height, the height of the key at any particular pin position, is the inverse of the corresponding depth of the cut. [07:31.420 --> 07:37.440] So, a correct key is going to correspond in its height to the height of that cut inside the lock. [07:37.880 --> 07:47.520] So, if you talk about the bidding of the key, that's just a list of all of the heights that the key is cut to at each of the individual pin position. [07:47.920 --> 07:53.500] Now, even though a lock looks kind of like an analog device, in fact, it's really digital. [07:53.500 --> 08:02.520] In the sense that a lock maker is typically going to use a fixed number of different heights that a key might be cut to. [08:02.760 --> 08:08.300] There might be somewhere between five and ten possible heights that a key might be cut to. [08:10.000 --> 08:19.340] And so, you can kind of get a complete description of a key by knowing what kind of lock it fits in and the complete list of the heights that it's been cut to. [08:20.460 --> 08:22.480] So, here's an example of a key. [08:23.080 --> 08:27.880] And this is a key of type SC20 that's conveniently printed on the key. [08:28.240 --> 08:30.060] And here's its bidding surface. [08:30.260 --> 08:31.280] And here are the cuts. [08:31.500 --> 08:35.580] So, the first cut here is cut to this depth, cut number three. [08:35.840 --> 08:37.020] Then it's a little higher. [08:37.140 --> 08:37.980] Here's cut number one. [08:38.080 --> 08:40.420] You can see that's a little higher up than cut number three. [08:40.580 --> 08:43.300] And there's four, a one, a five. [08:43.400 --> 08:44.980] And here's a really deep cut, a nine. [08:45.160 --> 08:48.120] So, this is cut three, one, four, one, five, nine. [08:51.940 --> 08:54.380] And so, a complete description. [08:54.540 --> 09:03.320] You could get a duplicate of this key by walking into a locksmith and saying I need an SC20 key cut to three, one, four, one, five, nine. [09:03.720 --> 09:10.840] And, you know, they would be able to cut it to these specifications and it would work in the same lock as this one. [09:10.840 --> 09:17.000] So, now we've got a kind of concise way of thinking about and describing keys. [09:17.240 --> 09:19.600] And that's going to turn out to be very useful to us later. [09:20.680 --> 09:28.460] So, when we stick that correct key into the lock, that will make all of these cuts line up at the shear line. [09:28.460 --> 09:33.840] And now we can rotate the plug and it will operate the lock. [09:34.020 --> 09:40.400] If you put a wrong key in, it might line some of the cuts up at the shear line. [09:40.560 --> 09:49.200] But as long as at least one is in the wrong place, the lock is going to, from the user's point of view, not operate at all. [09:49.200 --> 10:05.940] So, one of the important properties of these locks is that if the lock is a perfectly designed lock, if there's no mechanical imperfection, a slightly wrong key is the same, from the user's point of view, as a completely wrong key. [10:06.400 --> 10:11.000] And only the exactly correct one will operate the lock at all. [10:11.520 --> 10:15.040] And that turns out not to be true, but I'm going to assume it's true. [10:15.040 --> 10:19.860] You know, I'm going to give the lock maker really the benefit of the doubt and still attack locks. [10:20.960 --> 10:24.640] So, what if you wanted to attack a lock? [10:24.780 --> 10:25.780] How might you think about it? [10:25.940 --> 10:29.220] So, there's some attacks that just bypass the lock completely, right? [10:29.420 --> 10:35.820] So, getting an unauthorized duplicate of a key is an example, where you're not attacking the lock itself, you're just getting a copy of the key. [10:35.980 --> 10:38.020] Or you might bypass the lock, right? [10:38.100 --> 10:43.980] You might go in through the window or stick something under the door to turn the knob from the inside or something like that. [10:43.980 --> 10:50.440] There are other attacks against locks that you might have to worry about, that depend on weaknesses in the lock's implementation. [10:51.160 --> 10:56.280] So, they, you know, depend essentially on the manufacturing process having bugs in it. [10:56.840 --> 11:12.080] So, examples of weaknesses that depend on the lock being manufactured poorly, are things like lock picking, vulnerability to lock picking, or vulnerability to brute force, which in locks means applying brute force. [11:14.300 --> 11:16.780] And in computers, it means something else. [11:17.160 --> 11:20.720] But there are other attacks that are based on design weaknesses. [11:21.080 --> 11:37.140] And what I mean by a design weakness is, even if the lock is manufactured absolutely perfectly, even if physics is really nice to the lock, and prevents, you know, there from being any mechanical imperfections, and anything that's round is actually really round, [11:37.220 --> 11:43.620] and anything that's a particular height is really that height, you're still going to have a flaw. [11:43.860 --> 11:46.820] And that's the kind of attack that I'm going to be focusing on here. [11:49.400 --> 11:50.800] So, let's... okay. [11:51.040 --> 11:53.240] So, one question is, what about brute force? [11:53.520 --> 11:56.740] How secure are locks if you want to try all the keys? [11:57.260 --> 11:59.700] Well, there are two parameters. [12:00.420 --> 12:04.220] One is the number of pins in it, the number of tumblers in the lock. [12:04.480 --> 12:08.640] And the other is the number of different cut depths that it might be used to. [12:08.800 --> 12:19.040] And basically, the maximum number of keys that a lock might have, is the number of cut depths raised to the power of the number of pin stacks. [12:19.780 --> 12:23.060] And that's exponential, in other words, in the number of pin stacks. [12:23.560 --> 12:28.700] And there are a couple of little factors that reduce that slightly, but basically that's pretty close to the number. [12:29.020 --> 12:31.300] So it's exponential in the number of pin stacks. [12:31.460 --> 12:33.620] A computer scientist would say that's great news. [12:34.460 --> 12:39.660] But on the other hand, there aren't really that many pin stacks and that many cut depths. [12:39.840 --> 12:46.300] So the bottom line is that there are somewhere between about 250 and 10 million different keys for a given lock design. [12:46.300 --> 12:54.240] Now, the computer scientist in you would say, yeah, but my Pentium 4 can go through, you know, 10 million keys in, you know, under a second. [12:54.420 --> 12:56.180] So obviously that's insecure. [12:56.400 --> 12:59.720] But remember that you have to try these keys one at a time. [13:00.520 --> 13:05.200] And testing 10 million keys or even only 250 keys is going to take a while. [13:05.340 --> 13:08.560] So that's probably not a very good attack against locks. [13:08.820 --> 13:10.760] So we might have to be a little more clever than that. [13:12.600 --> 13:13.600] So let's see. [13:13.860 --> 13:15.420] Barry will talk about lock picking. [13:20.500 --> 13:23.460] So let's go back to computer science here for a second. [13:24.840 --> 13:35.140] So one of the useful principles from computer science, from computer security, is to separate out thinking about the design from thinking about the implementation. [13:35.320 --> 13:41.580] In other words, you think about what the thing is supposed to be doing and think about whether that's secure. [13:41.940 --> 13:50.260] And if that's not secure, it doesn't matter how good a job the programmer does because even if it's perfect, you're still going to have a weakness. [13:50.620 --> 13:54.220] In fact, if it's imperfect, maybe the imperfection will cancel out the weakness. [13:54.560 --> 14:00.920] So, you know, thinking about the design first is a useful kind of computer science way of thinking about this. [14:01.140 --> 14:15.940] There's another computer science principle, and this is a principle from somewhat