Showing posts with label locksmiths. Show all posts
Showing posts with label locksmiths. Show all posts

Thursday, July 03, 2014

Inmates compromise jail locks in Van Zandt County

English jail cell door, UT Tarlton Law Library collection
Dozens of inmates were removed from the Van Zandt County Jail after "inmates figured out a way to compromise the locking systems." KLTV reported (July 2) that "one of the inmates figured out how to compromise the locks and started teaching others his tricks." Added the Tyler Morning Telegraph (July 1):
Following an inspection of the facility, it was determined that although the locks were functioning as designed, an engineering flaw existed with the mechanisms enabling a simple process to defeat the security of the lock.

This issue effected confinement cells in high security sections of the facility as well as ingress and egress access to the building.

State and County Officials were immediately notified of the situation and the Sheriff’s Emergency Action Plan was put in action.
Because the separate, newer constructed Minimum Security Confinement Facility was not equipped with the same locking systems, of the currently incarcerated 161 inmates, 90 were required to be transported to the Henderson County Jail and 35 to the Kaufman County Jail and the remaining female inmates were transported to the Upshur County Jail for the safety and the security of the inmates and the jail staff.
One wonders how many other secure lockups this same vendor has sold these locks to?
Surely tiny Van Zandt County can't be their only client. See this essay for more background on how locks in detention facilities can be defeated by enterprising inmates.

Tuesday, July 09, 2013

Dallas saw spike in safecracking, dying down after recent arrests

Thanks to our friends at TDCAA for pointing out this interesting Dallas Morning News article ("Dallas police take aim at old crime that's hot again: safecracking," July 8) revealing that safe robberies at businesses are on the rise.
Safes aren’t so safe these days.

Bandits have been breaking into safes or stealing them outright from businesses all over North Texas. The problem is so pervasive that Dallas police recently created a safe burglary task force and have been working with other area agencies to battle the onslaught.

“I don’t think you could name a city that borders Dallas that hasn’t been hit,” said Deputy Chief David Pughes, who oversees the task force.

“It’s not necessarily a well-structured criminal enterprise,” he said. “It’s groups of individuals who have decided that this is their crime of choice. It’s very lucrative and obviously what’s driving it right now is that they’ve had a lot of success.”

A Dallas Morning News review found that Dallas police recorded more than 165 business safe burglaries through the first half of 2013. That review found that thieves have swiped more than $500,000 in cash and caused at least $390,000 in damage. ...
The safes range from easily removed cash boxes to bigger bolted-down ones. The thefts typically involve thieves crudely bludgeoning their way inside the safe or simply carting the safes away to be opened later. Authorities said this isn’t high-tech Mission Impossible work.

Thieves have hit car dealerships in Rockwall and Garland, and even an upscale Mexican restaurant in Carrollton, authorities said.

Break-ins often take place overnight. Thieves typically wear gloves and masks and force their way in using crowbars and sledgehammers. Often they are in and out with their loot within minutes.
Some of the episodes have been caught on video but with perpetrators wearing masks and gloves, that didn't help much. The activity died down after the feds nabbed a crew last summer, but this year, "In May, the numbers exploded with Dallas-area agencies recording an average of about 30 safe burglaries a week." Then they dropped off again in late June after several recent arrests of people associated with the guys the feds caught last year. That's not surprising: Safecracking is not a grassrootsy crime committed on impulse like shoplifting or fighting. It requires intention, specialized knowledge, preparation and execution. Few criminals have that sort of focus or discipline and those who do tend to make their money selling dope.

Grits has recently evinced a passing interest in locks and keys, arguing that locks' symbolic role is as or more important than the physical barrier they pose to thieves, which a determined person can typically overcome. Clearly that goes not just for the lock on the front door but the safe in the office.

Saturday, July 06, 2013

Hardly 'hackproof': Vehicles' remote keyless entry systems vulnerable

Grits earlier mentioned that I've been spending some time post-session, as a diversion from political topics, immersing myself in the history and functioning mechanical locks and keys. But of course, these days electronically controlled locks are replacing mechanical ones in many settings, perhaps most commonly with the advent of "remote keyless entry" (RKE) for automobiles. As it turns out, the keyless locks used in many modern vehicles are just as vulnerable as the pin-tumbler lock on your front door to somebody who understands how they work.

The auto industry has relied on "security through obscurity" in this arena, hoping ignorance and a lack of technical expertise among car thieves would prevent them from bypassing RKE locks. That worked for a while, but now auto thieves have discovered how to bypass many of those systems, often more quickly than they could have 30 years ago with a "slim jim" or a pick gun. NBC's Today Show reported on June 5:
You think when you lock your car and set the alarm, your car is pretty safe. But criminals have designed a new high-tech gadget giving them full access to your car. It's so easy, it's like the criminals have your actual door remote. Police are so baffled they want to see if you can help crack the case.

