The App I Used to Break Into My Neighbor’s Home
wired.com
wired.com
If anyone in the world could anonymously try and open my doors and, if they succeeded, could steal my valuables, locks would have been found insecure a long time ago.
Yes, the author here doesn't know how to use lockpicks or a crowbar to break into a house. The author also has presumably never tried to steal something from a house. Houses are generally just secure enough that the casual passer-by can't easily get into them, but not secure enough that if you really wanted to you couldn't get in. Most people who pick locks will tell you that picking locks is not a particularly good way to break into a house to steal things because breaking into a house is easy when you don't mind destroying someone's property. If you're a criminal you don't need anything more sophisticated than a crowbar (and even then you might just walk around until you find a door that's not locked at all).
So sure, maybe this makes one particular attack marginally easier (not really all that much easier than it was before), but illicit key duplication is still not the weakest part of your physical security by a long shot, so I don't think there's anything to worry about.
I don't see why the other people would want to break into my house if they weren't interested in stealing my things or hurting me (and if they are just breaking in to like, hang out in my house, that's a bit weird but not really something to lose any sleep over). If they do that habitually, I think they'd find breaking into the house without using a credit card to buy a copy of my key is quicker and less risky than using KeyMe. I am not particularly worried about the extremely rare threat model of being my non-criminal friend or coworker's first break-in, where they decide opportunistically to break into my house because I left my keys somewhere and they know they can easily make a copy of them at a kiosk.
They could also just get a screwdriver and a rubber mallet and remove the lock, or smash a window.
They always have. It was always possible to take a blank key and just copy it with a file. You could use a softer material to expedite the process and then copy it again later...
Which is why, most cars come with a valet parking key that only turns the ignition, and doesn't open your trunk. You're not supposed to hand the valet your entire keyring. That's ludicrous (although a lot of people do this)
Though with the availability of this app we're going to see a lot more crime committed this way.
2) The value of contents of my trunk is rarely within two orders of magnitude of the value of my car.
Depends on the model. New cars usually have this, but e.g. older cars like Mazda 626 or VW Bus, up to the new T5 line, do not.
In some cars, it's configurable at order time if you want this feature.
The valet key cannot unlock the glove box, and there is a switch in the glove box to disable the drivers seat trunk switch.
But then again, I don't really like valeting my car anyways.
I don't really know that this app will perpetuate a lot more crime - 5 kiosks in NYC actually seems like less availability than your crooked buddy at the hardware store turning a blind eye to you bringing in a key or two every so often.
Plus, it seems to me that use of the app and kiosks is even more trackable than walking into a physical location.
Cloners can be bought from underground websites, the same sites that sell credit cards etc. Look around on Youtube, it's a bit scary how easy it is.
Definitely agree about trackability with the app.
A former prison officer said the design of the master key - which could open every lock in Berrimah jail in Darwin - was printed on the front of the prisoners' information handbook.
http://www.news.com.au/national/killer-escaped-prison-after-...
It's KeyMe, a service that lets people make copies of keys from a vending machine, using photographs of keys. He got the photos because his neighbor let him handle the keys.
No particular high-tech involved. (Even though he claims they're 3d-printed in the vending machine, i suspect they're simply cut from a raw.)
Otherwise an accurate and brief summary. The article is relatively short and worth the read, though.
if we are willing to call this a "break in" then the app is not the operative concept, it's the social engineering that enabled the guy to give you the fucking key.
might as well have written about the shoes you used to break in with.
- The app makes it in 30s,
- "Do Not Reproduce" keys can be reproduced,
- Lock nerds can reproduce keys from a 60-feet picture.
All 3 imply a change of the possibilities and thus, newsworthy.
it says he "spent about 30 seconds in the stairwell scanning his keys". the app doesn't "make" anything in 30 seconds.
> "Do Not Reproduce" keys can be reproduced
"do not reproduce" does not mean "can not reproduce".
> Lock nerds can reproduce keys from a 60-feet picture.
i read "One group of researchers ... could reproduce keys photographed from nearly 200 feet away and at an angle." this is without the app. which is more to my point.
moving on, if the person trusts you enough to give you a key, you don't need it.