advanced cryptography, is to remember that some kinds of security systems are easy to analyze by thinking about some components as what we call oracles. [14:16.340 --> 14:23.680] And basically an oracle is something that you're not allowed to look inside of, but that the attacker is allowed to use through the normal interface. [14:24.120 --> 14:29.000] So there's a user interface, and that will tell you whether you guessed right about something. [14:29.220 --> 14:32.120] And an example of an oracle is like logging in online. [14:32.120 --> 14:35.620] That's an oracle for testing somebody's password, right? [14:35.680 --> 14:41.600] You can log in over the network, try their password, and the computer will act as an oracle, telling you whether or not that was the right password. [14:41.820 --> 14:43.180] Well, a lock is an oracle. [14:43.280 --> 14:45.200] It tells you whether or not you've got the right key. [14:45.680 --> 14:47.920] So maybe we can think about these in those terms. [14:50.040 --> 14:59.560] So a question, as soon as you have a system that has an oracle in it, the computer scientist in you should ask two questions, two really important questions. [14:59.560 --> 15:04.040] First of all, what does it cost the attacker to ask the oracle a question? [15:04.240 --> 15:05.380] How long does it take? [15:05.600 --> 15:08.340] What are the resources for the attacker to ask a question? [15:08.540 --> 15:12.320] So how many questions can you expect the attacker to maybe be able to ask? [15:13.320 --> 15:21.300] And can they structure queries to the oracle in a way that lets them learn something they're not supposed to be able to know, right? [15:21.400 --> 15:31.540] You think the oracle only tells you whether or not one key is valid, but maybe the oracle will tell you something more interesting about the key that you didn't think the attacker should be able to learn. [15:32.520 --> 15:37.380] So here's an example of, you know, again, this is computer science, not locksmithing. [15:37.460 --> 15:40.940] But here's an example of a way of testing whether a password is valid. [15:41.220 --> 15:42.200] So you have a little loop. [15:42.280 --> 15:43.540] This is kind of pseudo C. [15:44.660 --> 15:47.320] So, you know, go up to the length of the password. [15:47.780 --> 15:49.040] Get the next character. [15:49.420 --> 15:51.260] Compare the character to the password. [15:51.260 --> 15:57.060] If the character is the wrong character at that position of the password, return bad password. [15:57.260 --> 16:00.240] Otherwise, get... print out the message bad password. [16:00.400 --> 16:02.240] Otherwise, go and get the next character. [16:02.580 --> 16:04.640] Is this a good way of testing passwords? [16:05.280 --> 16:05.760] No. [16:06.200 --> 16:07.960] Why is it a bad way of testing passwords? [16:09.100 --> 16:10.420] So, what can you do? [16:11.300 --> 16:15.520] Instead of having to test the whole password, you can test the password how? [16:16.880 --> 16:18.380] One character at a time. [16:18.380 --> 16:24.060] So instead of having to submit the whole password, you can find out, is the first character of the password A? [16:24.300 --> 16:25.540] If not, is it B? [16:25.660 --> 16:26.140] Is it C? [16:26.200 --> 16:26.940] Ah, it's C. [16:27.140 --> 16:28.260] What's the next character? [16:28.400 --> 16:29.200] And so on. [16:29.500 --> 16:34.520] So this is a really bad program to write for testing passwords in an online system. [16:34.780 --> 16:39.200] So one question is, you know, what went wrong here? [16:39.400 --> 16:50.200] Well, in more formal terms, right, in kind of mathematical terms, what we'd expect is that the cost of an exhaustive search should be exponential with the length of the password. [16:50.380 --> 16:54.940] It should be the number of characters raised to the power of the length of the password. [16:55.160 --> 17:05.700] But here, it's only the number of characters in the password times the number of possible characters, which is much smaller. [17:06.400 --> 17:24.250] So the standard fix to this problem, right, if, first of all, you'd fire the programmer who wrote that program, you'd fire somebody who would know not to reveal whether the password is right until the person has committed to the entire password, right? [17:24.770 --> 17:27.440] So that's pretty straightforward. [17:27.990 --> 17:29.700] So are locks like this? [17:29.990 --> 17:32.080] Locks are online authentication oracles. [17:32.420 --> 17:33.700] The user presents a key. [17:33.880 --> 17:36.010] The lock reveals if the key is valid or not. [17:36.530 --> 17:40.440] And anyone can ask a question by submitting a key to the lock. [17:40.440 --> 17:48.180] So is it possible to use a small number of queries to reveal information about the key? [17:48.700 --> 17:59.230] And it turns out that at least I can't figure out any obvious way in the standard lock design if the lock is manufactured properly to do that. [17:59.530 --> 18:01.340] The user has to submit the whole key. [18:01.460 --> 18:06.360] You can't submit just part of the key and test some of the tumblers at once in a perfect lock. [18:09.010 --> 18:13.920] But if the lock is perfectly manufactured, you have to test all of the tumblers at once. [18:14.140 --> 18:17.880] And you don't get an answer back that says, ooh, you know that key you sent? [18:17.960 --> 18:19.120] It's really close. [18:20.360 --> 18:26.770] Instead, you get the same answer for a completely wrong key as for an almost right key. [18:26.940 --> 18:34.730] So from this kind of analysis, that perfect lock seems to have the same amount of security that's been advertised. [18:35.140 --> 18:41.290] And this would be good news for lock users who can get these perfect locks that turn out not to actually be made. [18:42.840 --> 18:45.660] But okay, so we've got to move on to something. [18:47.270 --> 18:51.210] Sometimes there's more than one lock that can... more than one key that can operate a lock. [18:51.400 --> 19:00.400] So institutions like to have master keys that can open all of the locks in the system so the janitor doesn't have to walk around with a huge ring of keys. [19:00.880 --> 19:03.640] Now again, here's some locksmithing terminology for you. [19:04.380 --> 19:12.420] The keys that operate just one lock are called change keys for technical locksmith-y reasons. [19:12.680 --> 19:18.710] So if you want to be impressive to a locksmith, you could refer to your key that only opens one lock as a change key. [19:19.250 --> 19:22.550] And then the top master key is the lock that you'd want to get. [19:22.920 --> 19:27.120] That's the lock that opens all of the... the keys that opens all of the locks in the system. [19:27.250 --> 19:37.880] So one question that you might ask is, is it possible to take a change key that change key and convert it into a master key in a perfect lock system? [19:38.100 --> 19:40.360] So let's think about how you might master key locks. [19:40.470 --> 19:42.880] One way you might do it is install two cylinders. [19:43.230 --> 19:45.010] One with the master key, one with the regular key. [19:45.200 --> 19:45.970] No one does that. [19:46.660 --> 19:50.490] There are special lock designs that have more than one shear line. [19:50.600 --> 19:51.400] Nobody uses those. [19:51.710 --> 19:55.100] There are locks that have lots of pins and only uses a subset of them. [19:55.460 --> 19:58.360] Those are required the use of a lot of pins. [19:58.360 --> 20:04.400] But the common technique for master keying is to have more than one cut in each pin position. [20:04.990 --> 20:06.810] And that's what I'm going to talk about here. [20:07.080 --> 20:13.180] So instead, our side view of the lock that's been cut away, instead of one cut, there are two. [20:13.730 --> 20:15.960] One of them corresponds to the change key. [20:16.200 --> 20:17.790] The other is used by the master key. [20:19.880 --> 20:23.990] A