A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and...

61
A FAILURE OF IMAGINATION: Kwikset Smartkey® and Insecurity Engineering ONE OF THE MOST SECURE and INSECURE LOCKS IN AMERICA

Transcript of A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and...

Page 1: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

A FAILURE OF IMAGINATION: Kwikset Smartkey® and Insecurity Engineering

ONE OF THE MOST SECURE andINSECURE LOCKS IN AMERICA

Page 2: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET SMARTKEY

Page 3: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

#1: IS SMARTKEY SECURE?Brian: 06/25/2013 1105 A.M.

Page 4: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

#2: IS SMARTKEY SECURE?Satima: 06/24/2013 4:26 P.M.

Page 5: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

#3: IS SMARTKEY SECURE?Raymond: 06/25/2013 3:58 P.M.

Page 6: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET LOCKSA Spectrum Brands Company

iMILLIONS IN USE IN AMERICA AND CANADA

iHOMES, APARTMENTS, BUSINESSESi INEXPENSIVE: COST: $20-$30iMODELS:

– Pin tumbler, 5 and 6 pin– Smartkey, 5 pin– Deadbolts– Electronic + override

Page 7: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

ONE OF THE MOST POPULAR LOCKS IN U.S.

iMILLIONS SOLD EVERY YEAR– COMMON KEYWAY: WEISER, BALDWIN

iFOR MORE THAN FIFTY YEARSiDIVERSE PRODUCT LINE

– Deadbolts– Rim– Lever handle– Electronic

Page 8: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET DISTRIBUTION

Page 9: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

WIDE PRODUCT LINE

Page 10: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

HOMES, APARTMENTS, BUSINESS, COMMERCIAL

Page 11: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET, WEISER, BALDWIN:The Basics

i PIN TUMBLER AND SMARTKEYi 5 or 6 PIN CONVENTIONAL CYLINDERS

– Many configurationsi 5 PIN SMARTKEY PROGRAMMABLEi COMMON KEYWAYS, NO SECURITYi NO DUPLICATION PROTECTIONi NOT HIGH SECURITYi MAINLY RESIDENTIAL AND APARTMENTS

Page 12: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET HISTORY

iORIGINAL PIN TUMBLER DESIGN– Rim cylinder– Deadbolt– Key-in-knob design

iEASILY COMPROMISEDiMOST POPULAR UNTIL 2008

– Smartkey introduced to Canada and U.S.

Page 13: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

PIN TUMBLER v. SMARTKEY

Page 14: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

PIN TUMBLER DESIGN

iNOT SECUREiEasy to pickiEasy to bumpiEasy to impressioniEasy to mechanically bypassiCan be master keyediEasy to determine the Top Level MKiLimited number of combinations

Page 15: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

PIN TUMBLER DESIGN:How it works

Page 16: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

PIN STACKS = SECURITY:Plug can turn: pins at shearline

Page 17: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

LOCKED: PINS NOT AT SHEARLINE

Page 18: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET SMARTKEY:Not a pin tumbler lock

Page 19: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SMARTKEY ATTRIBUTES

i 5 PIN ONLY 6 DEPTH INCREMENTS iSINGLE SIDEBAR SECURITYiEXTREMELY PICK RESISTANT UL437iCANNOT BE BUMPEDiCANNOT BE IMPRESSIONEDi INSTANT PROGRAMMABILITY TO

ANY KEYiCANNOT BE MASTER KEYED

Page 20: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

MORE ATTRIBUTES

iONE PRIMARY KEYWAYiBHMA 156.5 GRADE 1 RATINGiUL 437 RATINGiSPECIAL “KEY CONTROL DEADBOLT’

AS ALTERNATIVE TO MK SYSTEM

Page 21: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SMARTKEY DESIGN

Page 22: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

PROGRAMMABLE SLIDERS

Page 23: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SIDEBAR =SMARTKEY SECURITY

Page 24: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

MASTER KEY SYSTEMS:Pin Tumbler v. Smartkey

iCONVENTIONAL MK SYSTEMS

Page 25: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

CONVENTIONAL MK SYSTEM ATTRIBUTES

iONE KEY OPENS MANY LOCKS– Only bottom pin and master pin per chamber

iDIFFERENT LEVELS OF KEYING– Can reduce number of change keys

iEXPENSIVE TO REKEY OR ADD KEYS– Must disassemble cylinder to rekey

iCROSS KEYING BETWEEN LOCKS AND SYSTEMS

Page 26: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

MK SYSTEM SECURITY

i INHERENT INSECURITYiMUST HAVE AT LEAST TWO

SECURITY LAYERSiEASIER TO COMPROMISE ENTIRE

SYSTEM– Multiple shear lines– Unintended key combinations will open lock– Easier to pick, bump, impression, decode– Extrapolation of TMK

