MIT Researchers: Printable Keys Make Mechanical Locks Insecure
dailytech.com
dailytech.com
Mechanical locks are far from dead, but I'd love if someone reading this took it as a challenge to reproduce keys with movable components. I'm a big proponent of pushing these systems and finding ways to circumvent them, using any technology available. I just don't like it when the response is to throw the baby out with the bathwater.
[0] http://www.dom-sicherheitstechnik.com/DOM-ix-Saturn.667.0.ht... [1] http://www.mul-t-lockusa.com/614.html [2] http://www.vachette.fr/fr/site/Vachette/Systemes-de-Securite... [3]http://www.lockpicking101.com/viewtopic.php?f=9&t=56691
(edited to add links)
This comment captures the security problem well.
> "[Locks] are more of a tamper-evident seal, or a delay tactic. The issue with bumping, picking, carding, and 3d-printing is how it invalidates the current approaches towards those two aspects."
However, of those options, 3D-printing is clearly the worst. Bump keys and carding latches takes seconds, picks minutes, and 3D printers hours. It seems that the only situation this method would be useful is with advance access to a key, a radial-pin lock, and a free 3D printer.
I'm about to go on a whole thing here, so let me first say that I am excited about their work and I have personally been pushing for years to see more high security key printing happening (see Nirav Patel's Abus Plus key printing[0])
What I take umbrage with is the idea that this development is going to be the death of mechanical locks. Even the suggestion that it _should_ be the death of mechanical locks. In the Forbes article [1] One of the students behind this work suggested that his goal was the elimination of mechanical locks:
"If we show that mechanical locks are vulnerable to key duplication just by having a handful of numbers you can download off the internet, hopefully they'll be phased out more quickly," says Van Albert.
What this fails to address is that the cuts on your key are supposed to be a secret, and your behavior toward your keys should be the same as your behavior toward a password. You don't pass it around and you are very careful about who you trust it with.
I also dislike the characterization of the discovery of the "numbers" in the main and sidebar bittings. That information has been publicly available and the suggestion that they "reverse-engineered" (from their abstract submitted to defcon)[2] the lock is a bit dramatic. Better, I think, to say that they "read the documentation."
Obviously I have a chip on my shoulder when it comes to mechanical security, but I am confident saying that any call for the blanket abolition of mechanical locks is short-sighted and narrow-minded. This could have been an amazing opportunity to address human behavior as it relates to mechanical security, but instead it was wasted on the age-old call for the death of locks. There remain myriad places where a traditional lock is still required, there are myriad populations who are not able to sustain electronic locks.
If the day does come when mechanical locks can be left to the dust of history, it will be more likely the result of dramatic shifts in society than in technology. It will be the death of all locks, not just mechanical ones.
[0] https://github.com/nrpatel/PhysicalKeygen/blob/master/abus_p... [1] http://www.forbes.com/sites/andygreenberg/2013/08/03/mit-stu... [2] https://www.defcon.org/html/defcon-21/dc-21-speakers.html#La...
I don't think the average mechanical key user is aware of this fact.
I wonder if someone makes keys that hide their cuts during normal use. For example, a cylindrical key with the cuts on the inside of the cylinder.
And yes, they do. There have been a handful of concepts to do exactly that. Check out the Van Lock[0] for one, which is almost exactly what you are describing.
What?? This ties in with the recent reports on insecure electronic keyfobs for cars. In Germany it used to be that your key number used to be printed on your car title, and your friendly car dealer would gladly cut you a replacement key if you had lost yours, but he wouldn't do it unless you procured ID and the title.
However, when the threat model is one where a more funded organization is attempting to break in, then you need a better system.
Sadly I have no patent reference for the lock, only a description in an old newspaper that ran a story on the creator.
1) A difference in scope means a difference in kind. Using a service such as KeysDuplicated (formerly Shoosl[1]) from your mobile phone enables opportunities. These opportunities break previous assumptions in the security threat model but can also lead to new business opportunities (see for instance Prim[2] - a laundry service that will come into your home if you send them a photo of your key; they will then find and do your laundry.)
2) The huge missing element here, which has been a necessity in computer security for years, is monitoring. For many, many people, replacing the lock or installing an alarm may not be an option. My company makes a device that fits over your lock and alerts you when someone uses a key (or bumps your door, or comes in without your permission, etc)[3]. It also allows you to grant virtual keys to actuate the lock - enabling use cases like Prim without having to fabricate a physical, non-revocable access token.
[1] http://keysduplicated.com/ [2] https://getprim.com/ [3] https://lockitron.com/
I am of course aware of Lockitron & the competitors in the market, but really appreciate your integration with pre-existing hardware and the point about users who cannot change their hardware out is a great one.
Re: threat model vs. business opportunities, I've been following shoosl and the like closely and despite my background, I absolutely love the idea. Again, you have to choose who you trust with your key, and if a service can engender sufficient trust, you can reap the benefits of those services. Glad you chimed in on this, sorry I missed your talk in Vegas.