key just has to raise one of these two cuts to the shear line. [20:24.940 --> 20:29.010] And the other one will either be above or below. [20:29.200 --> 20:34.710] And in a well-designed system, it's going to be kind of uniformly distributed where it's above and sometimes it will be below. [20:35.620 --> 20:41.730] So the change key is going to lift the change key cuts to a particular height. [20:43.470 --> 20:48.010] So now, I'll talk about some of these issues. [20:48.230 --> 20:58.180] So if you could figure out how to turn your change key that was given to you, say, for your dorm room and for your office into the master key, they might as well just give you the master key. [20:58.270 --> 21:02.860] There's no point in having different keys if it's easy to turn a change key into a master key. [21:03.230 --> 21:06.050] So it would be bad if you can do this. [21:06.050 --> 21:07.550] But it turns out you can. [21:09.340 --> 21:11.680] So let's go back to computer science for a second. [21:11.900 --> 21:15.380] Here's another bad program that somebody wrote. [21:16.440 --> 21:18.270] And it's, again, in pseudo C. [21:18.530 --> 21:23.550] This is for a two-password system where there's a user password and a master password. [21:23.840 --> 21:25.470] And here's the algorithm. [21:25.900 --> 21:30.290] You get the entire password. [21:30.290 --> 21:32.510] So we fixed that first bug. [21:32.510 --> 21:40.180] And now, we go up... and we'll assume the master password and the user password are the same length just to keep the program simple. [21:40.550 --> 21:42.310] We go up to the password length. [21:42.460 --> 21:50.840] If the letter at the particular position is the same as the user password or the master password, we keep going. [21:51.040 --> 21:52.220] Otherwise, we stop. [21:52.580 --> 21:54.940] And at the end, we return good or bad password. [21:55.420 --> 22:01.160] Does this meet the objective of opening with either the user password or the master password? [22:01.980 --> 22:02.740] It does. [22:02.900 --> 22:03.240] Yeah, it does. [22:03.360 --> 22:04.780] But it has another problem. [22:04.980 --> 22:06.740] Does it open with any other passwords? [22:07.260 --> 22:07.740] Yes. [22:08.020 --> 22:12.860] It opens with any password that's a combination of the user password and the master password. [22:13.100 --> 22:25.240] So this might be pretty secure against the outsider, but there are, in fact, a whole lot of passwords, other than the two that it's supposed to accept, that it turns out to accept. [22:25.240 --> 22:40.520] And, in fact, if you know one password, you can very efficiently learn the other, just by changing one character of the password that you know, one at a time, submitting it to the Oracle, and seeing whether or not it works. [22:41.000 --> 22:41.290] Right? [22:41.540 --> 22:46.900] You can see how you would be able to figure out the master password one character at a time. [22:47.680 --> 22:55.160] And that only costs you the size of the alphabet times the number of characters in the password queries to the Oracle. [22:55.440 --> 22:59.200] So, you'd fire the programmer who wrote this program, too. [22:59.740 --> 23:02.420] So, do master keyed locks work this way? [23:02.860 --> 23:03.280] Yes. [23:03.380 --> 23:04.260] So, ah! [23:04.600 --> 23:06.220] Turns out, yes, absolutely. [23:06.860 --> 23:10.780] All you need is a single lock and its change key, plus a few blank keys. [23:11.040 --> 23:12.620] You don't need any special skills. [23:12.620 --> 23:15.290] You can be as old as I am and still have this work. [23:15.290 --> 23:19.790] You don't need any precise hand movement like Bari has. [23:20.960 --> 23:28.740] And you just think of the lock as this password system that's been badly designed, so it checks the passwords one at a time independently. [23:29.220 --> 23:31.480] And the algorithm is very simple. [23:31.860 --> 23:32.940] P is the number of pins. [23:33.100 --> 23:34.100] D is the number of depths. [23:34.420 --> 23:46.760] And for each pin, and for each depth, prepare a test key that's the same as your change key, in every position except the one you want to find the master key for. [23:47.540 --> 23:50.900] Submit it to the Oracle and find out whether or not it turns. [23:51.620 --> 23:56.500] If it doesn't turn, you know that the depth you cut that for was not on the master key. [23:56.640 --> 24:04.240] If it does turn, then you've found the master height at that particular position. [24:04.240 --> 24:14.420] You can optimize this to only consume the number of blanks as tumblers by reusing blanks in a slightly cleverer way. [24:15.300 --> 24:22.440] And the bottom line is that for $2 or less, you can compromise virtually any master key system this way. [24:22.600 --> 24:25.740] You can cut the blanks with either a file or a key cutting machine. [24:25.740 --> 24:29.680] You can get blanks for most locks pretty readily available. [24:29.980 --> 24:31.180] You know, the internet is your friend. [24:32.360 --> 24:34.700] And yeah, it really actually works. [24:35.260 --> 24:41.740] Now, the important thing here is, first of all, this attack is against abstract locks. [24:42.140 --> 24:46.040] Making the lock more precise doesn't fix this. [24:46.280 --> 24:49.960] It's a problem with the design, not the problem with the manufacturer. [24:51.460 --> 25:01.480] So, the countermeasures to this have to either make it impossible for the attacker to get blank keys, which is pretty hard because blank keys are just pieces of metal. [25:02.700 --> 25:10.040] Or, fix the basic weakness that a lock shouldn't open with a combination of cuts for the change key and the master key. [25:10.200 --> 25:13.340] And this standard lock design just doesn't work that way. [25:17.090 --> 25:24.200] So, bottom line is that cryptography can be applied to locks fairly easily. [25:24.960 --> 25:26.740] Can I take about two more minutes? [25:26.920 --> 25:27.020] Sure. [25:27.140 --> 25:27.680] Okay, great. [25:28.580 --> 25:34.550] And, you know, it turns out computer security isn't very successful at protecting computers, as we can see. [25:34.700 --> 25:36.020] There are viruses all over the place. [25:36.120 --> 25:37.310] But it's good for something. [25:37.360 --> 25:39.180] You can at least use it to analyze locks. [25:40.480 --> 25:42.180] So, you know, that makes me feel better. [25:42.180 --> 25:43.780] I'm a computer security person. [25:43.980 --> 25:47.120] I've been a horrible, miserable failure at protecting computer systems. [25:47.260 --> 25:50.580] But at least I can get a job as a locksmith. [25:53.400 --> 25:56.660] Now, I just want to talk for a second about culture clash. [25:57.310 --> 26:03.980] You know, computer security people have traditionally, you know, kind of thought about openness as being really important. [26:04.500 --> 26:07.810] Talking about vulnerabilities is a good way to eliminate them. [26:08.180 --> 26:10.540] That's really in our blood, right? [26:11.280 --> 26:14.100] The scientific method kind of requires that. [26:14.540 --> 26:19.860] You know, you're kind of arguing with Isaac Newton if you say that you shouldn't talk about vulnerabilities. [26:21.500 --> 26:25.900] And basically, this acknowledges that we don't know everything there is to know about security. [26:25.900 --> 26:27.140] We've got a lot more to learn. [26:27.280 --> 26:29.400] The only way we're going to learn it is by being open. [26:30.360 --> 26:38.960] The human scale world, like, for example, locks or physical security or anti-terrorism, often doesn't view things this way. [26:39.550 --> 26:41.640] Security isn't really viewed as a research topic. [26:41.780 --> 26:43.740] It's just viewed as a way of keeping out bad guys. [26:43.920 --> 26:48.460] And people intuitively think that we already know everything there is to know. [26:48.580 --> 26:52.100] The problem is, you know, people just shouldn't