Page 27: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET KEY CONTROL:The Alternative to Master KeyingiTWO INDEPENDENT CORESiTWO SEPARATE AND DISTINCT KEYS

– Supposed to maintain security of key blanks– Control key only from factory

i INSTANTLY REPROGRAMMABLEiNO CROSS KEYING OR INCIDENTAL

MASTER KEYSiNOT A REAL MK SYSTEMiONLY ONE LEVEL OF KEYING

Page 28: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET “KEY CONTROL”Positive Attributes

iNO LOCKSMITH REQUIREDi 46,656 THEORETICAL COMBINATIONSiGOOD FOR FACILITIES THAT NEED

ONE MK LEVEL ONLYiGREAT FOR CONSTRUCTION MKiNO DISASSEMBLY OF CYLINDERSiTWO INDEPENDENT SHEAR LINES

WITH NO INTERACTION LIKE CONVENTIONAL SYSTEMS

Page 29: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET “KEY CONTROL”More positive attributes

i INSTANT ABILITY TO REPROGRAMiTWO SEPARATE KEYWAYSiCANNOT DERIVE CONTROL KEY

FROM CHANGE KEYiLIKE CORBIN “MASTER SLEEVE”

SYSTEM 75 YEARS AGO, INHERENTLY MORE SECURE

iLITTLE CHANCE OF ONE SYSTEM OPENING ANOTHER

Page 30: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET “CONTROL KEY”The Bad

iNO WARRANTY FOR COMMERCIALiNOT FOR COMPLEX OR

COMMERCIAL SYSTEMSiCAN BE COMPROMISED IN 15

SECONDSiEASY TO DECODE CONTROL KEYiEASY TO REPLICATE CONTROL KEYiNO PATENT PROTECTION ON KEYS

Page 31: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SECURITY: YOU GET WHAT YOU PAY FORiDO YOU EXPECT A $20-$30 LOCK TO

PROVIDE ANY SECURITY?– Some buyers cannot afford higher security– What is the minimum they are entitled to?

iKWIKSET KNOWS THESE LOCKS HAVE SERIOUS VULNERABILITIES

iDOES THE PUBLIC HAVE A RIGHT TO KNOW HOW EASY TO OPEN?– Should there be warnings on packaging?

Page 32: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET SMARTKEY:INSECURITY ENGINEERINGiMILLIONS OF PEOPLE AND

FACILITIES AT POTENTIAL RISK– COVERT ENTRY– FORCED ENTRY

iKWIKSET “Highest grade of residential security available.”– True but misleading– Open in less than thirty seconds

Page 33: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

FALSE SENSE OF SECURITY

iBHMA GRADE 1 RATINGi “Highest grade of residential security”iUL 437 PICKING RATINGiVIRTUALLY BUMP PROOFiUSERS ARE NOT AWARE OF RISKSiLOCKS CAN BE OPENED IN SECONDSiFAILURE TO DISCLOSE

VULNERABILITIES

Page 34: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KWIKSET ADVERTISING andMISREPRESENTAIONS

iFALSE OR MISLEADING STATEMENTS BY TECH SUPPORT AND SALES

i 8 SEPARATE INTERVIEWS:– “Cannot be opened except by drilling”– “No maintenance problems”– “Video on YouTube not true: lock was

tampered with”– “No way can be opened with a screwdriver”– “The problem has been dealt with”

Page 35: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SMARTKEY DESIGN ISSUES

iSIDEBAR SHOULD PROVIDE MORE SECURITY THAN PIN TUMBLER LOCK

iONLY ONE LAYER OF SECURITYiSMALL FRAGILE SLIDERSiPROGRAMMING PROBLEMSiLOW TOLERANCE, LIMITED DIFFERS

– 243 Key combinations– All the same blank

iCAST METAL EASILY COMPROMISED

Page 36: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

MORE DESIGN ISSUES

iPLUG DESIGN CAN BE WARPEDiSLIDER DESIGNiABLE TO DECODE THE SLIDERSiSLIDERS EASILY JAMMEDiTAILPIECE DESIGN AND ACCESSiNO KEY DETENT FOR

