Live data from Hacker News

How to open a safe

github.com

81–85 of 85 posts

Re: How to open a safe

#81

Earlier quoted context omitted.

Judging by the fact that master lock is still widely sold, it’s not common knowledge how crap they are.

>Judging by the fact that master lock is still widely sold, it’s not common knowledge how crap they are. I think you misunderstand the threat model and/or use case. Most of the time I don't think anyone expects locks to do anything except keep honest people honest and dissuade the lowest level of opportunistic attacks. A sledge hammer is cheap. It can open just about any door. The difference between a cheap door and…

Nit: isn't this a threat scenario? Where a composition of scenarios and mitigations relevant to a use case would be the model?

Re: How to open a safe

#82

I can't even imagine what happened here. I do quite a bit of coding on front panels like this for my job engineering industrial controls. Even without the need for security, I wouldn't allow a front panel to make decisions. It has only two jobs, to accurately display what it is asked to and to report in a timely manor what keys have been pressed. Doing more than that is not only unnecessary, but it reduces the abilit…

This boggles my mind for a different reason. I can't understand why would they design the lock to be so shitty. They're saving probably a miniscule amount of money required to upgrade the lock's design to "barely decent" in exchange risking lawsuits and reputational damage. I really don't get it. The amount they save cannot possibly justify the product being such a clusterfuck.

Re: How to open a safe

#83
post #39

Earlier quoted context omitted.

It's a vulnerability in the inside panel that was covered up by requiring the front panel to do more than it should. If the front panel were just a dumb I/O device, the inside panel could not have this specific vulnerability.

No that's still wrong. The inside panel is the only thing doing any validation. The front panel more or less is dumb IO. The vulnerability really is in the inside panel and changing the outside panel to just be a keypad wouldn't have prevented the mistake.

No, you're misunderstanding. The front panel is validating that the factory code is entered correctly before it allows the lock code to be reset. If the front panel were just dumb I/O, the inside panel would have to validate the factory code before allowing the lock code to be reset.

Re: How to open a safe

#85
post #84

Earlier quoted context omitted.

Kwikset's SmartKey deadbolts are very common in hardware stores, and quite difficult to pick.

Interesting. I hadn't heard about them.

They're "purple belt" rank for the reddit /r/lockpicking belt ranking system[1]. That rank's description is "You are now picking locks that are categorically hi-sec. They have two or more discrete locking mechanisms and are considered unpickable by nearly every locksmith on the planet. You are helping new pickers frequently and sharing challenge locks."

The SmartKey locks have two major flaws: a tiny endoscope camera can view the positions of the sliders and allow visual decoding of the correct position of each one independently (very specialized expensive equipment, about $350[2]), and it's possible to stick a shim in between the cylinder and body of some of the locks to tension the sidebar directly. Without a way to tension the sidebar it's extremely difficult to get any feedback.

[1] https://www.reddit.com/r/lockpicking/wiki/beltranking#wiki_r...

[2] https://www.lockpicks.com/catalog/product/view/_ignore_categ...

Post reply on HN