think about how to do these things. [26:52.100 --> 26:55.000] Why would somebody think about how to attack systems? [26:55.480 --> 26:57.790] And, you know, you probably get that all the time. [26:57.920 --> 26:58.780] Why are you thinking about this? [26:58.860 --> 26:59.810] You must be a bad guy. [27:00.420 --> 27:06.310] And it's interesting that mechanical locksmithing used to be the way computer scientists thought. [27:07.040 --> 27:10.040] And have kind of slipped into a dark ages. [27:10.460 --> 27:11.780] So I'm going to read you this quote. [27:11.920 --> 27:12.980] It's impossible to read there. [27:13.240 --> 27:14.700] Alfred Hobbes, he's my hero. [27:14.860 --> 27:16.280] He deserves to be your hero. [27:16.860 --> 27:17.980] He was an American. [27:17.980 --> 27:22.880] He went to London and broke all of the major lock systems in use at the time. [27:22.980 --> 27:24.660] He figured out how to pick all these locks. [27:25.140 --> 27:27.760] And he picked the Brahma lock. [27:28.000 --> 27:33.700] That was the thing that really made him famous, which was this unpickable lock that for 50 years they'd had a challenge. [27:33.700 --> 27:36.900] You could win 200 guineas if you could pick the Brahma lock. [27:37.160 --> 27:40.200] 50 years later he went to London and he did it in a couple of days. [27:40.920 --> 27:43.660] And then he picked the Yale lock and the Chubb lock. [27:43.860 --> 27:46.340] And these are all the major lock designs that are still used. [27:46.520 --> 27:48.640] So nobody listened to Hobbes, it turned out. [27:50.280 --> 27:54.000] So he wrote his memoirs and he described how he did all of these things. [27:54.440 --> 28:00.980] And in the preface, he and Tomlinson, the editor of his memoirs, wrote this very eloquent thing. [28:00.980 --> 28:03.540] It could have been written today except for the fact that it's well written. [28:06.020 --> 28:11.440] A commercial and in some respects social doubt has been started within the last year or two. [28:11.600 --> 28:15.840] Whether or not it is right to discuss so openly the security or insecurity of locks. [28:16.420 --> 28:27.700] Many well-meaning persons suppose that the discussion respecting the means for baffling the supposed safety of locks offers a premium for dishonesty by showing others how to be dishonest. [28:27.700 --> 28:29.360] This is a fallacy. [28:30.000 --> 28:36.400] Rogues are very keen in their profession and already know much more than we can teach them, respecting their several kinds of roguery. [28:37.100 --> 28:42.260] Rogues knew a good deal about lockpicking long before locksmiths discussed it among themselves as they've lately done. [28:42.540 --> 28:53.540] If a lock, let it have been made in whatever country or by whatever maker, is not so invaluable as it has hitherto been deemed to be, surely it is in the interest of honest persons to know this fact. [28:53.700 --> 28:58.240] Because the dishonest are tolerably certain to apply the knowledge practically. [28:58.700 --> 29:04.380] And the spread of the knowledge is necessary to give fair play to those who might suffer by ignorance. [29:04.740 --> 29:12.840] It cannot be to earnestly urge that an acquaintance with real facts will in the end be better for all parties. [29:12.840 --> 29:16.240] Now, you know, that's a pretty modern view, right? [29:16.360 --> 29:17.620] And this is 1853. [29:18.460 --> 29:22.360] Now, it turns out that Hobbes was preaching to the choir. [29:22.600 --> 29:26.600] The community that he was in understood that you had to talk about these things. [29:26.620 --> 29:29.680] And he was really just playing with you. [29:30.180 --> 29:34.500] And, you know, giving people ammunition for thinking about what they already knew to be right. [29:34.500 --> 29:39.490] So this was the mainstream of locksmithing openness in 1853. [29:40.440 --> 29:43.580] Somewhere in a hundred years, things just took a turn. [29:44.160 --> 29:49.900] So I'm going to give you a quote from another book, the standard book on opening safes. [29:50.050 --> 29:58.550] The standard book on safe cracking called The Art of Manipulation, written by Lentz and Kenton, published in, a hundred years later, 1953. [29:59.070 --> 30:02.200] And it has a preface, too, in which they talk about openness. [30:02.700 --> 30:12.640] So they say at the beginning of their book, it is extremely important that the information contained in this book be faithfully guarded, so as not to fall into the hands of undesirables. [30:12.840 --> 30:14.080] That, by the way, is you. [30:15.390 --> 30:23.780] We also suggest after you become proficient in the art of manipulation, you destroy this book completely, so as to protect yourself and our craft. [30:24.900 --> 30:27.780] By the way, I got my copy of this out of the library. [30:27.780 --> 30:28.440] So... [30:29.280 --> 30:30.280] What can you do? [30:30.500 --> 30:37.020] Now, 50 years after that, in 2003, a fellow by the name of Billy B. [30:37.200 --> 30:54.400] Edwards, a prominent locksmith expert in master keying, wrote in a guest editorial in the National Locksmith, which I think he didn't realize I subscribed to, a publication for locksmiths, Blaze's master keying paper, the stuff I just described, shouldn't have been published, [30:54.400 --> 30:59.240] because the only people that will educate are the dishonest who will use it to compromise security. [30:59.860 --> 31:01.480] Locksmiths don't have to be surreptitious. [31:01.860 --> 31:07.020] No, we can't call him a moron, because he is obviously intelligent. [31:07.660 --> 31:10.860] After all, he did grasp the concepts of master keying. [31:11.220 --> 31:15.580] We can see, however, that he is an inexperienced amateur when it comes to physical security. [31:15.580 --> 31:20.000] In his computerized world, it's a simple thing to fix a security problem. [31:20.200 --> 31:21.680] You just load new software. [31:23.220 --> 31:31.680] So, the bottom line is that the locksmithing community and the computer science community seem to have different views on the subject of openness. [31:32.160 --> 31:38.580] But, in fact, some of the tools of computer science are probably very useful for thinking about locks. [31:38.580 --> 31:46.200] And with that, I'd like to turn it over to the second most dangerous person I know, Mark Tobias. [31:51.670 --> 31:52.970] Whoa, whoa, whoa, whoa, whoa. [31:53.330 --> 31:54.030] Yeah, wait, wait, wait. [31:54.270 --> 31:55.230] We just had a... [31:55.230 --> 31:58.410] He's loading. [31:58.950 --> 31:59.170] All right. [32:00.110 --> 32:00.250] Yeah. [32:03.120 --> 32:03.380] Problem. [32:03.880 --> 32:04.640] Just going to... [32:04.980 --> 32:06.460] Just a minute, I've got a problem here. [32:06.960 --> 32:08.340] Because it's coming off the... [32:08.340 --> 32:09.100] What did I say here? [32:09.540 --> 32:09.680] Yeah. [32:20.160 --> 32:21.120] It's, um... [32:21.120 --> 32:21.880] It should be... [32:21.880 --> 32:23.400] Yeah, that was the... [32:23.400 --> 32:24.500] You got something... [32:24.500 --> 32:25.480] We can... [32:25.480 --> 32:26.520] No, not for right now. [32:28.680 --> 32:29.120] Um... [32:29.120 --> 32:29.740] Do you have a... [32:29.740 --> 32:30.900] Law of some sort? [32:31.040 --> 32:31.240] No. [32:31.940 --> 32:32.140] Um... [32:32.140 --> 32:34.200] The woman with the baby probably has one, yeah. [32:34.460 --> 32:36.940] Does anybody have an absorbent piece of material? [32:37.780 --> 32:38.060] Or... [32:40.060 --> 32:41.220] Like a paper towel. [32:41.380 --> 32:42.000] Or a diaper. [32:42.360 --> 32:42.580] Or a diaper. [32:42.740 --> 32:44.740] Yeah, we just spilled some water here. [32:46.460 --> 32:47.660] Keyboards absorb water. [32:48.260 --> 32:48.700] Yeah. [32:48.700 --> 32:50.160] Yeah, so do computers. [32:50.560 --> 32:51.260] Hey, hey, hey, hey. [32:54.240 --> 32:54.840] Thank you. [32:54.960 --> 32:55.040] Thank you. [32:55.040 --> 