Defeating The [Works By Design]’s Unpickable Lock

Even though the very concept of an ‘unpickable lock’ is as plausible as making water not be wet, this doesn’t take away from the intellectual thrill of devising solutions to picking attacks and subsequently circumventing those solutions. Case in point the ‘unpickable’ traveling key lock that [Works by Design] recently featured and sent a few copies off to lock pickers such as [Lock Noob] who gave picking it a shake.

Many of the details and reasoning behind [Works by Design]’s lock design can be found in the original video, with [Lock Noob] going over the basic summary before getting to work trying to pick it.

Rather than trying to bump the tumbler lock mechanism or another indirect approach, the focus is here on an impressioning attack. Although in this traveling key mechanism the physical key is moved inside the lock, the pins of the tumbler lock will leave impressions on the brass blanks when the lock is gently forced to rotate, indicating that there’s still too much material there.

The approach here is thus to slowly file away these sections, with interestingly the plastic pin that [Works by Design] had added to dodge impressioning attacks not being too much of an issue. Thus after over an hour of turning-filing-turning-filing ad nauseam, the lock mechanism rotated, confirming that it had been defeated.

In the subsequent teardown of the lock it can be seen that a plastic pin is indeed rather fragile, with part of its top having been torn off. After replacing this damaged plastic pin with a fresh one, a foil-based impressioning attack is attempted by putting aluminium foil over a skeleton key, but this didn’t quite work out as the pins come in sideways and thus do not leave a useful impression.

Theoretically the pins would press down onto the soft foil, creating an almost immediate impression of the required key. Perhaps that leaving a solid side on the blank would make it work, but this is an approach that would have to be refined.

Either way, it shows that ‘unpickable’ depends on your definition, as ‘1+ hour of filing with knowledge of bitting depths’ would be considered ‘unpickable’ by some. At least it’s not as dramatic as a 2020 [Stuff Made Here] ‘unpickable lock’ hack that we covered, before it got shredded by the [LockPickingLawyer] with resulting list of potential fixes of multiple easy exploits before even having to resort to impressioning.

Considering that traveling key designs generally require at least a tedious impressioning attack, with potential ways to address this in a more substantial way, a redesign featuring these changes would be rather interesting to see picked. If it can defeat the average lockpicking enthusiast including those practicing the legal profession, it’s probably as close to ‘unpickable’ as can be before the bolt cutters and angle grinders are used against any vulnerable parts that aren’t the lock itself.

Continue reading “Defeating The [Works By Design]’s Unpickable Lock”

Making The Most Pick-Proof Lock Yet

3D cutaway of the lock with the handle engaging the cog that rotates the mechanism. (Credit: Works By Design, YouTube)
3D cutaway of the lock with the handle engaging the cog that rotates the mechanism. (Credit: Works By Design, YouTube)

Throughout the centuries the art of lock-making and lock-picking have been trapped in a constant struggle, with basic lock designs being replaced by ever more complex ones that seek to thwart any lockpicking attempts, as well as less gentle approaches. When it comes to the very common pin-and-tumbler lock design, the main issue here is that the keyway also provides direct access to the lock’s mechanism. This led [Works By Design] to brainstorm a lock design in which the keyway is hidden.

The ingenious part here is that because the actual key is rotated away after insertion, there is no clear path to the pins. This did require some creative thinking to have a somewhat traditional style key as well as a way to turn the internal mechanism so that the key would be pressed against the pins. Here inspiration was drawn from the switchable magnet mechanism as seen with e.g. magnetic bases. This ensures the key and key handle can be detached and attached quite firmly.

After many 3D printed prototypes, a metal version was CNCed and subjected to some early testing by a locksmith, who even with having seen the CAD model of the lock was stumped. With this initial result and some user feedback in the bag, it was time for large-scale testing with more lockpick enthusiasts, as there are many more ways to open a lock beyond pushing pins. That said, a mechanism was also added to the lock to prevent bumping attacks.

The next testers were found in the Lock Pickers United community, one of whom raised the issue of an impressioning attack. With a couple of test locks on their way to said lockpicking enthusiasts it’ll be exciting to see whether this new lock design will set the standard for future locks or not.

Continue reading “Making The Most Pick-Proof Lock Yet”

Physical Key Copying Starts With A Flipper Zero

A moment’s inattention is all it takes to gather the information needed to make a physical copy of a key. It’s not necessarily an easy process, though, so if pen testing is your game, something like this Flipper Zero key copying toolchain can make the process quicker and easier when the opportunity presents itself.

Of course, we’re not advocating for any illegal here; this is just another tool for your lock-sports bag of tricks. And yes, there are plenty of other ways to accomplish this, but using a Flipper Zero to attack a strictly mechanical lock is kind of neat. The toolchain posted by [No-Lock216] starts with an app called KeyCopier, which draws a virtual key blank on the Flipper Zero screen.

The app allows you to move the baseline for each pin to the proper depth, quickly recording the bitting for the key. Later, the bitting can be entered into an online app called keygen which, along with information on the brand of lock and its warding, can produce an STL file suitable for downloading and printing.

Again, there are a ton of ways to make a copy of a key if you have physical access to it, and the comments of the original Reddit post were filled with suggestions amusingly missing the entire point of this. Yes, you can get a key cut at any hardware store for a buck or two that will obviously last a lot longer than a 3D printed copy. But if you only have a few seconds to gather the data from the key, an app like KeyCopier could be really convenient. Personally, we’d find a smartphone app handier, but if you’ve got a Flipper, why not leverage it?