A Long Beach, Calif., surveillance video shows a thief approaching a locked SUV in a driveway. Police say he's carrying a small device in the palm of his hand. You can barely see it, but he aims it at the car and pops the locks electronically. He's in, with access to everything. No commotion at all.

Then his accomplice shows up and hits another car, using that same handheld device.

Long Beach Deputy Police Chief David Hendricks is mystified. "This is bad in the sense we're stumped," he told us. "We are stumped and we don't know what this technology is."

He said it's almost like the thieves are cloning your car remote, which is virtually impossible to do. Here's why: On most cars, when you hit the unlock button, it sends a code to the car. That code is encrypted and constantly changing — and should be hackproof.
Except RKE devices are decidedly NOT "hackproof," clearly.  See more background on how thieves may be spoofing them. These vulnerabilities were known long before this recent episode in California. For example, in 2011 USA Today reported that, "Those remote key fobs nearly all automakers offer -- turns out they're fairly easy to hack so the bad guys can unlock your car and high-tail it before you even finish your shopping, Swiss researchers discovered." For that matter, here's an informative item from 2008 titled, "Hacking car security system and remote keyless entry." So at least five years ago these vulnerabilities were well known. In 2009, a commenter at Car and Driver offered up this detailed explanation of one method to bypass such systems:
it's been already over 15 years since car thieves began to use not single but double code-grabbing. with keyless entry systems it works a little more complicated, but the general principle is like this:

1) a driver comes to his car. The key in his pocket sends a code to the car to open

2) while this is performed, car thieves wirelessly capture the sent code, and instead send a wrong one to the car, which the car rejects

3) in a few seconds, the key again sends a code to the car (the "next" floating code, generated by both key and the cars safety system)

4) which thieves again capture, but then immediately send to the car the FIRST code which was captured.

5) the car unlocks (by the first code), the owner drives in a car somewhere, being followed by car thieves who have the next correct code which the car's safety system will be awaiting next

6) when driver leaves the car, thieves simple come and open the car with this "2nd" code.
Clever. Apparently, the Long Beach police and Today Show reporters don't use Google or they'd have figured this out.

This method allows thieves to open doors and trunks but not necessarily start the car. However, last year it was widely reported in Europe that BMW key fobs could be easily reprogrammed using the vehicle's onboard diagnostic port and actually start the vehicle. See here for a video explaining the details of keyfob programming and footage of BMW thieves making use of the tactic.

These vulnerabilities will apply to a huge number of cars on the road for the foreseeable future. It's easy to purchase key fob blanks and clearly knowledge of their detailed functioning is filtering down to the criminal class.

While locking technology will improve over time, historically secrecy surrounding the locksmith's trade has caused technology in that field to innovate at a snail's pace. Whereas most other technological fields operate within a relative culture of openness - e.g., the tradition of scientific publication and the filing of patents - locksmithing is a rather insular profession where detailed technical knowledge is rarely shared outside a relative handful of licensed commercial vendors. Even their trade journal restricts who can subscribe. That makes it less likely that vulnerabilities will be identified by the industry or that security upgrades will be promptly created to patch them when they're exploited by others. The development of encoded keys was one of the most significant improvements in lock technology in the 20th century. But unfortunately, we're now in the second decade of the 21st century and technology that was cutting edge two decades ago is already becoming outdated.

Bottom line: There's no such thing as a "hackproof" lock, there are only locks that no one has hacked yet. And increasingly, there aren't that many of those.

Thursday, June 27, 2013

Locks and keys: Security and symbolism

So the Texas Legislature has finished the special session, accomplished nothing, and will do it all over again beginning July 1st. Grits can't begin to tell you how glad I am not to have a dog in any of the particular fights on the special session call. Better them than me.

Over the years, your correspondent has come to indulge the habit of finding some subject utterly unrelated to (or at least fundamentally different than) the topics covered on this blog to occupy my time and reading habits for at least a month or two following each legislative session: Helps clear the intellectual palate a bit and avoid burnout. This year, I decided to delve into an area that's directly related to many of the criminal-justice topics covered on this blog but which has nothing to do with the government, the courts, police, or prison policy. It's a subject that's fundamental to American and indeed human security but which few people outside of a tightly regulated profession ever think deeply about: locks and keys.