32:55.340] Very kind. [32:55.640 --> 32:56.120] Thank you. [32:56.520 --> 32:56.860] Ah, great. [32:57.040 --> 32:57.180] Thanks. [32:57.300 --> 32:57.920] Thanks very much. [32:58.360 --> 32:58.820] There we go. [32:59.180 --> 32:59.280] Thanks. [32:59.740 --> 33:00.140] Okay. [33:00.320 --> 33:00.940] Yeah, we're all right. [33:00.940 --> 33:01.140] Probably enough. [33:01.340 --> 33:01.440] Yeah. [33:02.760 --> 33:03.160] Okay. [33:03.400 --> 33:05.460] Let's make the overhead work. [33:05.780 --> 33:06.660] So it should be... [33:06.660 --> 33:07.180] It should be up. [33:07.480 --> 33:07.720] Yeah. [33:08.080 --> 33:08.260] Yeah. [33:28.500 --> 33:30.680] What do you want to do here? [33:31.060 --> 33:31.680] Function F7 again. [33:32.160 --> 33:33.020] Function F7? [33:36.220 --> 33:36.620] Wait. [33:36.840 --> 33:37.860] It sometimes takes a second. [33:38.780 --> 33:39.220] Ah, look. [33:39.380 --> 33:39.660] Something... [33:39.660 --> 33:39.740] Yeah. [33:39.800 --> 33:40.160] There you go. [33:40.200 --> 33:40.620] There we go. [33:40.820 --> 33:40.900] Okay. [33:41.660 --> 33:42.020] Okay. [33:42.800 --> 33:43.680] Well, good morning. [33:43.980 --> 33:47.000] We're going to talk about some reality now rather than more theory. [33:47.540 --> 33:47.820] Um... [33:47.820 --> 33:49.060] I deal in the real world. [33:50.260 --> 33:50.660] Um... [33:50.660 --> 33:51.420] Matt more... [33:51.420 --> 33:53.900] Matt more deals than the theoretical world. [33:54.400 --> 33:54.700] Um... [33:54.700 --> 33:55.780] And so the two have merged. [33:55.880 --> 33:59.940] And some of the slides that I've got are going to be duplicates of his so I'll run through them pretty fast. [34:00.940 --> 34:01.540] Um... [34:01.540 --> 34:04.040] I want to talk about, um... [34:04.040 --> 34:08.660] More master keying but in somewhat in more of the real world. [34:09.000 --> 34:09.520] Um... [34:09.520 --> 34:12.220] My background, very briefly, I'm a lawyer. [34:12.460 --> 34:22.400] I specialize in, uh, fraud investigations and bypass of high security locks for a variety of clients and analyzing, uh, locks and locking systems for bypass. [34:23.700 --> 34:24.300] Um... [34:24.300 --> 34:29.920] I'm the guy that wrote the eight pound book that's great for, uh, pressing flowers and nighttime reading. [34:30.640 --> 34:31.200] Uh... [34:31.200 --> 34:39.640] And also the multi... the multimedia edition of that book, uh, which is up to 14 volumes of CD and about 60 hours of audio and video. [34:40.420 --> 34:43.640] And, uh, which... part of it's available. [34:44.140 --> 34:46.140] Barry, uh, contacted me. [34:46.260 --> 34:51.320] I see Barry, uh, sort of frequently in Amsterdam for dinner, um, when I'm in Europe. [34:51.320 --> 35:03.380] And, uh, we decided that for you guys that are getting into lock picking, um, we would run a special, um, set of picks to commemorate the conference here. [35:03.560 --> 35:07.900] And so we did that and, uh, actually some of those are still left. [35:08.260 --> 35:14.780] Um, if you really want to get into it, um, this is... this is how you start and... and with some reference materials. [35:14.780 --> 35:21.200] Um, so I'm gonna talk about a variety of issues, uh, in the very few minutes left to me. [35:22.040 --> 35:24.780] Um, and... no... [35:25.340 --> 35:25.780] Thank you. [35:26.380 --> 35:32.940] Um, and so first I'm gonna talk about Master King and security issues and the reality side of this. [35:33.560 --> 35:39.160] Um, Matt caused quite a stir in the industry, um, that I'm sort of part of. [35:39.160 --> 35:46.720] Um, uh, in January of 03 in the New York Times, um, when he was with AT&T Labs. [35:47.100 --> 35:55.640] Um, in exposing a vulnerability in Master Key Systems that, um, some locksmiths were aware of. [35:55.980 --> 35:58.660] Almost none of their clients were aware of. [35:58.760 --> 36:05.900] And from the legal standpoint, um, my interest in it as a lawyer is the liability issue to start with. [36:05.900 --> 36:15.820] And the problem is that virtually every building in the world, other than some military installations, are Master Keyed. [36:16.000 --> 36:22.860] And generally, there's a top level Master Key that we abbreviate TMK. [36:22.980 --> 36:26.880] Um, that will open every lock in the facility. [36:27.240 --> 36:35.160] And so, obviously, if you can break that top level Master Key, you own the facility. [36:35.980 --> 36:37.600] And therein lies the problem. [36:37.740 --> 36:43.900] And I also have to tell you guys, um, I was listening to the, uh, the panel before us on phone freaking. [36:44.420 --> 36:50.300] And, uh, I can tell you if they had computers when I was in high school and college, I would still be locked up. [36:51.960 --> 36:52.360] Uh... [36:53.040 --> 36:59.740] And also, I can tell you that because the statute of limitations is run on phone freaking, I can admit to doing a lot of it. [37:01.040 --> 37:05.020] Especially when Teltone came out with their chip to make it really easy to do. [37:05.860 --> 37:12.540] Uh, and as a matter of fact, uh, a case I was working about ten years ago, one of the email addresses I have. [37:12.660 --> 37:15.040] And I have two of them that you guys can write down. [37:15.360 --> 37:20.120] And if you have any feedback or information that you'd like to share with me, it'd be great. [37:20.120 --> 37:25.560] Uh, my primary address is MWTobias at security.org. [37:26.040 --> 37:30.460] And my second one is Multifreak at security.org. [37:30.760 --> 37:34.420] And for you guys that have been around, you know exactly what that means. [37:34.420 --> 37:42.360] Okay, so master keying, um, we're gonna talk about master keying, high security locks. [37:42.660 --> 37:53.740] Uh, there are two of them in the world that can essentially, um, combat the issue that Matt Blaze brought to a blazing public light. [37:54.120 --> 38:01.480] And much to everybody's chagrin in the locksmith profession, um, they all actually think this is still secret information. [38:01.480 --> 38:03.440] They obviously haven't gone on the internet. [38:04.480 --> 38:08.440] And, uh, there, there essentially are no secrets in the industry. [38:09.360 --> 38:15.960] Um, and there are ways of protecting master key systems that I'll briefly touch on this morning. [38:16.780 --> 38:20.740] Um, and, uh, and two in particular. [38:21.400 --> 38:25.840] I'll also touch on a couple issues that, uh, you probably would find of interest. [38:26.180 --> 38:32.480] There's been a lot of talk lately about the 999 or the bump key or the percussion key, as they're calling it in the UK. [38:32.980 --> 38:36.560] And this is a method that was developed in Denmark. [38:36.900 --> 38:45.200] Um, that will allow you to open a lot of cylinders instantly by wrapping on them with a specially designed key that you insert into the lock. [38:45.400 --> 38:47.620] And by the way, uh, Matt mentioned... [38:47.620 --> 38:52.360] Oh, okay, so Barry's got one to show you, which actually we talked about last night. [38:52.360 --> 38:56.620] And, and so I had forgotten at this point, but it's very simple. [38:56.620 --> 39:00.680] And there's a video that you can look at offline, uh, after the panel, if you'd like. [39:00.800 --> 39:02.500] It was done by Hiles Miles... [39:02.500 --> 39:11.780] Um, Hans Miles Heda in Denmark that I shot as part of my CD-ROM series that shows in about two minutes how to go click, click, and the cylinder's open. [39:11.780 --> 39:14.400] And I'm sure Barry will demonstrate that for you. [39:14.500 --> 39:15.480] It's actually very clever. [39:15.780 --> 39:23.840] Um, and it's based on the old impact, uh, picking principle, uh, with a pick gun or a snap gun that I'll also show you very briefly. [39:24.600 --> 39:35.500] Um, also, I wanted to make a note about the Schlage Everest lock, which is a, uh, very clever lock that Schlage sort of represents as a high-security