<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; blackbag</title>
	<atom:link href="http://hackaday.com/tag/blackbag/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 11:18:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; blackbag</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Medeco high security lock picking</title>
		<link>http://hackaday.com/2008/07/29/medeco-high-security-lock-picking/</link>
		<comments>http://hackaday.com/2008/07/29/medeco-high-security-lock-picking/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 14:40:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[barrywels]]></category>
		<category><![CDATA[blackbag]]></category>
		<category><![CDATA[highsecurity]]></category>
		<category><![CDATA[highsecuritylock]]></category>
		<category><![CDATA[jonking]]></category>
		<category><![CDATA[lock]]></category>
		<category><![CDATA[lockpick]]></category>
		<category><![CDATA[lockpicking]]></category>
		<category><![CDATA[locksport]]></category>
		<category><![CDATA[medeco]]></category>
		<category><![CDATA[medecoder]]></category>
		<category><![CDATA[nde]]></category>
		<category><![CDATA[toool]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/07/29/medeco-high-security-lock-picking/</guid>
		<description><![CDATA[Despite, Hack a Day seeming to be fairly lock heavy lately, we&#8217;ve yet to cover a major story from The Last HOPE. At the conference, [Jon King] talked about vulnerabilities in Medeco locks and presented his Medecoder tool. Medeco is really what makes this story interesting; unlike the EU, the US has very few high [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2355&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="182" border="0" alt="" src="http://hackadaycom.files.wordpress.com/2008/07/had_medecoder.jpg?w=450&#038;h=182" /><br />Despite, Hack a Day seeming to be fairly <a href="http://www.hackaday.com/tag/lock">lock heavy</a> lately, we&#8217;ve yet to cover a major story from <a href="http://www.mahalo.com/The_Last_HOPE_Conference">The Last HOPE</a>. At the conference, [Jon King] talked about vulnerabilities in <a href="http://www.medeco.com/">Medeco</a> locks and presented his Medecoder tool. Medeco is really what makes this story interesting; unlike the EU, the US has very few high security lock manufacturers. You pretty much have to use Medeco and it&#8217;s found in many government agencies.</p>
<p>The Medeco locks have a vertical row of six pins arranged like most pin tumbler locks. Unlike your average lock, the rotation of the pins is important. When the key is placed in the lock, it not only moves the pins to the correct height, it also rotates them to the correct orientation. A sidebar blocks the cylinder unless the pins are rotated properly. Each pin has three possible orientations. They&#8217;re biaxial as well, which means the pin&#8217;s offset point allows for three more possible positions.</p>
<p><span id="more-2355"></span></p>
<p>[Jon King]&#8216;s Medecoder tool helps deal with the sidebar issue. Each pin in the lock has a groove running up the side. When the pins are in the correct orientation, these grooves are all perpendicular to the lock body and the sidebar can slide into place. [Jon]&#8216;s Medecoder tool is a thin piece of wire with a sliding scale to help you position these grooves correctly.</p>
<p>To pick the lock, you first set all the pins to the correct height. Then, using the Medecoder you find each pin&#8217;s individual groove. All Medeco locks have the pins at the same distance from the lock face. The scale on Medecoder indicates where the pin currently is and where the pin should be. You can see [Jon] using this technique to <a href="http://www.toool.nl/blackbag/?p=211">open a lock onstage at The Last HOPE</a> in under three minutes.</p>
<p>This pin vulnerability has been known in Medeco locks since 1974. With the recent release of the Medecoder, Medeco has started manufacturing ARX pins <span style="font-weight: bold;">again</span>. ARX pins don&#8217;t have the groove cut all the way to the keyway, so they can&#8217;t be manipulated by the tool. As we mentioned earlier, unlike software companies, physical security companies have <a href="http://www.hackaday.com/2008/07/28/lock-picking-and-security-disclosure/">no perceived obligation to patch their install base</a>&#8230; even if they&#8217;ve known it was broken in some form for 30 years.</p>
<p>The latest issue of NDE has just been released and features a <a href="http://www.ndemag.com/nde4.html">full write up on the Medecoder</a>. It also details the different kinds of ARX pins that have been developed.</p>
<p>[photo: <a href="http://www.toool.nl/blackbag/?p=213">blackbag</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2355/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2355/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2355&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/07/29/medeco-high-security-lock-picking/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/07/had_medecoder.jpg" medium="image" />
	</item>
		<item>
		<title>Toool picksets at The Last HOPE</title>
		<link>http://hackaday.com/2008/07/12/toool-picksets-at-the-last-hope/</link>
		<comments>http://hackaday.com/2008/07/12/toool-picksets-at-the-last-hope/#comments</comments>
		<pubDate>Sun, 13 Jul 2008 01:00:00 +0000</pubDate>
		<dc:creator>Benjamin Eckel</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[misc hacks]]></category>
		<category><![CDATA[blackbag]]></category>
		<category><![CDATA[centipede]]></category>
		<category><![CDATA[hope]]></category>
		<category><![CDATA[last]]></category>
		<category><![CDATA[lockpick]]></category>
		<category><![CDATA[lockpicking]]></category>
		<category><![CDATA[magentic]]></category>
		<category><![CDATA[pick]]></category>
		<category><![CDATA[picksets]]></category>
		<category><![CDATA[ring]]></category>
		<category><![CDATA[toool]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/07/12/toool-picksets-at-the-last-hope/</guid>
		<description><![CDATA[Speaking of laser engraving, the blackbag blog announced that Toool has designed 2 unique picksets for The Last HOPE this year. First is the credit card sized snap-off set seen above. They have named this one The Last HOPE emergency pickset. The other pickset is a new version of the &#8216;double sided pick&#8217; series. This [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2264&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="center"><img width="450" vspace="4" hspace="4" height="258" border="0" src="http://hackadaycom.files.wordpress.com/2008/07/lasthopeemergencypickslarge.jpg?w=450&#038;h=258" alt="" /></div>
<p>Speaking of laser engraving, the blackbag blog announced that <a href="http://www.toool.nl/blackbag/?p=209">Toool has designed 2 unique picksets</a> for <a href="http://www.mahalo.com/The_Last_HOPE_Conference">The Last HOPE</a> this year. First is the credit card sized snap-off set seen above. They have named this one The Last HOPE emergency pickset. The other pickset is a new version of the &#8216;double sided pick&#8217; series. This set consists of picks with the same tool on either end, but they are sized differently. This set will contain 8 picks with promised improvements. If you are interested in more complex picks, check out <a href="http://www.toool.nl/blackbag/?p=208">the centipede</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2264/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2264/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2264/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2264&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/07/12/toool-picksets-at-the-last-hope/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ben</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/07/lasthopeemergencypickslarge.jpg" medium="image" />
	</item>
	</channel>
</rss>
