Live data from Hacker News

Enclave: An Unpickable Lock

ominoushum.com

291–300 of 328 posts

Re: Enclave: An Unpickable Lock

#291

Earlier quoted context omitted.

To counteract brute-forcing, how about adding a rate-limiting mechanism? I could imagine each attempt to rotate the cylinder could partially compress a spring-loaded lever. There could be some sort of ratcheting return mechanism that allows the spring to decompress at a known rate (think a kitchen timer). Once the spring is compressed beyond a certain point (e.g. after 5 failed attempts), a mechanism locks out the cy…

Sounds like an interesting way to get locked out of your house. You would need successful uses of the key to reset the ratchet or every 5 times you opened your door it would become inoperable for 10 minutes, assuming the spring for the timer hasn't rusted or got a bit of grit in it or whatever.

Revised:

- Each [failed] attempt to rotate the cylinder could partially compress a spring-loaded lever.

- The return mechanism would always return if not in its resting position, not only after each 5 failures.

- Successful attempts immediately reset the spring.

Re: Enclave: An Unpickable Lock

#292
post #271
post #246

Earlier quoted context omitted.

No, that won't work, because the pins cannot be bumped once the lock is partly turned.

Why not? Vibrations can travel through solid metal. You might be able to make a custom tool that sends vibrations through the core enough to cause the wafers to move up and down even if the core is turned.

The bump key hits the lower pins, which move the upper pins. This is not possible with the Enclave design.

You really cannot move the pins by vibrating the entire lock. The pins are so light that you would need tens if not hundreds of g of acceleration to overcome the spring force.

Re: Enclave: An Unpickable Lock

#293
post #70

Earlier quoted context omitted.

The interaction of engineering and "use" by the Lock Picking Lawyer ( https://youtu.be/Ecy1FBdCRbQ ) was fascinating - "use" here really meaning "exploiting". It's a problem many here are aware of, either by over-engineering things intended for use by non-engineers, or designing things to be used by customers when the designer isn't intimately familiar with the use. In this case it was sort of somewhere in between. I…

I can't be bothered to use YT anymore with all the ads. They're basically interactive, on-demand, corporate TV monetizing other people's content and nothing more. The world needs a co-op video sharing app and a microblogging app.

or just pay to avoid the ads?

Re: Enclave: An Unpickable Lock

#294
post #283

Earlier quoted context omitted.

My point is that every single lock (or password) is susceptible to trying every key combination: the only protection against that is to increase the number of combinations available. Sure, if a particular lock is more prone to brute-forcing due to its design than an average lock (eg. side channel attacks like timing attacks with passwords), one could surely qualify that as a pickable lock (or a "weak" password scheme…

> I am not sure if I would call trying all combinations "picking s lock" [...] that would not make the lock pickable if I was to talk about it [...] but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock. [...] So I am not saying that a brute-forceable lock is not pickable You quite literally said it's not pickable and not even lockpicking at all, a…

>> So I am not saying that a brute-forceable lock is not pickable > You quite literally said it's not pickable and not even lockpicking at all

I think you have a problem with me communicating using (formal) logic.

If I say that A (lock is brute-forceable) is true, I am not making a statement on whether B (lock is pickable) is true: it could be either true or false. When I say that B is not true when A is, it means that B does not follow from A.

As an admittedly non-expert, I find it useless to consider something that's a tautology (always true, lock is bruteforceable) as a special skill (lock-picking), and I complain of the terminology. IOW, it is my personal opinion that this is a useless terminology if it's used like that.

> As far as I can determine, your opinion boils down to believing that successfully brute-forcing a lock with only 100 possible combinations does qualify as lockpicking

But I explicitly clarified my position, and you even quote that twice:

> but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock.

Which means that a lock with 100 combinations, and you try all 100 of them, you are not lock picking, but if you reduce that to trying out 50 combinations, then you are (again, I hope I don't have to highlight how this is my opinion of the terminology: I am repeatedly claiming I am no authority, but I can still have an opinion on language, along with the argument I am presenting).

I apologize if my use of somewhat general language confuses you: my background in formal maths influences the way I communicate sometimes.

Re: Enclave: An Unpickable Lock

#295

I designed something like this before. Multiple shear lines with a two stage isolation-then-check is intuitive. The details matter, though, and this looks clean. I could see it manufactured. My design tried to avoid it being possible to interact with any of the components storing the code before the pins are isolated. I did this by having two styles of pins (normal vs. T-shaped), and an insertable bar in a specially-…

Multiple shear lines with a two stage isolation-then-check is intuitive. The details matter, though, and this looks clean. I could see it manufactured. Yes. If you're willing to have a really big lock, it's much easier to make room for a two-stage mechanism where the keying info is stored before use. I'd thought about a lever lock like that, but the thing would need a huge box in or behind the door. There's a possibl…

My design just used grooves cut into the cylinder, which the two pin types would ride at different heights, so it didn't need to be any bigger.