PROGRAMMING

Page 37: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SMARTKEY: METHODS OF DEFEAT

iTRYOUT KEYSiTAILPIECE, WIRE THROUGH

KEYWAYiVISUALLY READ SLIDER POSITIONiTORQUE THE PLUG AND OPENiREPLICATING CONTROL KEYiDECODING OF THE MASTER KEY

Page 38: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TRYOUT KEYS

iBITTING = 6 DEPTHS @.023”i 5 SLIDERS iUNIVERSE OF KEYS = 3 to 5th = 243i #1.5 =DEPTHS 1-2i #3.5 = DEPTHS 3-4i #5.5 = DEPTHS 5-6

Page 39: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

DEPTH INCREMENTS AND TOLERANCE

DEPTHS 1-2-3-4-5-6

Page 40: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

DEPTH INCREMENTS 1-2

DEPTHS 1-2 = 1.5

Page 41: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

DEPTH INCREMENTS 3-4

DEPTHS 3-4 = 3.5

Page 42: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

DEPTH INCREMENTS 5-6

DEPTHS 5-6 =5.5

Page 43: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TRYOUT KEY SET

Page 44: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TAILPIECE DESIGN

iSAME DESIGN FOR PIN TUMBLER AND SMARTKEY

iHOLLOW AND SOLID TELESCOPINGiPLUG CAP NOT SUFFICIENTiZIG ZAG WIRE THROUGH KEYWAY

– No trace– No damage– Less than 30 seconds

Page 45: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KEY-IN-KNOB ATTACK:Tailpiece access

Page 46: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KEY-IN-KNOB ATTACK

Page 47: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TAILPIECE AND WIRE

Page 48: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TAILPIECE ATTACK

Page 49: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

VISUAL DECODING SLIDERS

iSLIDER TO TUMBLER INTERFACEiCAN DETERMINE POSITION OF

SLIDER AND KEY CODEi INSERT BORESCOPE OR MIRROR TO

VIEW POSITION

Page 50: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TORQUE THE PLUG

iBELIEVE VIOLATES THE BHMA 156.5iFormal complaint filediHOW THE LOCK CAN BE

COMPROMISED: DESIGN ISSUES– Warp sliders or keyway– Application of 110 pound force inches– Set sliders to specific position– Apply torque with 4” screwdriver and wrench– OPEN IN ABOUT FIFTEEN SECONDS

Page 51: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SLIDER DESIGN AND TORQUE ATTACK

Page 52: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

TORQUE AND BHMA 156.5REQUIREMENT = 300 lbf-inOPEN in 112 lbf-in

Page 53: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

112 Pounds Force Inches = OPEN

Page 54: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

KEY CONTROL: NONE

Page 55: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SMART KEY LOCKS AND KEY CONTROL

Page 56: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

DECODING THE LOCK OR CONTROL KEYiKEY CONTROL BLANK ONLY

AVAILABLE FROM FACTORYiNOT THE SAME AS CHANG KEYiSPECIAL DECODER TO READ THE

SLIDERS

Page 57: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

MAKING THE CONTROL KEY

iSEPARATE KEYWAYS ARE NOT SUPPOSED TO BE INTERCHANGEABLE

iTHE REPRESENTATION: CONTROL KEYS ARE SECURE

Page 58: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

CHANGE KEYS AND CONTROL KEYS

Page 59: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

SUMMARY: SMARTKEY INSECURITYiONE OF MOST POOPULAR AND

INEXPENSIVE LOCKS IN US. AND CANADA

iCONSUMER FRIENDLYiFILLS CERTAIN NEEDSiSECURE AGAINST CERTAIN

ATTACKS– Picking– Bumping

Page 60: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

BURGLARS: THEY DON’T PICK LOCKSi PICK RESISTANTi BUMP PROOFi ALL OF THE SECURITY IS MEANINGLESS

IF THE LOCK CAN BE OPENED IN 15 SECONDS

i PATENTS MEAN NOTHINGi BHMA RATINGS MEAN NOTHINGi COULD BE MADE SECUREi YOU GET WHAT YOU PAY FOR

Page 61: A FAILURE OF IMAGINATION: Insecurity Engineering€¦ · A FAILURE OF IMAGINATION: G iTobias and Tobias Bluzmanis imwtobias@security.org itbluzmanis@security.org i. Title: DEFCON-21

A FAILURE OF IMAGINATION: INSECURITY ENGINEERINGi© 2013 Security Labs, Marc Weber Tobias

and Tobias [email protected] [email protected]