Thanks to [JohnU] for the tip.

Nitric Acid Is The Hot New Way To Pick Locks

Lockpicking is a grand skill to have, and one that’s often presumed to be one of the dark arts of the burglar. However, a new technique has come to the fore in some European contexts. It appears nitric acid is being used to damage locks to allow criminals to gain entry into residential premises.

Germany’s Bild has covered this matter, as has Feuerwehr Magazine. The technique has apparently come to prominence in the last couple of years. Attackers pour the corrosive liquid into the keyway of a typical door lock. This damages the cylinder, and perhaps the pins inside as well. Once the metal has been eaten away and the structure of the lock is sufficiently degraded, it can presumably be forced open quite easily with hand tools. The technique is apparently especially effective in Germany, where locks are typically installed with the pins facing down. This makes it easy for any liquid trickled into the lock to eat away at the pins in the bottom.

German authorities advised people to be on the look out for discoloration around door locks. If seen, it’s important to avoid contact with any corrosive liquid that may have been used on the lock.

It’s a nasty technique that doesn’t just damage locks, but doors as well! Meanwhile, if you’re learning the art of lockpicking, just remember not to practice on any important locks you might actually need. More pictures after the break.

Continue reading “Nitric Acid Is The Hot New Way To Pick Locks”

Hackaday Podcast 082: DJ CNC, NFC Black Box, Sound Of Keys, And Payin’ For 3D Prints

Hackaday editors Elliot Williams and Mike Szczys check in on the best hacks from the past week. All the buzz is the algorithm that can reverse engineer your house keys from the way they sound going into the lock. Cardboard construction goes extreme with an RC car build that’s beyond wizard-level. Speaking of junk builds, there’s a CNC mill tipped on its side grinding out results worlds better than you expect from something made with salvaged CD-ROM drives. And a starburst character display is a clever combination of laser cutting and alternative using UV-cured resin as a diffuser.

Take a look at the links below if you want to follow along, and as always, tell us what you think about this episode in the comments!

Take a look at the links below if you want to follow along, and as always, tell us what you think about this episode in the comments!

Direct download (60 MB or so.)

Continue reading “Hackaday Podcast 082: DJ CNC, NFC Black Box, Sound Of Keys, And Payin’ For 3D Prints”

Physical Security Hack Chat With Deviant Ollam

Join us on Wednesday, June 3 at noon Pacific for the Physical Security Hack Chat with Deviant Ollam!

You can throw as many resources as possible into securing your systems — patch every vulnerability religiously, train all your users, monitor their traffic, eliminate every conceivable side-channel attack, or even totally air-gap your system — but it all amounts to exactly zero if somebody leaves a door propped open. Or if you’ve put a $5 padlock on a critical gate. Or if your RFID access control system is easily hacked. Ignore details like that and you’re just inviting trouble in.

Once the black-hats are on the inside, their job becomes orders of magnitude easier. Nothing beats hands-on access to a system when it comes to compromising it, and even if the attacker isn’t directly interfacing with your system, having him or her on the inside makes social engineering attacks that much simpler. System security starts with physical security, and physical security starts with understanding how to keep the doors locked.

join-hack-chatTo help us dig into that, Deviant Ollam will stop by the Hack Chat. Deviant works as a physical security consultant and he’s a fixture on the security con circuit and denizen of many lockpicking villages. He’s well-versed in what it takes to keep hardware safe from unauthorized visits or to keep it from disappearing entirely. From CCTV systems to elevator hacks to just about every possible way to defeat a locked door, Deviant has quite a bag of physical security tricks, and he’ll share his insights on keeping stuff safe in a dangerous world.

Our Hack Chats are live community events in the Hackaday.io Hack Chat group messaging. This week we’ll be sitting down on Wednesday, June 3 at 12:00 PM Pacific time. If time zones have you down, we have a handy time zone converter.

Click that speech bubble to the right, and you’ll be taken directly to the Hack Chat group on Hackaday.io. You don’t have to wait until Wednesday; join whenever you want and you can see what the community is talking about.

3D Printed Snap Gun For Automatic Lock Picking

At a far flung, wind blown, outpost of Hackaday, we were watching a spy film with a bottle of suitably cheap Russian vodka when suddenly a blonde triple agent presented a fascinating looking gadget to a lock and proceeded to unpick it automatically. We all know very well that we should not believe everything we see on TV, but this one stuck.

Now, for us at least, fantasy became a reality as [Peterthinks] makes public his 3D printed lock picker – perfect for the budding CIA agent. Of course, the Russians have probably been using these kind of gadgets for much longer and their YouTube videos are much better, but to build one’s own machine takes it one step to the left of center.

The device works by manually flicking the spring (rubber band) loaded side switch which then toggles the picking tang up and down whilst simultaneously using another tang to gently prime the opening rotator.

The size of the device makes it perfect to carry around in a back pocket, waiting for the chance to become a hero in the local supermarket car park when somebody inevitably locks their keys in their car, or even use it in your day job as a secret agent. Just make sure you have your CIA, MI6 or KGB credentials to hand in case you get searched by the cops or they might think you were just a casual burglar. Diplomatic immunity, or a ‘license to pick’ would also be useful, if you can get one.

As mentioned earlier, [Peter’s] video is not the best one to explain lock picking, but he definitely gets the prize for stealth. His videos are below the break.

In the meantime, all we need now are some 3D printed tangs.

Continue reading “3D Printed Snap Gun For Automatic Lock Picking”