Hackers crack high-tech locks

August 1, 2010
A woman uses a fingerprint scanner

Enlarge

A woman uses a fingerprint scanner. Security maverick Marc Tobias showed hackers on Saturday how simple it is to defeat some of the world's top high-tech locks.

Security maverick Marc Tobias showed hackers on Saturday how simple it is to defeat some of the world's top high-tech locks.

"These locks might be winning awards but they are forgetting the basics," Tobias said while giving AFP a first-hand look at how to crack several models. "They might be clever, but they aren't secure."

A Biolock model 333 designed to scan and unlock for chosen people was opened by simply pushing a paper clip into a key slot.

An Amsec ES1014 digital safe was breached by sliding a flat metal file folder hangar through through a crack at the edge of the door and pressing an interior button allowing the access code to be reset.

Tobias grew passionate when it came to an award-winning electromagnetic lock made in China for Finland-based iLoq.

The innovative iLoq used the action of a key being pushed into the lock to generate power for electronics that then checked data in a chip on the key to determine whether the user is cleared for access.

Tobias and lock-cracking colleague Tobias Bluzmanis pointed out that the iLoq design counted on a small hook being tripped to reset the devices as a key was removed.

In what they referred to as a viable inside attack possible on locks geared for office settings, someone could borrow a key and shave tiny bit of metal from the tip and it would no longer catch the iLoq reset hook.

A pocket-sized tool available in US stores for about 60 dollars could be used to grind down the hook in seconds, the men demonstrated.

With either method, the result would be that once a valid key is used to open the iLoq it will yield to any key or even a screw driver stuck in the slot because it remains stuck in the unlocked position.

An audit trail left by a compromised iLoq would stop at the person whose key legitimately opened the lock.

"It is really clever, but it is also very defective," said Tobias, a longtime advocate for tougher standards in the lock industry.

"Electromechanical locks are more secure if done right. The question is whether the technology is implemented properly."

The security.org crew opened a Kwikset programmable "smartkey" lock with a key blank, a screw driver and a vice grip tool.

Tobias and his team consistently show up at the annual DefCon gathering in Las Vegas to pop locks with wires, magnets, air, shock, screw drivers and other improvised tools.

Their presentation this year was met with hoots and applause.

Lock-picking holds a natural appeal to hackers, who thrive on bending hardware or software to their wills.

(c) 2010 AFP

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

Sanescience
Aug 02, 2010

Rank: not rated yet
Who do they think they are, testing the security of products who's purpose is security.

LOL!
AlejoHausner
Aug 02, 2010

Rank: 5 / 5 (1)
It's probably a socialist plot to interfere with the well-meaning corporations who are trying to make an honest dollar selling high-tech locks. Shame on these researchers!
ForFreeMinds
Aug 02, 2010

Rank: not rated yet
Hooray for these ingenious guys. It's a good thing they show everyone the easy to pick locks, so the better locks win.
Rank 5 /5 (20 votes)
Related Stories
Relevant PhysicsForums posts

More news stories

Netflix light on flicks as viewers soak up TV shows

Like most fresh faces that arrive in Hollywood, Netflix wanted to be a movie star. But now it's learning what many in Tinseltown have known for decades: Movies are sexy, but the real money is in television.

Technology / Business

created 6 minutes ago | popularity not rated yet | comments 0

Sony's Hirai refuses to abandon dire TV business

Struggling Japanese entertainment giant Sony will not abandon its cash-bleeding television business, its incoming CEO says, but he acknowledges tough decisions lie ahead including over redundancies.

Technology / Business

created 36 minutes ago | popularity not rated yet | comments 0

New error-correcting codes guarantee the fastest possible rate of data transmission

Error-correcting codes are one of the triumphs of the digital age. They’re a way of encoding information so that it can be transmitted across a communication channel — such as an optical fiber o ...

Technology / Computer Sciences

created 3 hours ago | popularity 5 / 5 (3) | comments 2 | with audio podcast

Small modular reactor design could be a 'SUPERSTAR'

(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...

Technology / Energy & Green Tech

created 2 hours ago | popularity 5 / 5 (4) | comments 9 | with audio podcast

Advanced power-grid model finds low-cost, low-carbon future in West

(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...

Technology / Energy & Green Tech

created 2 hours ago | popularity 5 / 5 (1) | comments 3 | with audio podcast


Experts reveal how plants don't get sunburn

(PhysOrg.com) -- Experts at the University of Glasgow have discovered how plants survive the harmful rays of the sun.

Fool's gold may prove an unlikely alternative to overexploited catalytic materials

Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...

Curry spice component may help slow prostate tumor growth

Curcumin, an active component of the Indian curry spice turmeric, may help slow down tumor growth in castration-resistant prostate cancer patients on androgen deprivation therapy (ADT), a study from researchers ...

Unpicking HIV’s invisibility cloak

Drug researchers hunting for alternative ways to treat human immunodeficiency virus (HIV) infections may soon have a novel target—its camouflage coat. HIV hides inside a cloak unusually rich in a sugar ...

What lies beneath: Mapping hidden nanostructures

The ability to diagnose and predict the properties of materials is vital, particularly in the expanding field of nanotechnology. Electron and atom-probe microscopy can categorize atoms in thin sheets of material, ...

To avoid early labor and delivery, weight and diet changes not the answer

One of the strongest known risk factors for spontaneous or unexpected preterm birth – any birth that occurs before the 37th week of pregnancy, most often without a known cause – is already having had one. For women ...