cylinder. [39:35.500 --> 39:37.260] Um, it is not. [39:37.660 --> 39:47.820] And, uh, their, their lawyers sent me the appropriate threatening letter, um, because I was teaching at a LOA last summer in a covert entry course and they didn't like it. [39:48.140 --> 39:56.600] And I suggested that maybe they get John Ashcroft to modify the Patriot Act to prevent, uh, teaching or documentation of lock picking or bypass. [39:56.920 --> 40:02.520] And they, they didn't find that too humorous and ended up sending me a apology letter. [40:02.520 --> 40:07.000] Um, and so I'm, um, helping them out a little bit. [40:07.660 --> 40:16.600] And, but anyway, the Schlage Everest lock and, um, actually, uh, I think Matt brought a, uh, dome lock that's, uh, based on the same principle. [40:17.380 --> 40:21.060] Um, you probably, you won't be able to see this, but Barry, why don't you hold that up? [40:21.480 --> 40:23.940] Okay, but maybe we, we, we could try to... [40:23.940 --> 40:24.600] We can show it. [40:24.800 --> 40:27.380] Basically, the bottom line is, and I'll show you a macro photograph. [40:27.380 --> 40:34.540] There's an undercut on the, uh, key that makes the key blank extremely difficult to replicate. [40:35.140 --> 40:36.880] Uh, you can't do it in a normal key machine. [40:37.060 --> 40:38.760] Basically, the blanks come from the factory. [40:39.080 --> 40:41.400] Also, I'll make a couple impressioning notes. [40:41.540 --> 40:56.300] And the reason for that is that one of the conference participants that's registered on our website came up to me yesterday and presented me with the, uh, computer lock made by Kensington, which is probably the best one in the country, and probably also the most effective. [40:57.580 --> 41:02.320] Um, and, uh, my newfound friends at Kensington, I'm sure I'll be hearing from them. [41:02.940 --> 41:07.800] Um, this, uh, this is an axial pin tumbler lock that you're all familiar with. [41:08.280 --> 41:13.640] Um, unfortunately, you can stick a ballpoint pen into it and impression it in about 10 seconds and open it. [41:13.640 --> 41:25.180] Um, and, uh, so I'll show you the other side of that is a foil impressioning system that was developed by John Fall, one of my associates in England, uh, who's probably the top guy in the world. [41:25.360 --> 41:29.840] But it turns out that a little paper mate pen, you just stick it in the key way and go click, click, and it's open. [41:30.460 --> 41:49.960] And, and finally, if, if at the end of this panel we have any time, um, I'd like to summarize for you a burglary investigation that I was privileged to review a part of in Antwerp a few months ago in Belgium involving the theft of a hundred million dollars worth of diamonds, [41:50.320 --> 41:53.020] essentially none of which have been recovered. [41:53.460 --> 41:56.120] Seven career criminals from Italy were involved. [41:56.340 --> 42:09.760] Um, the burglary occurred essentially out of, uh, negligence and aptness and stupidity on the part of building owners, um, at the diamond exchange in Antwerp where 85% of the world's uncut diamonds are processed. [42:10.140 --> 42:22.620] Uh, they sent me one of their threatening letters a couple months ago, um, telling me that if I represented that they were in any way negligent that they would go after me and I sent them an appropriate letter in response. [42:23.360 --> 42:28.740] And, um, the, the lawyers have the right to do that. [42:28.740 --> 42:36.280] And, uh, the bottom line is, one, I haven't heard from them, and two, they haven't recovered the hundred million dollars in diamonds. [42:36.620 --> 42:38.500] And so, with that, let's move on. [42:38.720 --> 42:46.760] Okay, Master King Theory, and as I said, um, some of these slides are the same as Matt used, so I, I won't go through them, uh, in detail. [42:47.260 --> 42:51.240] We're basically talking about conventional pin tumbler locks. [42:51.420 --> 42:55.980] There are essentially two kinds of basic pin tumbler locks. [42:55.980 --> 43:00.940] Um, one uses conventional keys, as Matt showed you. [43:01.200 --> 43:08.060] The other type use a master keying system called positional master keying, and Barry's got some of these. [43:08.520 --> 43:10.260] Uh, basically they're dimple locks. [43:10.440 --> 43:26.820] And dimple locks vastly differ from conventional pin tumbler locks, um, in that they're, the, the secret to opening a dimple lock is, A, to know where the dimples are, because they're moved around as far as tumbler positions. [43:27.100 --> 43:34.180] And they're pin tumbler locks, but they, the, the keys have holes in them, rather than a normal bidding surface. [43:34.640 --> 43:37.520] And so, we, we, and Barry is showing you one. [43:37.760 --> 43:41.860] And so, there's a number of high security manufacturers that make these. [43:41.860 --> 43:54.100] Uh, however, most of them can be, uh, opened and decoded rather instantly with a foil impressioning system, where the foil actually impressions the lock. [43:54.900 --> 44:08.380] Um, and there's, there's several very high tech tools to do this, but the bottom line is, a popsicle stick soaked in alcohol, or a, a little carrier with aluminum foil, with special aluminum foil will open them. [44:08.380 --> 44:14.640] Uh, so, Matt showed this, uh, basically inside the pin tumbler lock, we have what are called pin stacks. [44:14.980 --> 44:20.820] And there's a pin stack comprised of a top pin, a bottom pin, uh, in this lock. [44:21.000 --> 44:22.960] This lock is not master keyed. [44:23.080 --> 44:28.200] And so, we only have what's called one shear line. [44:28.380 --> 44:39.400] That is when all the bottom pins line up, um, at the edge or circumference, uh, the inner circumference of the plug, then the plug can rotate. [44:39.700 --> 44:45.340] So, what we're talking about is a shear line, as you can see here, lined up and it can rotate. [44:45.780 --> 44:53.920] When the correct key is inserted as shown, the shear line is lined up, so the plug forms a continuous surface and it can rotate. [44:54.240 --> 45:05.060] When the incorrect key is inserted, then one or more pin tumblers, and all it takes is a couple thousandths of an inch difference, uh, the plug is blocked from rotation. [45:05.060 --> 45:11.120] So, here, this is... and all of these photographs, by the way, are contained, um, in my book and CD. [45:11.340 --> 45:13.780] There's a lot of information that we're all covering today. [45:14.060 --> 45:18.080] If you want to do more reading about it, uh, that's one of the places to go. [45:18.720 --> 45:24.000] Um, so, this is a plug that cannot turn, as you can see, because the blue top pin is blocking it. [45:24.960 --> 45:32.380] Here, the pin is... the pins are at shear lines, so they're split between what's indicated by the red pin and the blue pin. [45:32.380 --> 45:34.380] And there, the plug is turned. [45:34.960 --> 45:37.700] Okay, so, master keying, why is it important? [45:37.980 --> 45:45.100] Because every large facility is master keyed, and a compromise of the top-level master key, you'll own the facility. [45:45.560 --> 45:50.100] Basically, to compromise a master key system, there's no risk involved. [45:50.320 --> 45:51.780] You get all the locks. [45:51.980 --> 45:54.060] It's absolute access. [45:54.500 --> 45:56.180] There's no high-tech involved. [45:56.180 --> 45:59.080] There's no forensic trace that can be found. [45:59.480 --> 46:02.520] And there's no time limit to break the system. [46:02.820 --> 46:04.400] So, what is master keying? [46:04.500 --> 46:07.980] As Matt told you, we have change keys, and we have a top-level master key. [46:08.200 --> 46:11.460] We also have what's called incidental master keys. [46:11.820 --> 46:22.480] And incidental master keys are composite combinations of pins, bottom pins and middle pins, that'll also allow that lock to be open. [46:23.380 --> 46:25.280] So, master key security design. [46:25.420 --> 46:27.740] What makes a master key system secure? [46:28.220 --> 46:32.980] Well, essentially, it's how difficult is the blank to replicate. [46:33.280 --> 46:35.680] That's really what it all comes down to. [46:36.000 --> 46:43.660] The rest of this, it's okay, but the bottom line is, if you can't replicate the blank, you're not gonna break the system. [46:45.080 --> 46:48.240] A number of different locks can be master keyed. [46:48.420 --> 46:51.540] There's lever locks, wafer locks, and pin tumbler locks. [46:51.680 --> 46:59.260] But the bottom line is, we're talking about pin tumbler locks because there's billions of them in the world, and that's what's really out there. [46:59.520 --> 47:07.380] So, again, in the master keyed environment, we have two lower pins that comprise the pin stack plus a top pin. [47:07.380 --> 47:15.860] And so, what we're doing is, we're creating a composite, and then we're sampling the cylinder at each position. [47:16.280 --> 47:25.560] So, what I've called in my book, this process, is called extrapolation of the top level master key. [47:25.840 --> 47:35.420] And basically, what we're doing, as Matt told you, is we're testing a sample lock, which is not going to be your target lock. [47:35.420 --> 47:42.020] We're testing that lock for every pin segment in every position. [47:42.360 --> 47:47.240] It's simple, it's easy, there's been a lot of publicity about it. [47:47.360 --> 47:50.140] It is a serious threat to security. [47:50.400 --> 47:55.240] And as Matt said, there's no special tools involved, no expertise is really required. [47:55.520 --> 47:58.400] All you need is a file, and it's basically covert. [47:59.040 --> 48:10.160] And so, and basically, all you need is one change key to target a lock, to test it, to open a lock to generate the top level master key. [48:10.360 --> 48:13.100] So, as Matt told you, we're reading the lock. [48:13.540 --> 48:15.540] An attack can cost less than $2. [48:17.020 --> 48:21.240] A blank can be cut with a handheld punch, a file or a key machine. [48:22.100 --> 48:24.740] Blanks are available for most locks. [48:25.180 --> 48:30.300] Now, the trick is, some locks, some high security locks, have restricted keyways. [48:30.460 --> 48:37.940] And we're going to talk about that in a minute, because there's a neat little machine made in Germany, called the Easy Entry. [48:38.040 --> 48:43.040] It's a profile milling machine that will replicate almost every blank. [48:43.040 --> 48:49.960] So, basically, what are we going to do when we go to break a master key system? [48:50.540 --> 48:53.360] Basically, what you're going to do is you're going to set up... [48:53.360 --> 48:55.780] Let's just say it's a five pin lock. [48:56.000 --> 49:08.260] We're going to pre-cut, if we really want to do this quickly and rapidly, we're going to pre-cut five blanks with the same key code as on the change key that you have. [49:08.260 --> 49:14.300] But we're going to alter one position to begin at the top, either a zero or a one. [49:14.900 --> 49:22.920] And then we're going to file down or cut down each one of those positions in sequence until we derive the top level master key code. [49:23.160 --> 49:32.660] And when I was interviewed by the New York Times as part of Matt's article, they said, well, bring this down to real reality here. [49:32.760 --> 49:34.960] And I said, well, let's take New York. [49:34.960 --> 49:38.640] All the restrooms in public buildings are generally locked. [49:39.260 --> 49:47.300] And so when you go to an office for a visit, if you want to use the restroom, you ask the receptionist for a key to the restroom. [49:47.440 --> 49:48.880] And, of course, they'll oblige you. [49:49.120 --> 50:02.000] Once you have that key to that restroom, if that restroom cylinder is on the top level master key, which in most places it is because this is called convenience, you own the system. [50:02.000 --> 50:08.960] Because all you have to do is decode that key or make a silicone impression or copy it. [50:09.480 --> 50:16.680] And then at will, over your convenience, you can go sample that restroom lock for the top level master key. [50:16.900 --> 50:20.780] And, as I said, when you get that, then you walk into anywhere in the building. [50:21.600 --> 50:27.080] So the decoding process, as Matt referred to, you can do it in one session. [50:27.080 --> 50:29.220] You can do it in multiple sessions. [50:29.700 --> 50:31.260] There's no forensic trace. [50:31.440 --> 50:32.380] This is the problem. [50:32.920 --> 50:34.460] And you walk up to a lock. [50:34.620 --> 50:35.400] You stick a key in it. [50:35.460 --> 50:39.200] If it opens it, you know that you've decoded another position. [50:39.200 --> 50:43.060] If it doesn't, you go back or, you know, you go wherever. [50:43.100 --> 50:47.340] You file it down to the next tumbler position and you test it again. [50:47.340 --> 50:52.360] So what I've done is a graphic representation of each chamber position. [50:54.520 --> 50:57.440] And, basically, you're testing each chamber. [50:57.680 --> 51:01.100] And, actually, a five tumbler lock, you can do it. [51:01.120 --> 51:04.080] I calculate it in four keys if you're really lucky. [51:04.220 --> 51:05.450] It depends on the bidding combination. [51:06.160 --> 51:09.740] So, how do we make master key systems more secure? [51:09.740 --> 51:21.100] Well, the real way to do it and the only way to do it, one, as Matt suggested, you can add additional pins in the pin stack. [51:21.720 --> 51:26.800] That's true, but it lessens the security of the lock because it becomes a lot easier to pick. [51:27.020 --> 51:29.640] So, it's not an acceptable alternative. [51:30.280 --> 51:34.960] Theoretically, yeah, it'll make it more difficult because you have to decode more permutations. [51:34.960 --> 51:37.280] But, at the end of the day, it's not the way to do it. [51:38.200 --> 51:43.140] You can use what's called a Corbin master ring, which is about a 75-year-old technique. [51:43.220 --> 51:45.400] Actually, it was invented over 100 years ago. [51:45.680 --> 51:47.680] There aren't very many of those systems around. [51:48.440 --> 51:52.380] And, it's also a way to do it, but they also have their own security problems. [51:52.760 --> 52:02.840] So, basically, the real way to protect these master key systems, because everybody asked me after Matt's article came out, well, okay, Matt's come out with a problem, what's the solution? [52:02.840 --> 52:05.540] Well, in fact, there is a solution. [52:05.820 --> 52:11.900] The solution is Medeco and ASA with multiple sidebar codes. [52:12.080 --> 52:15.080] And, what I mean by that is the Medeco lock... [52:15.080 --> 52:16.320] How many of you are familiar with Medeco? [52:17.160 --> 52:18.700] Okay, everybody's heard of Medeco. [52:18.840 --> 52:21.460] Medeco probably owns the high security market in America. [52:21.700 --> 52:23.500] They really are, in my view, the best. [52:23.720 --> 52:30.720] So, the bottom line is the Medeco locks, you not only raise the tumblers with the bidding on the keys, but you twist them. [52:30.720 --> 52:41.260] Both actions occur simultaneously, and when you twist the tumblers, a secondary sidebar drops into the plug to allow it to rotate. [52:41.560 --> 52:51.580] So, if either the vertical biddings are incorrect, or the sidebar cuts are incorrect, the rotation is incorrect, the lock won't open. [52:51.580 --> 52:55.320] So, you're really running two kinds of master key systems at once. [52:55.540 --> 53:05.880] You're running a conventional master key system, and you're also running a positional master key system with regard to the location of the rotating tumblers. [53:05.880 --> 53:23.740] So, these systems, although they can be defeated, it's a lot more difficult, and if you walk up to a lock without a change key, it's very, very difficult to obtain the top level master key. [53:23.740 --> 53:37.800] And