Lock Picking 101 Forum
A community dedicated to the fun and ethical hobby of lock picking.
       

Lock Picking 101 Home
Login
Profile
Members
Forum Rules
Frequent Forum Questions
SEARCH
View New Posts
View Active Topics


Live Chat on Discord
LP101 Forum Chat
Keypicking Forum Chat
Reddit r/lockpicking Chat



Learn How to Pick Locks
FAQs & General Questions
Got Beginner Questions?
Pick-Fu [Intermediate Level]


Ask a Locksmith
This Old Lock
This Old Safe
What Lock Should I Buy?



Hardware
Locks
Lock Patents
Lock Picks
Lock Bumping
Lock Impressioning
Lock Pick Guns, Snappers
European Locks & Picks
The Machine Shop
The Open Source Lock
Handcuffs


Member Spotlight
Member Introductions
Member Lock Collections
Member Social Media


Off Topic
General Chatter
Other Puzzles


Locksmith Business Info
Training & Licensing
Running a Business
Keyways & Key Blanks
Key Machines
Master Keyed Systems
Closers and Crash Bars
Life Safety Compliance
Electronic Locks & Access
Locksmith Supplies
Locksmith Lounge


Buy Sell Trade
Buy - Sell - Trade
It came from Ebay!


Advanced Topics
Membership Information
Special Access Required:
High Security Locks
Vending Locks
Advanced Lock Pick Tools
Bypass Techniques
Safes & Safe Locks
Automotive Entry & Tools
Advanced Buy/Sell/Trade


Locksport Groups
Locksport Local
Chapter President's Office
Locksport Board Room
 

High Security

Information about locks themselves. Questions, tips and lock diagram information should be posted here.

Re: High Security

Postby hydruh » 22 May 2009 10:27

Olson Burry wrote:O_o I didn't think of that but no, you only need 25 posts and 60 days membership for selling your stuff.

Could be referring to the fact that 40 used to be the limit for applying to the adv section but it's higher now.


Yes, that's that I meant. didn't know it was higher.

S
hydruh
Supporter
Supporter
 
Posts: 405
Joined: 29 Feb 2008 13:33
Location: Ohio

Re: Re:

Postby vap0r » 23 May 2009 15:44

FrenchKey wrote:
vap0r wrote:
Anyone who thinks UL 437 is 'high security' doesn't know much about security. For example, many of the locks that are UL 437 certified can be easily bumped open.


Lot of High Security locks can be compromised easily, by bumping or by other simple techniques including by-pass for example. They still are High Security locks.
So saying that UL437 is High Security seems coherent (Actually, I don't know UL437, it doesn't exist in France), but High Security means that the lock is protected against some attacks, not that it is effectively immune.

Otherwise, we could not have the pleasure to open High Security locks if the are considrered low-security since we can open them without the key :P

Just my two cents :D



That doesn't make a lock high security. UL 437 is NOT a high security lock rating. It is a medium security rating at best. You could call it 'higher' security, but that is like saying your lock is 'virtually bump-proof' and 'virtually pick-proof', neither of which are true.

If you want high security locks you need to look at the Builders Hardware Manufactuers Assn. guidelines or something like that.

UL 437 certified locks are only tested against basic hand tools like screw driver, 18" crow bar, etc. They do not test them with special drill bits, 4 foot crow bars, or any serious tools. They only use basic hand tools for the testing. If that is what you call a 'high security lock', you are very misled. As I said before, you don't seam to know much about high security locks, or standards, so go do some reading.

Buy a copy of LSS or another that details the specifications. There are also many youtube/google videos from toool, marc tobias, and others that talk in depth about high security locks and why UL 437 isn't a high security standard in addition to what I've just mentioned.
vap0r
 
Posts: 51
Joined: 9 Nov 2003 5:43

Re: High Security

Postby hydruh » 23 May 2009 17:17

Vap0r, nice to have you back. You talk a lot of sense!

Also, don't forget greyman's book:

http://www.amazon.com/High-Security-Mec ... 023&sr=8-1

S
hydruh
Supporter
Supporter
 
Posts: 405
Joined: 29 Feb 2008 13:33
Location: Ohio

Re: High Security

Postby vap0r » 23 May 2009 22:14

hydruh wrote:Vap0r, nice to have you back. You talk a lot of sense!