Anything to do with locks is not really relevant to robbery, since virtually none of the houses in the world have good enough security to resist anyone even moderately determined and willing to break things. Why bother with some elaborate charade to copy keys when a crowbar, or usually a boot, will get you into any house?
What is actually relevant is information about the house and what's in it. First, information about whether there is anything stealable in there - stuff that's easy to transport out and can be sold in a grey market for a good price without being easy to track back to the thief. Most houses don't have a lot of stuff like this, and there's probably a pretty stiff haircut on the price you can get when moving stolen goods through fences. I'm guessing that you'd want trustworthy information that there's stuff you can take and move for at least $1,000 or so to make it worth your risk to break into a specific house.
You'd also want solid information about who can be expected to be at the house, and when. Any chance at a confrontation is going to add a lot of risk.
Threats like the valet copying your keys don't really make any sense. Yeah, he has the keys, and information that could lead to an address, like registration and license plate. But he doesn't know anything about what's in the house or who's there. Why should he care that, after going through a complex and risky process to get a copy of the keys and the address, he has slightly easier access to a house of unknown quality?
Worry instead about people who have access to that information. Repairmen, exterminators, maids, anybody who has a legitimate reason to go around your house. And be wary of letting untrusted people know when your house might be empty for an extended amount of time.
In contrast to "stupid" ordinary house locks, which are not powered, car keys these days incorporate RFID chips so that the key at least cannot be used to steal the car. Granted, you can still empty it, but at least better than losing the car altogether.
A locked door to a home is rarely a deterrent for a determined thief.
I mean, heck, the valet could just as easily steal the garagedoor codes from a garage door opener, right?
Jail keys changed after TV lapse
All the locks and keys at Feltham Young Offenders' Institution have had to be replaced after security was compromised during a media visit last week.
Hand the valet a key fob that you've enabled for use within a 1 mile radius and two car starts?
That's a great way to have your dinner interrupted or end up waiting forever for your car.
https://www.kickstarter.com/projects/schuyler/lockpicks-by-o...
And Jason Scott is on the case to get things righted, you can't get a much more trustworthy caretaker than that...
https://www.kickstarter.com/projects/schuyler/lockpicks-by-o...
As a non-American, I agree the U.S. is way overmedicated.
That said, some people still do need medication. If you read the post you'll see the guy himself has avoided the medication until now due to a bad episode of being misdiagnosed and medicated as a child. He has literal first-hand experience of what you're complaining about.
I'm in Japan now, and this place is the exact opposite. Mental illness "doesn't exist" and half the medications prescribed in the US are illegal here. And hey, 3 train jumpers a day. "Hey pussy, pull yourself up by your bootstraps" doesn't work either.
Also, does KeyMe, et al, really not email/notify you when a dupe is made?
If you loose possession of your keys for a time someone can copy them. Did someone not know this?
It's 2014. Smart cards need to be everywhere. Even my college dorm had contactless smart card authentication.
Keys still have a place for manual override in outages, but that should be rare and set off alarms.
I just stayed at a hotel in New York with smart card locks. It was so nice to be able to just hold my wallet against the door rather than pull the card out of my wallet and try to remember which way the magstripe goes, etc.
The reader on the elevator was placed low enough that I just needed to stand within a few inches of it to "unlock" my floor.
Security is always a tradeoff, and there are many usecases where a huge increase in security isn't worth even a tiny increase in accessibility or cost.
Let's take an example of cheap padlock on a garden shed or a lock on a filing cabinet. Both of them are trivially broken, either by skill or simply brute force. Yet, they achieve their security goal - they do prevent (as in, significantly reduce frequency) random passers-by from taking the stuff inside. A more secure model, such as smart cards, would be an inferior choice there due to increased cost and decreased usability.
