Thinkpad Dock-Picking

Hackers at the “RaumZeitLabor” hackerspace in Mannheim Germany have noticed that the locking mechanism on the thinkpad mini dock is extremely easy to circumvent. Sold as an additional layer of security, the mechanism itself is not really secured in any way. The button that actuates it is locked by a key, but the latch isn’t secured and can be accessed via a vent on the side. They are using a lockpicking tool in the video, but they say that even a long paperclip would suffice.

We know that no security device is perfect, and if someone really really wants it, they’ll take it, but this seems a bit too easy. Maybe the next version will have a little plastic wall protecting the latch from being actuated manually.  Hopefully if security is your main concern you are using something a little more robust that a dock-lock.

[via the RaumZeitLabor hackerspace (google translated)]


15 thoughts on “Thinkpad Dock-Picking

  1. Nice hack. The video felt a bit OTT bu I guess you can’t argue that it showed the weakness well enough.

    If I’d bought it for the security feature, I’d now be looking to return it for a refund.

  2. The IBM docks have been notoriously lax in security. The dock for the T40 series is a prime example. All a would be thief would need to do is stick a paper clip into the key way and press down on the release button. It takes longer to read this comment than it does to open that dock.

  3. It doesn’t matter if the lock works or not. It shouldn’t be part of any security plan anyway. The data is always going to be more valuable than the hardware. Full disk encryption and encrypted communications should be the concern.

  4. They market it as security, so you only need to purchase one Kensington lock. On the face it looks good to a normal non-HR manager who generally makes the purchasing decision, as you can use a Kensington lock to secure the Dock, then the Dock to secure the laptop…

    The best bet is to use Kensington locks on both the dock and the laptop for real security. (The laptop key-hole is still accessible when it’s in the dock.)

  5. The fact that we didn’t use a paper clip in the video is that using a paper clip works, but it is a bit harder to do and less impressive for a video. As you can see, we were pretty fast using the pick tool with a docked ThinkPad, but we were much slower in the side view (the camera was in the way). So I guess it’s all about training.

  6. Kensington locks? Secure?! Oh please.

    Do a video search for “kensington lock toilet paper” to see them opened quite easily using only the cardboard of a toilet paper roll. Been featured on boingboing in 2005.

Leave a Reply

Please be kind and respectful to help make the comments section excellent. (Comment Policy)

This site uses Akismet to reduce spam. Learn how your comment data is processed.