we're talking now about the Medeco biaxial, which has double the number of rotating positions that the original Medeco did, and there's a representation here in the color diagram. [53:37.800 --> 53:43.020] There's four and aft positions, and there's left, center, and right rotation. [53:43.320 --> 53:56.840] And so, this is a very clever design, and Medeco has made it possible to have different sidebar codes for different groups of locks. [53:57.100 --> 54:06.360] So, if you're targeting a lock that isn't in the same sidebar code group, you have a serious problem to decode that lock. [54:06.360 --> 54:10.360] And here's a graphic representation of a Medeco biaxial lock. [54:10.780 --> 54:24.140] And essentially, what Medeco is doing for the top level master key is double cutting the master key, the top level master key, to accommodate a matrix of all the individual sidebar code groups. [54:24.380 --> 54:29.280] The other lock that will prevent the problem is made by ASSA. [54:29.560 --> 54:33.960] And it's the ASSA V10, which we don't see in America very much. [54:33.960 --> 54:43.840] It's only in three very high security installations in America, one of which doesn't exist anymore, because Al Qaeda took care of it in 2001. [54:44.340 --> 54:48.100] But there's two other major, major facilities in the country where this is used. [54:48.340 --> 54:56.400] And it's essentially the same as the Medeco approach, only it depends on sidebar millings as shown on these keys. [54:56.400 --> 55:02.740] And so if you don't have this right sidebar milling, you have a serious problem decoding this lock. [55:02.980 --> 55:13.640] And so basically what ASSA has done is take the pins and they look at either the left or the right hand side of the key for contact points, as you can see here. [55:16.660 --> 55:24.120] So the next level, Medeco just came out with the first of the year that some of you may have heard about. [55:24.300 --> 55:25.600] It's called the M3. [55:26.160 --> 55:42.400] This is a Medeco lock with a third level of security that has a protruding side pin that activates a slider mechanism that has to interface with the side bar that makes this lock extremely secure. [55:42.680 --> 55:46.940] I'm not telling you it can't be decoded, but it's very, very difficult. [55:47.340 --> 55:50.740] These photographs show what the sliders look like. [55:50.940 --> 55:54.460] There's over 25 positions that this slider can assume. [55:54.740 --> 56:02.040] And the locks can further be subdivided for master key only, change key only, or change key and master key access. [56:02.700 --> 56:05.620] And so it's a pretty slick deal. [56:06.880 --> 56:10.060] As I said, Barry's going to talk about a bump key. [56:10.420 --> 56:14.960] And this is the...it's a result of impact picking. [56:16.100 --> 56:20.940] Such as the electoral pick that's made in Germany, which is...this is actually one of the better ones. [56:22.120 --> 56:24.880] It's essentially Newton's third law of motion. [56:25.180 --> 56:27.760] For every action, there's an equal and opposite reaction. [56:27.760 --> 56:39.840] And so when you bounce the tumblers, and this is especially appropriate for picking mushroom pin tumbler locks, you bounce the pins and in two seconds you can buzz open the lock if you're really good at it. [56:40.360 --> 56:42.800] This is what a bump key looks like. [56:42.920 --> 56:54.900] And basically it's called a 999 key in Denmark because all the cuts are cut all the way down to the lowest code number that's available or the deepest cut on the lock. [56:55.060 --> 56:59.380] And Barry will explain a little more to you how that works shortly. [57:00.160 --> 57:01.560] There's also comb picking. [57:01.620 --> 57:02.440] Are you going to talk about that? [57:02.860 --> 57:05.320] I wanted to, but if you can show it, it's better. [57:05.540 --> 57:05.860] Okay. [57:06.120 --> 57:07.620] This is a comb pick. [57:07.980 --> 57:10.100] This is actually made by John Fall. [57:10.540 --> 57:15.660] Believe it or not, a lot of the manufacturers today still don't get this concept. [57:16.560 --> 57:24.600] All of the pin stack, the length of the top pin and the bottom pin in each pin stack have to be constant. [57:25.140 --> 57:32.180] In the old days, all of the top pins, which were then called drivers when I grew up, were of the same length. [57:32.400 --> 57:42.180] The problem with that theory is that you can take a comb, which is shown on the left-hand side, and you can essentially create your own shear line. [57:42.740 --> 57:46.500] So, Matt, let me have your laser pointer. [57:47.660 --> 57:48.280] Okay. [57:53.170 --> 58:07.330] We actually create our own shear line by sticking this, we replicate the key, and then we lift that so we actually push all the lower tumblers up above into the top chamber area, and then the lock opens, no problem. [58:07.790 --> 58:11.770] And you can still do this with a lot of locks today, unbelievable as it is. [58:12.990 --> 58:13.250] Okay. [58:13.610 --> 58:28.510] Then we have the Schlage Everest, which I referred to before, and the Schlage Everest has got an undercut, which I've denoted in blue, and what this does is it raises a little check pin, so unless that check pin is raised, the plug cannot rotate. [58:28.910 --> 58:33.690] It's actually a very clever design, but it's very easy to knock off with a profile milling machine. [58:33.690 --> 58:35.670] This is a patented key way. [58:36.290 --> 58:44.690] So, of course, Schlage said, Mr. Tobias, you can't talk about that, that's a felony, because you're showing how to infringe on our patent. [58:44.870 --> 58:47.510] Well, unfortunately for Schlage, not quite. [58:49.050 --> 58:54.810] Because what the easy entry does is it draws around the key way, so it creates a different profile. [58:55.370 --> 59:09.510] One of my friends, they actually, the company that made the picks that we have here for you guys, also make this pick, or tension wrench, that lifts the check pin, so if you put that into the Schlage Everest, it's a conventional lock to pick it. [59:09.990 --> 59:12.790] I think Barry's also going to talk about the Sputnik. [59:13.290 --> 59:14.190] Yeah, I brought one. [59:14.310 --> 59:14.570] Okay. [59:15.470 --> 59:21.650] The Sputnik is a very clever design that's made in Germany, sold by MSC. [59:22.330 --> 59:34.990] And it's actually got, you can actually manipulate each tumbler individually and at the same time with a series of fine wires that are pushed so you raise each tumbler to shear line. [59:35.190 --> 59:41.350] It's sort of like picking an axial pin tumbler lock, because you have access to all the tumblers at the same time. [59:44.750 --> 59:48.610] And this is, how do we, okay, let me get back to, [59:52.660 --> 59:56.700] how do we get back to, okay, alright. [59:57.000 --> 01:00:06.740] So, as we can see on this macro, from the area in my CD on this, it shows how each of these wires can control a pin. [01:00:07.620 --> 01:00:10.400] Okay, the Easy Entry Profile Milling Machine. [01:00:10.640 --> 01:00:12.820] This is really a slick box. [01:00:12.820 --> 01:00:15.320] This is a little 20 pound box. [01:00:15.600 --> 01:00:16.960] Runs on 24 volts. [01:00:17.540 --> 01:00:22.700] It'll replicate almost any key way in about five minutes. [01:00:23.020 --> 01:00:26.300] In Germany, it was developed because there are all the blanks. [01:00:26.580 --> 01:00:28.520] It's driven either in German or English. [01:00:28.820 --> 01:00:30.140] You stick the blank in. [01:00:30.340 --> 01:00:32.180] It samples the blank. [01:00:33.220 --> 01:00:35.580] It actually reads the blank. [01:00:36.360 --> 01:00:40.700] It measures it with a little probe that goes on both sides of the blank. [01:00:40.700 --> 01:00:43.320] And then, it actually mills it. [01:00:44.060 --> 01:00:46.940] And I think Barry's got one of those to show you. [01:00:48.740 --> 01:00:49.780] Well, I...