My interest began awhile back after we replaced the deadbolt on our front door. On a lark, I pulled out a screwdriver and began taking apart the old mechanism to see what was inside. Upon sliding out the cylinder where the key fits (perhaps a bit too abruptly), an array of springs and tiny pins flew everywhere, I picked them all up and tried to put them back into the slots, but not knowing the correct order, when I'd finished the key wouldn't work. I'd essentially re-keyed the lock, I later understood, and a locksmith in theory could have created a key for the new configuration. Though I threw the old lock away, the episode stuck with me and when the legislative session ended I dove headlong into the topic, seeking to learn more. Locks and keys, I realized, are all around us and arguably more essential to day-to-day security than police or jails. But for most people, they remain great mysteries.

Image via Design Junky
The deadbolt I took apart, like most mechanical locks in America, was a "pin tumbler" lock - a design which dates to antiquity and was popularized in modern times by Linus Yale and the Yale lock company. A pin tumbler lock may consist of 5-7 columns rising from the key slot, each with two small "pins" of different heights and a spring above them pushing the pins downward. (See the illustration at left of a cutaway lock.) When the key is inserted, the pins slide up until the top pins are all above the top of the cylinder, at which point you can turn the key. So the bumps on the key are precisely the right height to raise each pin to the necessary level, which is why the key wouldn't work when I put the pins back in the wrong order.

In his treatise, "Ancient Locks: the Evolutionary Development of the Lock and Key," Scott J. Klemm argues persuasively that the first pin tumbler locks date to ancient Greek and Roman times, not the Egyptians as is sometimes claimed in generalist literature on the subject. (Egyptians did develop the first locks with keys, says Klemm, but they were not pin tumbler locks.) Some of the best examples of ancient pin tumbler locks come from Pompeii, preserved under a mountain of volcanic ash. More than one hundred of these were photographed comprehensively by Italian locksmith Adalberto Biasiotti, Klemm wrote, but their examination revealed a fascinating discrepancy. All of Biasiotti's images show locks with multiple holes/columns, but "In each case the bolt has only a single pin of metal." Klemm wrote that "It would be strange indeed that all the pins deteriorated and only one pin in each lock survived. I think it's much more logical to conclude that in each of these cases only one pin was used." Another ancient lock from Palermo, he noted, included just two pins, but five holes where pins could potentially go.

Klemm suggested that, "Perhaps the most important reason" for using just one or two pins "was the structural weakness that would have resulted. Especially in smaller locks, five holes bored closely together would create very thin walls." But that seems unconvincing because the Roman locks described had extra holes drilled into them, they just weren't routinely utilized. Others have theorized that the rest of the pins may have been wooden and disintegrated thanks to time or fire, but Klemm correctly noted that "wooden pins would be no thicker than matchsticks and could be easily forced to their breaking point." To me, that hypothesis makes no sense, either.

Grits has a different theory as to why ancient locksmiths would only use one or two pins in early pin tumbler locks and it relates fundamentally to the nature of locks and our relationship to them. Locks are a mystery to most of us. We don't know how they work. One inserts a key, turns it, and the lock opens; turn it the other way, the lock engages. Most people today don't know any more about locks than that and it's a safe bet that purchasers of locks in ancient Roman times didn't either.

Back then, before the onset of mass production, each pin in a lock would have to be manufactured individually by hand, which must have been painstaking work. So using one pin instead of five would reduce the amount of labor spent making pins and springs by 80%. And as for the customer, who would know? If, once the lock were installed, it opened when a key was inserted and could not be opened without one (even if it's just one pin keeping the cylinder from turning), it would be all the same to them. And if some rare customer chose to take apart the lock, discover the missing pins, and knew enough about what they were looking at to complain, it would be simple enough to claim it was an error, pull a fully functional lock from behind the counter and appear to diligently correct the "mistake." It's not like there were consumer fraud protections on the books back then nor the sort of licensing strictures placed on locksmiths today. Anyway, odds are nobody ever noticed nor complained.

If Grits is right about why locks from Pompeii had just one pin, it speaks to the nature of locks and our relationship to them. For most of us, locks are a mystery. We know (or perhaps, assume) that they function but most of us have no clue how. Their outer housing conceals their inner workings and that opacity is part of their power. If one understands the inner workings, it's not that much more difficult to pick a lock with five pins instead of one. (Indeed, there's an entire "locksport" movement where amateurs pick locks competitively - go here and scroll down to see pictures from a locksport club at UT-Austin.)  But since most people don't have a clue how the lock functions at all, a single pin was sufficient in the vast majority of instances to provide security.

19th century Yale time lock inner workings (Source).
Even the most complex safe and vault locks ever produced can eventually be opened by someone who knows what they're doing. A wonderful book titled, "American Genius: Nineteenth century bank locks and time locks" demonstrated an almost unbelievable level of complexity and craftsmanship in 19th century safe and vault locks. But the authors conceded that "a conscientious thief could eventually open even state of the art locks" (p. 40) and that "no vault is wholly impervious to theft" (p. 22).

