Live data from Hacker News

Tourist's lucky guess cracks safe code on first try

bbc.co.uk

41–50 of 118 posts

Re: Tourist's lucky guess cracks safe code on first try

#41

Reminds me of the time I was playing a computer game, and right at the beginning you are presented with a door 5-digit combination lock. The objective of the game was to explore the game world and eventually discover all 5 digits of the code. First time I played the game I just randomly entered 5 digits, and the door unlocked.

Myst series?

That's what came to my head too. It still took me many hours more game play to find out WHAT I had unlocked and what to do with it.

Re: Tourist's lucky guess cracks safe code on first try

#42
post #2

A combination "20 - 40 - 60" on a dial that goes from 1 to 60... Sounds like an equivalent of a factory-default admin/admin login credentials. I wonder if it really was the default combination that the safe was bought with, and the owners never bothered to change it. :)

> A combination "20 - 40 - 60" on a dial that goes from 1 to 60... Sounds like an equivalent of a factory-default admin/admin login credentials. The article explains that it was a common combination for people to use on this type of safe - "Typical combination lock, three times clockwise - 20 - two times counterclockwise - 40 - once clockwise - 60, tried the handle and it went".

So that's a quote from the museum visitor who opened it. I don't think he knew "common combinations on this type of safe". I think he was saying what was typical was the mechanism, three times clockwise [some number], two times counter-clockwise [some number], etc. Not the numbers.

We of course wouldn't have heard about it if it wasn't succesful. The real odds are "how many safes are there like this that people are trying all over the world, and what's the chance that someone at ONE of them would succeed." :)

Re: Tourist's lucky guess cracks safe code on first try

#43

1 in 216000... seems like you could build some robotic device to brute force that pretty easily... or you know, introduce it to a thermic lance. EDIT: sorry, my research suggests that safe-cracking with thermic lances is plausible but not practical (source; Mythbusters, of course)

Irrespective of how practical thermic lances are, the likelihood that there would be something more valuable inside the safe than the safe itself was low (that’s also confirmed now by the actual contents of the safe) and that’s probably why destructive opening of the safe was never even considered.

The safe itself was the exhibition piece that was valuable to the museum. Destroying it just to get at its unknown but probably boring contents would have been pointless.

Re: Tourist's lucky guess cracks safe code on first try

#45

If the combination does allow for wiggle room and the 1 in 8000 figure is correct, the code could have been brute forced in a couple hours. Source: my wife has a habit of forgetting the combination to her 3 digit luggage lock and I had to brute force it a few times (it's surprisingly quick, about 15 minutes) :)

I bruteforced a 4-digit 2FA in 2 days, of course with the help of a small script instead of trying it myself. It's always fun to see dumb solutions work.

if it works, it's not a dumb solution :)

Re: Tourist's lucky guess cracks safe code on first try

#46

> "They have no value really, but they are of great interest to us. It gives us a little bit of idea of what the places were like in 1977, '78," said Mr Kibblewhite. This must be the most American thing ever. 40 year old stuff treated like they're ancient.

There used to be a joke along the lines of "In Europe people think a 100 miles is a long distance. In the States people think a 100 years is a long time".

Re: Tourist's lucky guess cracks safe code on first try

#47

If the combination does allow for wiggle room and the 1 in 8000 figure is correct, the code could have been brute forced in a couple hours. Source: my wife has a habit of forgetting the combination to her 3 digit luggage lock and I had to brute force it a few times (it's surprisingly quick, about 15 minutes) :)

I had this in university - when I started some documents I needed were delivered to my uni mailbox which was guarded by a code, but we weren't due to get our code until we had completely "matriculated" (signed in, got our IDs, etc). So I just sat down with a couple of beers and set out out to try all 9999 combinations (it was thankfully in the 2000s or so).

Made me realise that my university mailbox wasn't actually that secure ...

Re: Tourist's lucky guess cracks safe code on first try

#49
>The museum had previously enlisted the help of experts to crack the code

since they have (essentially) infinite time, why couldn't they attach a machine that tries all possible combinations? feels like something that someone from the high school robotics club could come up with.

Post reply on HN