For example, a secure system would require to make it harder for a random person to make copies of the key/token/whatever. An accessible system would require to actually make it easier - so that any keyholders can easily make copies without authorization from 'key owner' that takes some time and effort. For example, if a renter needs to involve the landlord to copy his key if one of them was lost, then it's more secure but less usable. "Easily copied" is a bug or a feature only depending on the system needs.
Spoiler/tl;dr summary of this comment: Soon you will be able to generate a key while standing at the lock, scanning it with the laser scanner built into your mobile device, generating the key with a hand-held 3D printer you bought at the convenience store on the corner.
OK, longer version.
A number of comments dismiss the security threat as not particularly meaningful (give someone your keys, give them an opportunity to mess you up) and they are correct insofar as this very specific threat is concerned. It really is very similar to the traditional "give someone your credit card, they can mess you up" threat.
But think about that threat for a moment: The reality of that threat led to chip-and-pin cards, to CCVs, and to PCI compliance.
That threat was also greatly magnified by the move from the pen-and-paper world to the world of online shopping - and we've had to adjust our threat mitigation strategies appropriately.
The point of the article isn't actually for example that valets require great trust. The author actually misses the real point while describing it quite clearly: It has always been possible to do this, it's just orders of magnitude easier, and cheaper, to do it today, because of the blend of off-the-shelf widely available low-tech technology. That's the point of mentioning KeyMe: It is so easy to build the bits to do this threat that there are reliable commercial services that make money from low-cost apps and unattended kiosks.
And it is going to get much, much, much, much worse, very, very, very soon.
Very soon now you will be able to buy a pocket or at worst back-pack size multifunction replication device, that is, a 3D printer with a scanner built-in, or perhaps a 3D printer that uses your mobile device as a scanner.
With that device, you will be able to duplicate the keys on the way up the stairs.
And soon you will be able to use a commercial hand-held 3D printer with a commercial hand-held laser scanner to generate a key by scanning the lock.
That's just the beginning of tomorrow's threat model.
EDIT: Added a missing word above, and the following thought....
We assess attackers based on motivation and resourcefulness: a motivated, resourceful attacker is always a worry. The key duplication threat used to require a motivated attacker capable to acquiring resources, e.g., the prisoner, who would duplicate a key slowly and laboriously, using low-tech tools. This is a very motivated attacker.
Existing and emerging technologies make the resources widely available and lower the motivation bar dramatically. The key duplication scenario will soon be populated by the equivalent of script kiddies who will perform the threat just because they can, just because it's that easy.
That's the point of the article. That's the threat model we face going forward.
I still find it an unlikely threat model, but I would admit that in the unlikely event that a technology allowing you to enter a door just by scanning it and printing up a key were invented and integrated into mobile phones or something else people are carrying around anyway, then that might actually overtake "crowbar"/"breaking the window" as the lowest-cost lowest-risk way of breaking into someone's home. And even then, probably it wouldn't affect all that many people. Plus you'd just have to modify lock technology slightly to fix the problem.
Especially if the scan included analyzing against known lock types? This is the sort of problem for which the Internet is ideal: An optical scan to narrow down lock makers and models, load custom signal processing configurations for those likely locks, perform a sonic scan of the lock and collect reflections, distortions, etc., and use the custom config to ease the decoding: Wah-la! A picture of the inside of the lock, with pin segment lengths.
Then print 5-10 likely keys on the spot.
Picking a lock requires a suspicious body posture and special tools.
Scanning a lock this way just requires you be close enough to the door. Checking your messages? Patting your pockets to make sure you have everything? Leaning your bag against the door on your knee to make sure you have everything? Many plausible scenarios for staying close enough long enough, and the tools are COTS, common.
Or maybe I "deliver" a "package" to your door, lean it against the door (UPS and others do this all the time), and the top of the package contains the scanning tools. I come back later (seconds, minutes?) after realizing I've made a mistake and take the package back.
The more I think about it, the more I cannot help but wonder if the physical lock of the future will not need a proof-of-authorization mechanism to vet the keyholder - at which point we eliminate the keyhole entirely and move to direct identification of authorized entrants.
And then of course watch for 0-day vulnerabilities in THAT technology.