5 ms·
> I am not sure if I would call trying all combinations "picking s lock" Lockpicking is defined as opening a lock with an instrument other than the appropriate
by bryans 4y ago
> I am not sure if I would call trying all combinations "picking s lock"
Lockpicking is defined as opening a lock with an instrument other than the appropriate key. It is not defined by how many attempts it takes. Many of the most common lockpicking methods are nothing more than brute force, which are sometimes incredibly effective. They're also sometimes the opposite of effective, meaning they may take many thousands of attempts before stumbling upon success. That doesn't disqualify them from the definition of lockpicking.
> You could also bring all 46k key variations and try them out [...] but that would not make the lock pickable if I was to talk about it.
The entire point of lockpicking is that you don't need to make every key combination, and instead only need a small set of tools or a single device. The personal decision to make every key instead of using another method, doesn't mean the lock isn't pickable, it just means you spent a lot of time making keys. You could also make all of the keys for a basic $1 padlock, but that padlock is still pickable with a paperclip. It didn't become unpickable by creating the keys.
> I have no clue about locks, but there's a difference between brute forcing a password and decrypting it from the hash.
Yes, the difference is that one will definitely take longer than the other, but you don't actually know which until you've successfully completed the task. They're both still password cracking methods with the same end result. One doesn't magically stop being a cracking method just because it takes longer.
- necovek 4y agoMy point is that every single lock (or password) is susceptible to trying every key combination: the only protection against that is to increase the number of combinations available. Sure, if a particular lock is more prone to brute-forcing due to its design than an average lock (eg. side channel attacks like timing attacks with passwords), one could surely qualify that as a pickable lock (or a "weak" password scheme). So I am not saying that a brute-forceable lock is not pickable, but that those are independent since every lock is brute-forceable. Sure, devil is in the details, and what seems like brute forcing is sometimes something smarter, but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock. Again, maybe I am totally off base with regards to terminology as used in lock picking circles, but this is how I would differentiate between different approaches.
- bryans 4y ago> I am not sure if I would call trying all combinations "picking s lock" [...] that would not make the lock pickable if I was to talk about it [...] but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock. [...] So I am not saying that a brute-forceable lock is not pickable You quite literally said it's not pickable and not even lockpicking at all, and have even reiterated as much in this new comment, so please don't pretend otherwise. > but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock. All of the dictionaries and an entire industry of professional locksmiths disagree with that statement. Given that you've twice admitted to having "no clue about locks," I'm not sure why you continue to insist that uninformed personal opinions are somehow factually obvious. > Sure, if a particular lock is more prone to brute-forcing due to its design than an average lock (eg. side channel attacks like timing attacks with passwords), one could surely qualify that as a pickable lock (or a "weak" password scheme). You keep trying to apply the concepts of digital authentication to locksmithing, but they're just not applicable in the way you're describing. The "average lock" doesn't exist, and certainly can't be used as a basis for determining the threshold of whether an entirely different lock qualifies as pickable. As far as I can determine, your opinion boils down to believing that successfully brute-forcing a lock with only 100 possible combinations does qualify as lockpicking, but successfully brute-forcing a lock with 1,000,000 possible combinations somehow doesn't qualify as lockpicking. I'm not sure how that position is justifiable, made worse that the lock being discussed is notably prone to brute force and within a very reasonable amount of time. So, if "weakness" is your qualification for a lock being pickable, then you're arguing against your own assertion that this lock is unpickable.
- necovek 4y ago>> So I am not saying that a brute-forceable lock is not pickable > You quite literally said it's not pickable and not even lockpicking at all I think you have a problem with me communicating using (formal) logic. If I say that A (lock is brute-forceable) is true, I am not making a statement on whether B (lock is pickable) is true: it could be either true or false. When I say that B is not true when A is, it means that B does not follow from A. As an admittedly non-expert, I find it useless to consider something that's a tautology (always true, lock is bruteforceable) as a special skill (lock-picking), and I complain of the terminology. IOW, it is my personal opinion that this is a useless terminology if it's used like that. > As far as I can determine, your opinion boils down to believing that successfully brute-forcing a lock with only 100 possible combinations does qualify as lockpicking But I explicitly clarified my position, and you even quote that twice: > but only when you are able to reduce the problem space from the full set of combinations would I say you are picking a lock. Which means that a lock with 100 combinations, and you try all 100 of them, you are not lock picking, but if you reduce that to trying out 50 combinations, then you are (again, I hope I don't have to highlight how this is my opinion of the terminology: I am repeatedly claiming I am no authority, but I can still have an opinion on language, along with the argument I am presenting). I apologize if my use of somewhat general language confuses you: my background in formal maths influences the way I communicate sometimes.