3-D Printed Keys Can Pick High-Security Locks in Seconds
wired.com
wired.com
This is the lockpicking equivalent of calling a cracker a hacker.
Also, no lock can be 'unbumpable' just because it has a restricted blank, as by definition in those cases, if the blank can be obtained, the lock can be bumped.
Unbumpable is generally reserved for locks that actually are, by using a mechanism other than pin tumblers (e.g. rotating discs (e.g. Abloy Protec), magnetic encoding on the key (e.g. EVVA MCS), sliders (e.g. EVVA 3KS), or driverless pins (e.g. BiLock)).
High security locks have for a few years been incorporating moving/active elements into keys to avoid duplication, both now from 3D printing, but also originally from casting a copy of the key. As it is, keys witout those can be directly duplicated rather than even needing to bother with a bump key (unless you wanted to open more locks than the key used to make the copy can access).
“The sky isn’t falling, but the world changes and now people can make stuff,” says Weyers. “Lock manufacturers know how to make a lock bump-resistant. And they had better.”
Always very pleased to see his name pop up when this sort of thing makes news, as he never seems to offer a quote that can be used to stoke unreasonable fear.
Yes.
It's funny because it's true.
What I'm saying is, if you lock the case to your desktop shut. Dumping your unencrypted hard drive is still possible, and easy. And fundamentally completely unchanged. All you did was put a hurdle in front of it, not fundamentally change the attack vector.
Additionally, people have been bumping things with just about anything that can fit into a keyway, it doesn't particularly matter if it conforms to the exact shape of the key, so long as it can still interact with the pins directly. So, bent sheet metal with teeth cut into them, flexible grocery loyalty cards, etc. have all been used by folks in the locksport community to bump locks they didn't have proper blanks for. I can't deny the SK6 (and many Ikon locks, they are vicious) didn't have a particularly murderous keyway, but the possibility of carrying out a percussive attack wasn't nil.
Not to mention that you seem to be ignoring the second paragraph entirely.
And, honestly, this seems like a silly argument to be having. I actually think the boys did great work on this, and I really appreciate that you mention the possibility of forensic evidence (in the practice of which Germany is a leader) left by these keys. I just think that some people commenting on this thread are a bit frustrated by some of the hyperbole, and your insistence that there is no hyperbole is continuing to derail whatever point you are attempting to make.
I agree this argument is silly. Whether an Ikon SK6 lock is considered "umbumpable" and by who is pretty subjective. But this thread began with a commenter saying that none of this is news, and that it's all 50 years old. Hyperbole is indeed pretty annoying.
"As a result, all anyone needs to open many locks previously considered “unbumpable” ..."
B: He asked someone to tell him how it could have been bumped prior to this application.
C: I described, in my scenario, the purchase of a 1 Euro blank from someone who runs the machine, which is actually /less/ than the Shapeways scenario, which is otherwise the same - you don't purchase the equipment, you purchase the product the equipment makes.
Again I'll state, "This doesn't fundamentally change the attack vector, all it does is put a hurdle in-front of it."
One that is now easier to circumvent, true. But one that was circumventable in the past with the correct resources.
"As a result, all anyone needs to open many locks previously considered “unbumpable” ..."
You are implying that this has made the impossible, possible. I think that may be valarauca's point of contention.
When the flaw becomes easier to exploit its isn't so much news, it was bound to happen anyways, I mean your just wrapping iron bandages around a flaw and causing it fixed. This happens in software security all the time. The flaw still exists, just we added an abstraction above the flaw, that makes the flaw harder to exploit.
If I have access to a mill and pictures of some "high security key", sans magnets and other types of active mechanisms, I can duplicate that key.
It may be difficult, but subtractive method still works. A subtractive method is what is used when you go from blank to key.
What is new here is someone can print a plastic key. Cool. with PLA and a rubber vacuum set, I can cast any amount of iron blanks of said 'secure keys'.
Unless they figured out this key because 3D printing allowed for rapid iteration.
For example:
> In this video, Holler demonstrates a 3D-printed and filed bump key for an Ikon SK6, a key that uses restricted, carefully contorted blanks that can’t even be created by many key-milling machines.
Even I could do it.
I don't even know where I'd find a CNC machine. If I asked someone who has one to make a blank key for me he'd probably tell me to fuck off or call the police, and if I tried to use it myself I'd probably cut off my arm.
It's definitely not a revolution of any kind, it's just another step towards lockpicking made easier and more accessible, and makes the concept of physical locks as a lone defense weaker.