While some texts, like "Lock and Key: The secrets of locking things up, in, and out," speak of "the war between locksmiths and lockpicks," IMO that's not a completely accurate characterization because the act of lockpicking is not necessarily nefarious. An important job of a locksmith is to be able to open a lock when the key or combination has been lost. For example, when a homeowner loses their keys and is locked out of their house, a locksmith can get them in without breaking down the door. When granddad dies and it turns out he was the only one who knew the combination to the safe, somebody must be able to get inside. The same skillset is necessary for cops, repo services, realtors, and others (though often such occasional users will use a pick gun instead of learning to pick locks themselves). Indeed, with the advent of "locksport," lock picking is now a competitive hobby. As long as locks exist there will at times be a need - and for some, also a latent, compelling desire - to open them without key or combination. Not everyone who does so has criminal intent.

Grits' recent study of locks - particularly the most common, pin-tumbler type - has caused me to consider the possibility that their main function may frequently be more symbolic than a meaningful barrier to unwanted entry. The stronger and more elaborate the lock - like some of the astonishing bank vault locks that look like works of art forever hidden behind heavy metal doors - the more powerful the symbol. A locked door sends a message, "You are not supposed to go in here." As it turns out, many common locks can be picked or bypassed with relative ease. But even for those of us without such skills, a door could just as easily be kicked in, a side window may be broken: A determined person who wants in can generally get in. In practice, a lock at best slows them down, hopefully delaying a would-be intruder until other security measures kick in. But perhaps just as or more importantly, a lock functions as a symbol that says, "You don't belong in here." "Keep out." "The belongings inside are not yours." Amazingly, that alone is enough to stop most people, just like the one-pin locks in Pompeii were almost certainly adequate to ward off most intruders.

Locks function to a remarkable degree on that symbolic level, as a tangible token of the social contract. As a practical matter, there are many ways around them. Locks must sometimes be opened and their contents thus exposed in the normal course of human activity, giving ample opportunity in many cases to simply act while the lock is not engaged. Locks may be bypassed instead of picked, like a bike lock overcome by cutting the chain with bolt cutters. And of course, the most elaborate lock ever imagined may be easily opened by placing a gun to the head of the person with the key or combination.

Some years ago I heard a comedian - wish I could recall now who - suggest a novel solution to border security, recommending tongue-in-cheek that the government line the border with those plastic dividers you use on the grocery store conveyor belt to separate your food from the person in front of you. Those dividers, he pointed out, are universally respected. You never see anyone violate them. I'm coming more and more to think of locks and keys like the divider on the grocery-store conveyor belt. Even to the extent their function is symbolic, posing minimal barriers to a determined thief, it doesn't really matter. For the most part they're tremendously effective, probably preventing far more crime overall than does threat of punishment under the penal code.

Friday, November 30, 2012

Millions of hotel rooms can be unlocked with $50 hack

An alleged Houston thief apparently used an inexpensive electronic hack revealed at the Blackhat conference this summer to defeat room locks and steal from the guests at three hotels, reported the Houston Chronicle on Wednesday.

The company, Onity, has sold their locks to hotels worldwide, which are estimated to be used on 4 million hotel rooms globally. Since the hack was revealed, others have perfected the technique and even created James-Bond like concealable devices to perform the task.

The Chronicle reported that, "In a statement, Onity said ... [their] engineers developed mechanical and technical solutions - tested and validated by two independent security firms - to address the issue." But the hacker who discovered and publicized the security flaws says the company's response won't prevent his hack: "I cannot imagine a fix for both of these issues which does not consist of replacing not only the lock circuit boards, but that of the portable programmer and the encoder."

The company responded to the revelations by blaming the hacker as irresponsible, but Darlene Storm at Computer World rightly argues that "in the four months since the flawed keycard lock vulnerability went public, Onity still hasn’t stepped up to fully pay for the required new circuit board and installation. Onity did supply plugs for the DC ports and suggested changing the screws, but left their hotel customers to foot the bill for a more secure fix. This likely means it won't be fixed in all hotels. Therefore, it seems there should be no excuse to blame the hackers instead of the company."

While on the subject of hotel-room security, even the manual metal lock guests can use to secure the door from the inside can be easily defeated though low-tech methods. Be forewarned.

RELATED: Even more disturbing than shoddy hotel security, while Grits was looking into the issue of hacking hotel locks, I ran across this startling story about insecure locks on most major models of gun safes, some of which can be easily defeated by a three year old. Seriously. Read the article, watch the embedded videos, and then, if you're a gun owner, immediately go check your own gun safe to see if it's similarly vulnerable.