Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Lock-makers should start including RFID and a software key checking mechanism, then sharing the key would be illegal
  • I don't really "get" locks. If you want something to be closed forever, seal it shut. If it should be opened and closed, leave a hinge. If it should only be open and closed by a select few, leave it in a trusted environment

    Don't you live in a good neighborhood?

  • > sharing the key would be illegal

    How so? And what region are you referring to? There are many countries in the world with vastly different laws.

  • What criminal mastermind could possibly defeat the DMCA? :D
  • Could you make access illegal using the DMCA, by putting some copyrighted content inside, with the physical key also being the license key?
  • 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
    by dcan
  • Here in Finland mechanical locks with electronic keying are pretty common in some places. Some of them like iLOQ or Abloy eCLIQ are actually pretty clever: electrical bits of the lock are powered from mechanical action of inserting and turning the key, so you don't have to worry about batteries. In theory, they promise significant cost savings in scenarios like rental apartment buildings where tenants move in and out, need access to common areas, lose keys, etc, without compromising security or having to replace or recode locks - they just give you a generic key, click some buttons in the admin panel, and your key could be provisioned accordingly once you first enter the building and interact with one of the "smarter" locks that are externally powered and networked to the mothership.

    In practice, in addition to the usual bugs you would expect from a software-based system managed and maintained by a plethora of organizations and contractors, they tend to become very annoying as parts wear out, so you have to fiddle with the key reinserting it repeatedly trying to find just the right angle so it will make a good contact to be recognized by the lock (for example the iLOQ system by my landlord communicates over a thin contact strip molded into the key opposite of the cutting and separated from the rest of the key with a thin layer of plastic).

  • If a company’s first reaction to a flaw is to sue instead of fix it, the problem probably goes beyond the lock itself. A real security company would appreciate someone pointing out a weakness rather than trying to take the video down. That kind of openness would actually make people trust them more.
  • The weird thing is, they actually had someone competent dealing with the issue:

    > The strange thing about the whole situation is that Proven actually knew how to respond constructively to the first McNally video. Its own response video opened with a bit of humor (the presenter drinks a can of Liquid Death), acknowledged the issue (“we’ve had a little bit of controversy in the last couple days”), and made clear that Proven could handle criticism (“we aren’t afraid of a little bit of feedback”).

    > The video went on to show how their locks work and provided some context on shimming attacks and their likelihood of real-world use. It ended by showing how users concerned about shimming attacks could choose more expensive but more secure lock cores that should resist the technique.

    Sounds to me like someone professional in the company with a cooler head was on this and was handling it well, but someone else higher up got angry and aggressive and decided that revenge was more important.

  • One of my favourite lock pickers is Marc Tobias. He was also sued by a number of lock companies.

    https://www.youtube.com/watch?v=NadPAE6BDbA

    It is interesting to see that these companies still don't know about the Streisand Effect or they choose to think that it won't happen to them.

  • He just dropped a new video. Totally roasted the cunt out of that Easilok: https://www.youtube.com/watch?v=3lS5_6D4q9k
  • https://youtu.be/qL_MeobAp5s?t=1487

    For those interested in the actual case, here's some deeper coverage of this bruhaha including how Lee may have perjured himself during deposition.

    by c420
  • That guy sure isn’t in a hurry to get anywhere. Good one to watch at 1.25x speed.
  • If you don't know him already, I highly recommend videos by LockPickingLawyer — he routinely destroys bogus claims of various companies within seconds. It's quite entertaining to see how little security you actually get from most locks.

    I wonder if anybody tried suing him…

    by jwr
  • The fact that he is actually a lawyer probably helps greatly, both in terms of what he can legally do, and as a deterrence to others trying to sue.
  • If a lock takes more than 20 seconds to break it’s basically Fort Knox
  • > It's quite entertaining to see how little security you actually get from most locks.

    Physical locks are for honest people. They signify that something is not meant to be accessed and at best slow down someone actively trying to access the other side of the lock.