An insert, aka. a rectangular metal bar with cuts in it, is inserted into a slot cut down the side to define the check key.

The pins are either a standard pin, ⣿⣿, or a T-pin, ⢹⡏. The core is cut all around with a groove like ⣿⣆⣰⣿, which they ride at different heights.

If the insert is shaped like ⣿⣶⣶⣿, it blocks the T-pin, but the standard pin can ride over the top. If the insert is shaped like ⣿⣇⣸⣿, the T-pin rides through the gap, but the standard pins catch.

Again, details like depth and offsets matter, because you don't want it to be bumpable with fast or angry rotations, or for the two pin types to lock at distinguishable offsets, and you don't want it to be jammable. Boring standard fixes can deal with comb attacks.

Enclave, OTOH, does need a bigger body, but it's merely a bit taller, nothing radical, and it's very easy to manufacture. It already has inserts to prevent comb attacks.

Re: Enclave: An Unpickable Lock

#296

Earlier quoted context omitted.

LPL is not a locksmith, he practices lockpicking as a sport. And evidently extremely good at it.

Has he won any tournaments? I'm not too familiar with the sport sorry.

Yes

https://www.youtube.com/watch?v=Avn7ABVHPYk

Re: Enclave: An Unpickable Lock

#298

Interesting design. I made a lock a couple years ago that is quite similar in principle (though this design is different and has a couple nice improvements). https://youtu.be/_7vPNcnYWQ4 One of my main goals is to be an inspiration, though if it was based by my design I wish they’d credit it. Especially since they’re patenting it.

I loved the way the puzzle was presented in that video and loved the partial solution. It has been consuming idle brain cycles eversince.

First we should proudly make the key flat as security by obscurity is not done. We should solve the problem for real and it has to be easy to manufacture.

The real idea: put a tube around the cylinder. after rotating the cylinder by 45 deg it drags the tube along.

  [cylinder][ tube ][case
   key]||||||||[   ][     ]////
  [cylinder][ tube ][case
you have a pin in the tube with small discs on the key side. The inner cylinder can rotate freely for 45 degrees at which point it drags the tube along IF the pin is in the correct position thereby testing the correctness of the key used therein all pins simultaneously.

different keys can be had by changing the number of discs. No machining required.

Have fun

Re: Enclave: An Unpickable Lock

#299

Earlier quoted context omitted.

Except this isn't a constant time comparison. You still reach the "no more turning" angle at whichever pin is incorrect first. This is more like forcing the password to be fully retyped after each failed attempt. A good feature, but not a feature which eliminates side channels which might be there.

There's still no direct way to detect which pin blocks it from opening. Maybe you could determine if the failed pin is the same as a previous attempt by listening with a stethoscope, or very finely measuring the turning angle, but you can't directly feel out which pin. So there may still be a way to reduce the search space in theory, but that attack still seems very difficult to pull off, and for the complexity it se…

Well, it didn't advertise itself as a "very difficult to pull off lock", or a "vastly better than previous lock". It advertised itself as an "unpickable lock". That's a very strong claim to be making. I wouldn't be satisfied with anything less than a proof that it is impossible to reduce the search space down to sub-exponential.

Building a lock which does not leak any information about what's happening inside is equivalent to building a mechanical, room temperature quantum computer. For if that information isn't leaking to the environment in some way, there is no mechanism to decohere a superposition state. Hence in principle a mechanical lock which is secure in the information theoretic sense is impossible. It is still theoretically possible to make a computationally secure lock (eg a mechanical implementation of a hash function). But there's currently no real proof that one-way functions are actually one-way. The security of such a lock is subject to a foundational guess in cryptography.

Re: Enclave: An Unpickable Lock

#300

Interesting design. I made a lock a couple years ago that is quite similar in principle (though this design is different and has a couple nice improvements). https://youtu.be/_7vPNcnYWQ4 One of my main goals is to be an inspiration, though if it was based by my design I wish they’d credit it. Especially since they’re patenting it.

I loved the way the puzzle was presented in that video and loved the partial solution. It has been consuming idle brain cycles eversince. First we should proudly make the key flat as security by obscurity is not done. We should solve the problem for real and it has to be easy to manufacture. The real idea: put a tube around the cylinder. after rotating the cylinder by 45 deg it drags the tube along. [cylinder][ tube…

Extra funny would be a second tube with a clock mechanism that delays a second attempt if the wrong key is used.

(Going to implement that one on all my enter password pages.)

Post reply on HN