Also, don't forget greyman's book:

http://www.amazon.com/High-Security-Mec ... 023&sr=8-1

S


It's nice to hear my words are appreciated. Some people (like Unlisted) seam to think my words are not 'family safe'. lol.

Here is a link to the defcon 15 video with marc tobias (LSS author) on high security locks.

http://video.google.com/videoplay?docid ... 2092668669
vap0r
 
Posts: 51
Joined: 9 Nov 2003 5:43

Re: High Security

Postby zeke79 » 22 Aug 2009 11:47

Unfortunately UL437 is the only "security" standard used in the US. I agree that it is not the best as like you said most locks in this category can be bumped open or bypassed in some way. It is however still somewhat useful to helping someone find a high security lock better than they could without any standard whatsoever. If the standard did not exist, end users could end up choosing a lock that has no security features at all and this choice could be made by simply reading advertising that is misleading. I think that having UL437 atleast gives the user a better chance of getting the security features they need than they would if we had no standard at all and end users were forced to weed through all of the misleading advertising out there.

Is the standard flawed? Yes it is severely flawed. Do we need a new standard that better outlines attacks that are tested? Of course we do. For now however, UL437 is all we have and it is better than nothing as it does improve the chances that an end user will end up with a product that offers some high security features. I do however agree totally that it is a seriously flawed standard that needs to be brought up to date and some of the locks UL437 listed should not be considered high security. UL437 should not be the end all security standard in the US.
For the best book out there on high security locks and their operation, take a look at amazon.com for High-Security Mechanical Locks An Encyclopedic Reference. Written by our very own site member Greyman! A true 5 Star read!!
zeke79
Admin Emeritus
 
Posts: 5701
Joined: 1 Sep 2003 14:11
Location: USA

Re: High Security

Postby JK_the_CJer » 22 Aug 2009 12:20

vap0r:

Most of the folks here are well aware of the flaws in UL437 as a standard for high-security locks. The problem with any industry standard is that the testers do not think like hackers. The devices/procedures are tested according to vary specific sets of procedures.

Imagine a standard that certified locks in a free-for-all manner; in other words: if you can break it faster than 10 minutes, it is decertified. This hypothetical standard would take research efforts like Marc's and use them the decertify cylinders. This sounds fine and dandy, but think further. What is the potential for abuse by competing companies? Also, what about the varying amounts of attention being paid to various locks? Who decides what research is valid and what is not? Have a look at who is on the board of directors for UL and BHMA (ANSII 156.30) that sets the standards. The potential for abuse in a certification system that is not based around a very specific set of guidelines (which hackers/researchers break by definition) is extremely high.

I have to go now, but plan to write more later.

Original Poster:

There are two locks that I am aware of that this community has not opened covertly/surreptitiously: Abloy Protec and Evva MCS. In light of recent research, the most manipulation-resistant keyed mechanical cylinder in production is the MCS.
Image
JK_the_CJer
Supporter
Supporter
 
Posts: 725
Joined: 19 Jul 2006 20:56
Location: San Diego, CA

Re: High Security

Postby mh » 22 Aug 2009 13:36

JK_the_CJer wrote:There are two locks that I am aware of that this community has not opened covertly/surreptitiously: Abloy Protec and Evva MCS.


While I believe the above statement concerning the MCS is still correct, recent research suggest that this will not hold for very long any more. Also, key control is somewhat weak as appropriate magnets can be easily procured these days.
See our presentation at HAR2009.

Cheers
mh
"The techs discovered that German locks were particularly difficult" - Robert Wallace, H. Keith Melton w. Henry R. Schlesinger, Spycraft: The secret history of the CIA's spytechs from communism to Al-Qaeda (New York: Dutton, 2008), p. 210
Image
mh
Moderator
 
Posts: 2437
Joined: 3 Mar 2006 4:32
Location: Germany

Re: High Security

Postby JK_the_CJer » 22 Aug 2009 14:42

mh wrote:
While I believe the above statement concerning the MCS is still correct, recent research suggest that this will not hold for very long any more. Also, key control is somewhat weak as appropriate magnets can be easily procured these days.
See our presentation at HAR2009.