  • LPL is superb. He inspired me to get a lock pick kit and a few simple padlocks - a cheap and fun hobby during COVID lockdowns.
  • > It's quite entertaining to see how little security you actually get from most locks.

    Yeah, one of my conclusions after years of watching LPL is ironically to start buying cheaper locks.

    The difference between a $3 and a $300 lock is just about a minute of time for an experienced lockpick. No lock is capable of dissuading a determined thief, but any lock is equally capable of dissuading a lazy one.

  • LPL is a crown jewel of YouTube. His April Fools' Day videos are hilarious, too, like the one where he gets into his wife's beaver [0] (SFW).

    0: https://www.youtube.com/watch?v=TRozAbaKs9M

  • > he routinely destroys bogus claims of various companies within seconds

    I watched his video on high-security shipping container locks. Jeez, two minutes long? They must be tough!

    No, it was two minutes long because he bypassed ten of them, one after the other.

  • LPL owns Covert Instruments, who employs McNally, the YouTuber who got sued in this case. Probably not a coincidence that Covert Instruments wasn't named in the lawsuit.
  • This guy shims a $100+ lock in 10 seconds with a liquid death can, all without speaking in the video, just replays and then destroyed their claims and GTFO. Absolutely masterful.
  • The most absurd thing is the original video response from the company was good, and with a very compelling argument: their customers never saw shimming in the field. Their user base don't need shimming resistance: security needs to be adequate, not perfect. And they follow-up by presenting options about people requiring the lock to be shim-proof.

    Granted, in this day and age, it's a disgrace to still make locks that can be shimmed. Especially when the shim-proof alternatives they show just have an additional notch to catch the shim.

  • > their customers never saw shimming in the field.

    This is arguably good PR, but a terrible response. Shimming is so quick and hard to detect that even if you had 24-7 video of the lock, you probably wouldn't notice that the lock had been shimmed. You would just assume that someone lost a key.

  • Back in 2007, I published the first YouTube bypass of the Master Lock #175 (very common 4-digit code lock), using a paperclip.

    After the video reached 1.5M views (over a couple years), the video was eventually demonetized (no official reason given). I suspect there was a similarly-frivolous DMCA / claim, but at that point in my life I didn't have any money (was worth negative) so I just accepted YouTube's ruling.

    Eventually shut down the account, not wanting to help thieves bypass one of the most-common utility locks around — but definitely am in a position now where I understand that videos like mine and McNally's force manufacturers to actually improve their locks' securities/mechanisms.

    It is lovely now to see that the tolerances on the #175 have been tightened enough that a paperclip no longer defeats the lock (at least non-destructively); but thin high-tensile picks still do the trick (of bypassing the lock) via the exact same mechanism.

    Locks keep honest people honest, but to claim Master's products high security is inherently dishonest (e.g. in their advertising). Thievery is about ease of opportunity; if I were stealing from a jobsite with multiple lockboxes, the ones with Master locks would be attacked first (particularly wafer cylinders).

  • >if I were stealing from a jobsite with multiple lockboxes, the ones with Master locks would be attacked first (particularly wafer cylinders).

    If you were stealing from a job site you'd just bring bolt cutters.

  • Issues with master locks are hardly new- back in the 1980s, I downloaded a file from a BBS explaining how to open a combo lock (basically by pulling on the shackle while turning, and a few other tricks.

    It's still online: https://cdn.preterhuman.net/texts/anarchy_and_privacy_contro...

  • Actual thieves don't give a shit to learn lock picking, they can use a fine toothed sawzall or oxy-acetylene torch and defeat any lock just as fast without having to youtube the particular brand.
  • > Under questioning, however, one of Proven’s employees admitted that he had been able to duplicate McNally’s technique, leading to the question from McNally’s lawyer: “When you did it yourself, did it occur to you for one moment that maybe the best thing to do, instead of file a lawsuit, was to fix [the lock]?”

    Sometimes a single question tells you how the entire case is going to go.