Then we moved on to attacking the firmware in each others keyboards.
I am pretty decent at lockpicking but I can't pick a Medeco or better in any practical amount of time and very few in the world can.
Little bit more money vastly reduces your attack surface.
Aren't medeco padlocks like $100, whereas master lock padlocks are less than $20?
I then taught kids to pick them.
If the case was locked in a cage I wouldn’t notice until I needed to put access the tower to plug in a usb, which might not be for weeks these days.
but check out this one instead: https://youtu.be/sES_Hbj92BQ - ~2h to open fully (though the author of the video claims impressioning could speed up the thing; anyway, reportedly attacking the door is just easier in this case)
Not only does it take a couple hours to pick for an expert but you have to make a custom set of tools that only work on that one particular lock.
If a lock keeps someone out for several hours it is a great lock.
Also worth noting, Bosnian Bill (a more recognized name) also attempted this lock here https://www.youtube.com/watch?v=tLeiPmfm-2s
LPL covers most locks in the wild which are bad, but locks like the Protec2 are quite strong and while it is implied one person in the world can beat it with custom tools (huxleypig)... even then not quickly.
I frequently use FF-L-2740 spec locks, which is the spec locks need to hit for use in classified government work, military contractors etc. They are very good locks I can't begin to defeat in any practical amount of time and don't know anyone who can. Particularly since they have timed brute force lockouts.
Problem is not a single vendor is allowed to sell locks of that spec to civilians by contract so you have to jump through lots of hoops to get them.
I have had doors kicked in, so these days I want the lock to be the weakest, not strongest, part of the door. So when it is kicked in it is a cheap lock that is destroyed not an expensive hardwood door (I like hardwood doors...)
If a door is broken then a lock did its job. It let you know you were broken into.
Who is going to pick a lock that is cheap and easy to break?
Mēh. I have dogs.
Probably a criminal who is trying to be quiet, so they can enter your house.
For your home, a high security pin tumbler with security pins are fine too. It takes very high skill to defeat these.
You can say that again.
I was once proud of myself for having thoroughly researched the market and I thought EVVA MCS was a safe bet[1].
Then someone showed me a YouTube video (published a year after I bought the locks) of someone picking it (not LPL, another YouTuber). Given the cost of EVVA MCS I was not a happy bunny.
[1] https://www.evva.com/int-en/products/mechanical-locking-syst...
You can buy locks that don’t have easy bypasses, and can’t be easily drilled, and can’t be picked by beginners.
To keep people like me out for a while buy a Medeco. Pins not only need to be at the right height, but also the right rotation. They are a real pain in the ass to pick. I don't even know any locksmiths that can pick them. Good security for the money.
Bosnian Bill and LPL... Okay they can pick them, but they are like the 0.0001% in skill.
Still even then pay an extra $100 for really high quality disk detainer lock like a Protec 2 and you will keep even them out for quite a while.
That is what I use on my luggage. TSA has to call me to unlock them with my consent every time. The way I like it. Great tip I picked up from Deviant Ollam.
No - no they don’t.
Anything locked with a non-TSA compliant lock is fair game for the bolt cutters, and frankly probably draws a lot of extra attention.
All you’re doing is asking for extra screening…
[1] https://www.tsa.gov/blog/2014/02/18/tsa-travel-tips-tuesday-...
I've been wondering the most sophisticated/effective/secure locks regular consumers have access to.
In other words, which locks does the Lock Picking Lawyer himself use in his house to protect his family?
The Lock Picking Lawyer chronicled very nicely a technique for turning a KW1-keyed Kwikset core (extremely common here in the US) into something that is tamper evident. See the YouTube video linked herein.
https://www.youtube.com/watch?v=7JlgKCUqzA0
This kind of thing thwarts covert attack attempts and serves as a good way to trigger an audit on the trust of the asset behind that lock.
If you don't fear your front door will be clandestinely accessed, I feel it's perfectly valid not to worry about doing this to the lock there.