I was in the Wireless Village (their speaker schedule was submitted a bit too late to make the program.) The second half of my talk was on the radio/encryption side of things along with various attacks when handling electronic keys. DaKahuna (the facilitator) should be posting slides soon.
Well, if we are treating it as passwords, then we need to give every individual with access to the building their own key, with a different secret.
I mean, we all know that shared 'role' accounts are a bad thing, right? you don't share passwords.
Now, taking the password situation further, many places have a mechanical "root access" lock, with an electronic lock for all the 'users' - which makes a lot of sense to me. (further, much like non-sudo root on a server, it'd make sense that actual use of this 'root level access' should generate a long or alert somewhere, as even the admins should normally use their account and sudo as needed.)
Logging in the physical security space is both important and incredibly overlooked.
[0]http://www.schneier.com/blog/archives/2005/03/flaw_in_winkha...
I'm mostly familiar with electronic locks and cameras in the data center context, and in that context, yes, there is a completely analog key that often opens everything[1], but then there are electronically fired locks, and, of course, a camera. There is camera software that will time sync with the electronic lock and show you what user had authenticated while showing you a video of the user entering the building. I don't know of any systems that correlate cameras with key use, but the motion-sensing thing should do at least part of that.
(There is also usually security sitting up front, but especially in the early AM when it's just us grunts? those folks are often not paying a whole heck of a lot of attention.)
[1]well, on the fail secure systems, anyhow. the mag-locks that are 'fail safe' - that open on power failure usually don't have an obvious manual key override.
With hardware, changing a "role" requires swapping logic inside of every lock that for the user's key: the lack of an abstraction layer makes it impossible. So, in the mechanical world, key-per-group is equally expensive to key-per-user in terms of replacement costs, but far harder to implement.
More of a concern is bump keys and the fact that Lockwood dominate the industry when they can be opened with 2 paperclips (although you do have to flatten them with a hammer). You can also get lockpicks and pickguns off the internet for under $20 delivered to your house.
edit: http://www.jacobsschool.ucsd.edu/news/news_releases/release.... for an example
I found two issues when researching its feasibility: printing accuracy and temperature range of the plastic. My results were that the lower-cost 3D printers didn't have the required precision, and more importantly, the printed plastic would simply melt if it sat in a hot car during the summer.
My research is probably out of date now, so I wonder what kind of plastic is being used these days.
It requires some knowledge of the tolerances of the specific printer and lock. For example, the disc detainer model has wider cutouts than the discs require to account for blobbing corners on the print.
Using something like a Formlabs 1 printer, that probably is no longer necessary.
TBH, there is no reason that the city should be using such archaic key types. In Brazil, they typically used a four sided key like a philips head screwdriver that would need to be photographed from at least two sides to be able to reproduce.
A device which can do such detection could be far less expensive than a device to both detect and actuate the pins.
I'm wondering how you can replicate a poorly taken smartphone camera image into a key that would unlock a high security lock. If you can't see the grooves clearly on the key from the photo, how does the software or printer know where the grooves should go? I feel like this is quite a stretch to think you can take a photo of a lock several feet away and get an exact duplicate from a 3D printer.
Schlage Master Security (SMS) "Turn the key, type the text"
The audit and management features of an electronic access control system already make mechanical keys inexcusable on any door that >1 person needs to open. Hopefully revelations like this will push more organizations to upgrade.
Either way, the owner almost always has a key that can mechanically override the electronics and open the door, but this is kept in a safe, rarely used, and will set off the "door forced" alarm.
Without getting into the discussion of the security factor of biometrics, the working mechanism of the lock itself is such that when it detects a success, a small servo engages some sort of a gear which enables you to complete the mechanical circuit (so to say) when you push the door lever down and move the physical lock with human effort.
This means that the battery is never constantly used, only when the actual sensor is active. Even if it were dead, there exists a manual key override. Also, (I've tested this personally), the factor of safety is quite good in that, the lock starts beeping "LOW BAT" a good 3-4 weeks before the battery is completely drained. Also, (Another one) it doesn't leak information about low battery until there's a successful entry, so an evil attacker can sit near your house activating the sensor all day and he won't know his progress in draining the locks' battery.
Edit: it seems electronic locks that come on top of the existing lock tend to have the battery pack inside, while electronic only locks can have it outside. BTW the batteries are supposed to last two years in the product description (that's in line with what I had too) I was mentionning these kind of locks:
[0]http://www.kabamultihousing.com/Products-Solutions/Multihous...
[0] http://www.kaba.com/access-control/en/Products-Solutions/Mec...
Better, but still vulnerable.
Do you know how in the 80's and 90's everything that everyone was already doing was 'changing' because of computers.
it's the same now with 3D printers. Forever you could duplicate a key in a machine with just a picture of the original. just because the machine to duplicate it become easier it's not going to change the world. dammit you could already do the same with a blank and a hand file, it would just take 40~200min depending on skill instead of 5~15min on the machine.