3 ms·
No, this is different. What you are talking about are things like bump keys which exploit known physical limitations in those types of locks in general. There
by pravus 3y ago
No, this is different.
What you are talking about are things like bump keys which exploit known physical limitations in those types of locks in general. There is no way to fix this other than switching to an entirely different internal mechanism.
What is being discussed here is the intentional disabling of existing security features within a locking mechanism which further reduces its effectiveness. This is regardless of the effectiveness of the class of lock overall.
An example would be going to the hardware store and buying a 7-pin tumbler lock but only 5-pins are installed. Yes, all tumbler locks are vulnerable to bump keys but an additional hidden (and fraudulent) act was performed which further compromised my wishes for a "more secure" tumbler lock.
In the case of cryptography, the locks are much stronger and there is vastly more at stake so it's important not to be too casual with the analysis. The 'fix' is to remove all doubt that any such malfeasance ever took place.
- lazide 3y agoEh. I'm not sure it's so different. For instance, security pins are inexpensive and dramatically increase picking difficulty while not impacting costs by more than a few cents/unit (at most!) or maintenance concerns by any noticable amount. The all plastic logout/tagout masterlock [https://www.amazon.com/Government-Safety-Lockout-Padlock-Zenex/dp/B00192092C/ref=sr_1_1?crid=PCAE426Z5GIB&keywords=masterlock%2Blockout%2Btagout%2Block&qid=1690218938&sprefix=masterlock%2Blockout%2Btagout%2Bloc%2Caps%2C135&sr=8-1&th=1 https://www.amazon.com/Government-Safety-Lockout-Padlock-Zen...] for instance has all security pins and is a real challenge to pick for most folks (including myself!), and makes it much harder to bump too. It isn't sold as high security. It's cheap, but also has a brass core and brass security pins, etc. so it's not like the core is skimping on things, or could be a major cost. The total (retail!) cost of the lock is a fraction of the 'high security' locks, even though those locks are much much easier to pick and bypass. The masterlock 'high security' pro series locks didn't have any security pins at ALL and were super easy to pick (or bump, likely) up until VERY recently. By very recently, I mean I just saw it when I checked out their current lineup - and a year or two ago they definitely did not have it!. It looks to have a SINGLE spool pin in it. They're now heavily promoting it as 'bumpstop' tech. I'm guessing LPL or similar finally made some sort of impact, or maybe word of mouth after contractors have all their shit stolen. Similar locks sold by the 'American Lock' brand (same ownership now) has always had at least one security pin, usually 3 in even their most basic padlocks for as long as they've existed I believe. 100 years? And that isn't even talking about bypasses which maybe fit what you're describing better. Many of the common commercial and residential locks sold today still have trivial bypasses or decoding that can be done with some practice in seconds by tools sold online. Such as this bad boy [https://www.amazon.com/Master-Lock-M40EURDNUM-Combination-M40EURDNUM-Best/dp/B00HUWZRS6/ref=sr_1_5?crid=2Q3JM32Z9LT96&keywords=masterlock+combination+lock+high+security&qid=1690219317&sprefix=masterlock+combination+lock+high+securit%2Caps%2C126&sr=8-5 https://www.amazon.com/Master-Lock-M40EURDNUM-Combination-M4...] And that is just the tip of the iceberg. Is it fraudulent? Eh... there is no real concrete definition for 'high security'! And fraud doesn't include 'mere fluffery' either. Masterlock certainly isn't claiming TR/TL-30 ratings on any of their stuff! These issues however have been widely known about in some cases for 50-100 years or more. For instance, doing some random googling I ran across this patent [https://patents.google.com/patent/US917365A/en https://patents.google.com/patent/US917365A/en] for pin within sleeve technology to work around that whole basic pin-tumbler picking issue (from 1908!), and at least according to this random website, spool pins were invented in 1865 by Yale himself, shortly after the first pin/tumbler locks were invented [https://www.art-of-lockpicking.com/security-pins/ https://www.art-of-lockpicking.com/security-pins/]! The patent expired so long ago, it is absolutely laughable to not use them, and it's definitely ridiculous for a pin-tumbler lock to not have at least ONE! If not have all but one of them spool or similar! I have a hard time seeing how that is any different than selling a secure system with an 80 bit crypto key where the 'secret algorithm' nukes all but a handful of the bits in a predictable way. Or like in the case of well known lock bypass exploits, where there isn't a way to poke the low level protocol to get it to set a known key value and let you take over. I think what you're getting at cryptography wise, is that unlike most physical locks, the vast majority of cryptographic usage is for data that there is no plausible way to have any confidence the cyphertext wasn't read by some unknown (and actively malicious) party. Bits can be copied perfectly, and stored essentially indefinitely without degradation and at low cost. And often, where the data is even public (or public like - with no way to control access). And no plausible way to have confidence that it hasn't been copied and someone isn't working on it right now. And no plausible way to have confidence that this wasn't being done on a massive scale, to nearly everyone, all at once. Even if someone picks a lock to an ATM, for instance, someone has to physically be there and spend actual time when they are at risk to pick it. And there are security cameras and usually some kind of guard or bystanders that can visually identify when something weird might be happening and intervene. That dramatically changes the actual risk profile and ability to extract value. The majority of situations tech wise, there is no equivalent. It's relatively easy to splice into an underground fiber link going into/out of a datacenter with no one noticing and 'pick' every lock going by and extract whatever you want from it with no one being able to tell for years. If ever. Frankly, there are also many reasons to be suspicious (or even know for sure!) that is actually being done, right now, by many parties. Some of which definitely don't have the data's 'owners' interests in mind. Most/All, if we're being honest, at least for them as individuals. Luckily, most of us don't seem to have anything worth stealing (individually), though in aggregate is another matter. And it would be a VERY tempting and VERY difficult to pass up target to not 'steal' all the interesting secrets from Congress and other powerful parties 'in the interest of national security' for instance. Especially the things not on official government computers. So I guess what I'm saying is - yes, it is absolutely critical to have good crypto. And yes, unlike a padlock guarding a shed, it has dramatically higher risks if it isn't actually a good lock - especially as we use it for banking, commerce, gov't, identity, etc). Especially since we need to be sure it will be good for the foreseeable future, because unlike a cheap padlock we decide to swap out when we figure out it's shit, someone can attack it and get what it was protecting potentially years or decades in the future. It's also in many parties interests to come up with reasons why people shouldn't have it (at least unless they're friendly/they like them), and there are a lot of market reasons why people won't notice or won't care until the problem is impossible to ignore and the damage is already occurring.
- rokkitmensch 3y ago[dead]