Not being you, that isn't my call to make.
The term for what you want is a "seal", not a lock.
You'd be driven mad trying to find what the intrusion was on your system.
>Then we moved on to attacking the firmware in each others keyboards.
In what world is hacking keyboard firmware easier than lockpicking?
And there were two - one on each side. What's more, it was a tubular lock, so if you were single-pin picking you'd have to pick it 5 times per rotation.
Nothing that would stand up to a battery powered angle grinder, of course.
$40 for tools designed to pick all pins at once and make a "key" with some quick impressioning motions.
Some do have spool pins. In those cases you will need manual fiddling to pick it once then you have a key to keep spinning.
Still, sounds like an interesting design. Link?
I looked for a picture of the case but couldn't find one. I was in that college CAD lab... quite a long time ago.
I taught everyone else involved to lockpick in the first place and chose locks well beyond any of our skill levels to pick.
One such effort features locks made by Stuff Made Here sent to Lock Picking Lawyer. According to LPL the locks are theoretically sound and he did not attempt to pick them, but these particular implementations had a couple (easily fixable) bypasses. Made for interesting videos on both sides:
Stuff Made Here describes the design in detail: TWO Unpickable (?) Locks for Lock Picking Lawyer! - https://www.youtube.com/watch?v=2A2NY29iQdI
Lock Picking Lawyer reviews them and performs some bypasses: [1299] Unpickable Locks From Stuff Made Here - https://www.youtube.com/watch?v=Ecy1FBdCRbQ
What the school did was run a steel cable behind the desks, then put a loop of the mouse chord through a steel washer and ran the security cable through all the loops. If you secure both ends you can’t get the cables separated even with slack.
The trick is that the hole in the washer had to be smaller than the connector so you couldn’t fish it back through no matter how much slack you get. That could still work for USB-A, but these days the connectors are getting smaller than the diameter of curvature of the cable, so you’d break it trying to do this. And on many peripherals you could destroy the chord without reducing the value of the device. One could cut the cable and install this Trojan one on many devices these days, the only telltale would be that the cable isn’t routed properly, which might be harder to notice immediately.
You can get a female/male versions of this connector placed on either side of an attiny85 for a quick solderless implant no one will ever see.
Then just undo 2 screws, plug your implant inside the mouse/keyboard, screw it back.
To make this harder intentionally strip the screws with a drill, understanding you will never be able to repair that unit again.
Or, y'know, open it up and solder the connecter together (or remove the connector and solder the cable wires directly).
But they’re right, these days when you crack open things you often find a connector soldered to the motherboard and the cable is merely plugged in. I think it’s just easier to manufacture. Pick and place, bulk solder and then a machine to plug in the cable, fast as you like, maybe with a loop in it as a poor man’s strain protector.
Well, if you're stealing them, you only need parts from one mouse: cut the cable close to the mouse, untangle it from whatever crap it's locked to, take mouse and cable home with you, disassemble mouse, feed cable back though (I think it's called) grommet, strip cable, pick out wires, solder wires to approriate mouse internals, reassemble mouse, done. You have a working mouse with only slightly shorter cable than before.
The point of using soldered cables for security is that setting up a soldering iron near a computer is conspicuous, so you get caught if try to install a attiny85 inside the mouse that way. You can still steal stuff just fine.
That's evil...
(Or do you know some way to strip the thread itself).
Or just epoxy the whole thing together.
That said I did make transparent and easily auditable USB type C condoms for one client that really wanted to use USB type C laptops.
Systems with security as a strong priority like the Librem 14 use barrel jacks for good reason.
I am in fact implying those that allow use of macbooks at coffee shops to directly access production systems at FAANG and fintech companies are taking a very inappropriate risk :-P
A tampered USB C to C cable on a conference room table can compromise people all day long.
If the USB C charge ports cut the data pins entirely then great, but I have not seen that be the case on any laptops yet.