Cheers
mh


Perhaps, Mul-T-Lock MT5 should be added to that list. I think the precedent for MTL being opened makes it a weak contender for "best lock evar!" but only time will tell. As for how easy those magnets are to procure, I called around asking a bunch of companies about them for a while (without an MCS) so I could work on some decoder ideas. Minimum orders for magnets of that size that are magnetized "through the axis" are quite high and I found no one that sold them non-custom (in SmCo anyway). I'll start looking for the HAR presentation; sounds interesting.
Image
JK_the_CJer
Supporter
Supporter
 
Posts: 725
Joined: 19 Jul 2006 20:56
Location: San Diego, CA

Re: High Security

Postby Schuyler » 22 Aug 2009 14:48

Have we seen a Diamant picked? Or a Fichet 3D? I mean, the price of the latter is defense enough against even getting your hands on one to test it out, but still :P

I've been bombing around LP101 & the internet at large and haven't seen the Diamant compromised. Anyone correct me on that?
Schuyler
Supporter
Supporter
 
Posts: 3448
Joined: 24 Jul 2006 1:42
Location: Boston

Re: High Security

Postby mh » 22 Aug 2009 14:57

DOM Diamant: yes, a tool has been made.

MCS magnets: Well, we had to order 1,000s of them, but the cost was within acceptable range.
"The techs discovered that German locks were particularly difficult" - Robert Wallace, H. Keith Melton w. Henry R. Schlesinger, Spycraft: The secret history of the CIA's spytechs from communism to Al-Qaeda (New York: Dutton, 2008), p. 210
Image
mh
Moderator
 
Posts: 2437
Joined: 3 Mar 2006 4:32
Location: Germany

Re: High Security

Postby Schuyler » 22 Aug 2009 15:01

mh wrote:DOM Diamant: yes, a tool has been made.


PM or email me details or a link? I love the lock, would love to see how it was attacked.
Schuyler
Supporter
Supporter
 
Posts: 3448
Joined: 24 Jul 2006 1:42
Location: Boston

Re: High Security

Postby mh » 22 Aug 2009 15:10

Schuyler wrote:
mh wrote:DOM Diamant: yes, a tool has been made.


PM or email me details or a link? I love the lock, would love to see how it was attacked.


I can't exactly remember if there were more than one of them; one has been made by John Falle, see the lawyer's book, and one used a contact microphone to pick up sound from the lock; they might be the same.
Obviously, the concept is the same as with ABUS Plus locks / Jaakko's tool.

Cheers
mh
"The techs discovered that German locks were particularly difficult" - Robert Wallace, H. Keith Melton w. Henry R. Schlesinger, Spycraft: The secret history of the CIA's spytechs from communism to Al-Qaeda (New York: Dutton, 2008), p. 210
Image
mh
Moderator
 
Posts: 2437
Joined: 3 Mar 2006 4:32
Location: Germany

Re: High Security

Postby Schuyler » 22 Aug 2009 23:31

mh wrote:I can't exactly remember if there were more than one of them; one has been made by John Falle, see the lawyer's book, and one used a contact microphone to pick up sound from the lock; they might be the same.
Obviously, the concept is the same as with ABUS Plus locks / Jaakko's tool.

Cheers
mh


Very good, thanks, mh.
Schuyler
Supporter
Supporter
 
Posts: 3448
Joined: 24 Jul 2006 1:42
Location: Boston

Re: High Security

Postby raimundo » 23 Aug 2009 9:25

This topic interests many people currently active, and even brought in Vapor, who joined in O3,
I just don't understand why unlisted asks "please stop necroposting". the way to stop this is to simply delete all posts that are from O3 since they are not valued.

should people start a new O9 topic on subjects that are covered in posts started years ago?

when was the never going anywhere story started, isnt that a necrothread?

If something is necro, it should be burned or buried. I suppose. That way all topics are available for new O9 threads and the necroposting resistance can be satisfied.
Wake up and smell the Kafka!!!
raimundo
 
Posts: 7130
Joined: 21 Apr 2004 9:02
Location: Minnneapolis

Re: High Security

Postby NKT » 23 Aug 2009 13:02

Don't worry about re-starting an old thread!

I asked the question at the HAR presentation regarding the cost of the MCS key duplication, and the guys told me that it was around €300 all in, to which I replied "So you broke the key security for less than the price of the lock and a few keys."

And that is true.

I still want a kit with a few of the magnets in it.
Loading pithy, witty comment in 3... 2... 1...
NKT
 
Posts: 1273
Joined: 13 Feb 2005 16:35
Location: West Mercia, England

PreviousNext

Return to Locks

Who is online

Users browsing this forum: No registered users and 5 guests