Physical security (the real, you-can't-break-this kind) is for banks and governments. For everything else there's video.
When I "locked" the wooden door with a piece of metal that has been photographed by probably countless cameras... I just had to laugh at myself and wonder why I bad been programmed to do this seemingly pointless action my entire life.
Myself, when I am able to own my own house, I am definitely fitting upgraded (unbumpable) locks as part of basic diligence with regards to security, along with fixing any easily breakable windows.
It's also worth noting that windows can always be reinforced/refitted with laminated glass or even protective films that provide enough protection that the random opportunistic crackhead will probably give up when it doesn't break straight away so as not to get caught. Burglaries that take longer than 30 seconds or so to get in will often be aborted because of the risk of getting caught, especially when there are so many houses with no or insufficient alarms, windows that can server as an easy entry point without a motion sensor behind them, and weak locks that can easily be bumped/pulled[1].
If you have big breakable windows, always invest in a good alarm with motion and/or glass-break sensors though.
[1]Pulling/snapping is gradually becoming the new bumping - some lock designs are physically weak enough that they can be either broken inside the door or physically pulled out with hand tools. Example news article: http://www.bbc.co.uk/news/uk-england-leeds-17075027
For most people it's not an issue. The only people that are likely to bump your lock are really professional thieves (who are rare) or intelligence services who'll have better equipment.
Most businesses are more than secure enough. It's far easier for a crook to gain access via social manipulation than it is to bypass physical security systems. As with home security, humans are always the weakest link in the chain.
https://www.google.com/atap/projecttango/#devices
Pin codes are also not secure, subject to capture by movie cameras Google glass and IR heat scanners picking up the key strokes.
So both keys and pin codes are not secure.
Doesn't actually prevent bumping, though! Additionally, the "angle between the rows" is interesting in thinking what exactly he might have said. Sargent, again, with the Keso introduced the idea of somewhat variable spacing of the pins in the Keso.
Additionally, if we're talking angles, there was the Medeco Biaxial (often confused for the original Medeco lock) which introduced the idea of "fore", "center" and "aft" positioning of the cuts in the key/position of the chiseled tips of the pins.
The former, Sargent, can still be readily bumped as even though you won't always know if a pin will be present, you know every possible location of the pins and can adjust accordingly. With Medeco, it's significantly harder, though they caused themselves problems with a heavily restricted code book so that the mere visual observation of the first two pins in the lock could give you a very good idea of the positing of the other elements and allow you to make a few possible bump keys to attack them. They've since fixed that problem.
waves hands
In the US the average length of car ownership is at an all time high of 6 years. You can reasonably expect the locks to outlive your interest in the vehicle. Whereas (and this is all quick googling to get to a point, so anyone feel free to correct my figures) the average ownership of a home is 20 years. Now, while locks can certainly survive that long, it's a good idea to replace them once in a while.
Additionally, in the rental market where turnover is significantly higher, there are often laws that require the regular changing of the locks from tenant to tenant.
And - another factor - insurance standards related to security on cars are much more robust than insurance related to security on buildings. You can occasionally find a break for having a second lock, or deadbolt, etc. but your returns on insurance breaks diminish completely as you invest in higher end physical security.
All of this is to say - door locks are a commoditized after-market product that are influenced by geography. They are made to be replaced/maintained by the user and there will always be a thriving budget marketplace for them. Your car locks, on the other hand, are never meant to be worked on by the user, are rarely replaced and have almost no competitive after-market.
Hope that helps lay out some of the differences between the two.
(and I could go on. Lot of other stuff around OEM, cost of production, ability to sell on security, etc. etc.)
Of course, the reason for this is that criminals largely don't pick locks.
Honestly it's probably just the industry wants to keep its separate businesses which adds up to more money. People sell rfid fobs separate from their high-security keys while cars combine the two. There's no reason you couldn't take the ECU out of a Lexus, wire it up to an arduino, plug it into a wall, attach a solenoid to a door lock and weld the lock cylinder of the car into a door handle. Since modern Lexus keys act as RFIDs when their batteries die it should be mostly fail proof.
I remember reading several years ago about how one can take a picture of a key from far away and use that image to replicate the key. Back then, replicating keys from a picture was not something just anybody could do, so it wasn't a threat worth fretting about. Presumably 3-D printing will make that easier too. One can even imagine an app: point your phone, press a button, and get a key in the mail a few days later. I expect we'll see that article soon.