Archive for the ‘Lockpicking’ Category

Lock Picking Forensics

Wednesday, October 6th, 2021

I (Walter) have created a geocache that requires some RSA hacking and subsequently lockpicking. I bought an Abus Titalium 64TI/40 padlock to be picked. Several people were able to find it by teaming up together. The feedback I got was that people spent considerable time on the lock, sometimes several hours (in separate sessions).

Geocacher #15 was unable to lockpick the lock, even though he had practiced on an identical lock at home. I offered to go with him to give advice. He couldn’t open it. Also I couldn’t (quickly) open it. I took the original key and that would not open it. By not fully inserting the key and wiggling, I succeeded in opening. (I let the geocacher pick his own lock and allowed him to log the cache.)

Once home, I decided to take a look at the lock. Although only a very limited number of people had worked on it, it was completely shot. I took a video comparing showing a new padlock and then the one from the cache:

I’ve taken apart the lock to have a look at the pins. We always say that picking a lock will leave tiny traces on the pins (and other parts of the lock) that can be found during a forensic investigation. Well, in this case, the naked eye was enough to see the abuse.

Here’s the plug with the key inserted. Note how the pins have shortened. This causes the key to no longer work.

This also explains why taking out the key a bit and wiggling opened it.

Here’s a view of the pins:

There’s now a new padlock in place. You can’t really tell from the picture here, but the pins are made out of aluminium, which kind of explains the wear on them. I bought the lock as it is marketed as being weather proof. But resisting weather is different from resisting lockpicks.

Photos/video CCBY4.0 Walter Belgers

Book review: Little Black Book of Lockpicking

Thursday, September 30th, 2021

Two weeks ago Alexandre “FrenchKey” Triffault published the book Little Black Book of Lockpicking on NDE techniques for Red teams and security professionals. The book has 171 pages with a broad variety of lock types and opening methods, from lockpicking to impressioning, and from making cutaways to decoding combination padlocks.

Whenever there is a new book about lockpicking I pick up a copy especially when it’s written by a friend. It sold for €35 Amazon that does the printing and distribution of this book. The book is a good read and is a continuation of the OFC guide to lockpicking (free pdf) that’s also written by Alex and translated by MrAnybody. The OFC guide is all about lockpicking while this book includes many more topics including bumping and impressioning, both topics I’ve paid extra attention to.

The first thing I noticed was the many high detailed graphics used. Alex modeled the locks, lockpicks and other tools and included 3D renderings in the book as virtual cutaways. The style works very well for this book. It does not just write about a concept but also shows how it is done.

The book is 27 chapters and on average six pages for each subject, this inevitably means there is not too much room for details or nuances. This is a pity as Alex has the ability to give insights I would never think of.

I want to mention that the advanced topics in the book like (self) impressioning will take a long time to get good at. For me, I’ve experienced it takes many failed attempts to do these attacks, even in a controlled environment. Attacks like self-impressioning took me a very long time to make work. I can only imagine how it would be to attack doors on an assignment.

This is one of the better books on the basics of NDE and I recommend getting a copy for yourself or to to share. When you share the book, do keep in mind the book is written for red teams on an assignment and not for hobbyists. It is never a bad thing to give a small lecture on the locksport ethics and our view on locks as a puzzle with the book.

Wooden lock; Binding order demo

Sunday, May 23rd, 2021

In 2019 Jan-Willem build a binding order demo out of laser cut wood.
In this post we would like to share the project with the rest of the world.

Binding order is the order in which the pins bind in a lock. This is mostly due to the manufacturing tolerances but can have other causes. This concept is hard to grasp for a new lockpicker and is one of those ‘You’ll get it when you see it’ concepts. When teaching lockpicking it is common to hear: ‘I have been pushing down this pin and it doesn’t want to stay down.’ This tool can be used to demonstrate why the pin did not want to stay put.

This demo is certainly not ‘the’ solution. It is just a fair attempt that works for us. It will make the explanation better by adding both the visual and touch to the explanation. The participants can play with the board and feel the effect of binding and what the effect is of using light or strong tension.

For reference: The board is about the size of an A4 piece of paper. The base is crafted from three layers of 3mm plywood. The core is a single sheet and the pins are three or four layers, depending on the feel you prefer. Each pinhole in the base/core has a different size and different offset. All of the pins are a different size er well. This gives plenty of options to change the binding order.

We used the demo in lockpicking villages across the globe. We have found that it helps the explanation immensely when encountering language barriers. Video link to how you can use the binding order demo: https://youtu.be/WiCdws84EuQ

The binding order in this model can be quite subtle. It would great to have another with extreme exaggerated binding order also a smaller, 3D printed version, would be great to have. A bit of paint will not hurt either.

CC-BY-4.0 Jan-Willem Markus Toool Blackbag.

Lock pin collection

Friday, March 19th, 2021

In a previous blog post Jan-Willem’s pin collection was mentioned. In this post the pictures of the pins and keys are shared.

There is no epic conclusions to this project. At this moment it’s is just a collection of photos of locks and pins. Shared with the world. Hopefully it’ll be a resource for new pickers that would like to know what they are up against. Maybe future research will use it. Where someone clever uses the fact some spools are different than others to decode the lock. Sputnik comes to mind and we think the possibilities are not exhausted yet. (If you are working on something I’m happy to assist.)

New pickers, don’t be intimidated by the key or keyway. If you look through the collection much of the pins are underwhelming. Where a Evva is known to be difficult lock it was not expected to find all standards or one spool pin. When struggling with a lock just take it apart and see what’s in there. For the next time you encounter the same lock you will know Nemef has a spool on position two (insider joke).

This collection has a few obvious biases:

  • The collection only contains basic pin tumblers.
  • Most locks are from Europe, and are from well known lock brands.
  • The locks are not too expensive and are usually old. Therefore it lacks fancy pins like gins and Christmas trees.
  • Pins/locks that are too similar are rejected. There are some duplicates as well.
  • This is a snapshot in time. The pinning of the locks change every few years. A good example is DOM RN with two different types of pins in this collection.

If you have specific knowledge on these locks. Please share, we are open to learning more about locks. Find us on Discord, leave a comment or send us an email.

The photos are: key, pins, key, pins. The photos of pins are arranged with the brand and number. The keys have ‘key’ in the name. The Titan with a key engraved D5474 will have the pictures: TitanD5474-1key-1-scaled.jpg and TitanD5474-1-1-scaled.jpg.

The pictures are by Jan-Willem Markus. CC BY 3.0. https://creativecommons.org/licenses/by/3.0/
In short: you are free to use, modify and share these photos as long as you give attribution. If you plan on selling them or using hem in a blog/paper/book please notify us.

The end.

Lockpicks for Hackerspaces

Tuesday, December 3rd, 2019

Post by: Jan-Willem
I’ve recently acquired ~20kg lockpicks, 4000 lockpicks. These where sold by a scrap metal dealer on eBay. As why he had them I can only guess. He did well for not scrap these. The picks are a bit rusty and need work to be useable. As you can imagine cleaning them all by myself will not be fun. There for I decided to sell most of them and give some away. (Yes, this project is not what a sane person would attempt.)

I’ve sold bags of 500g at LockCon. Most will be used at lockpicking villages around Europe. With the remaining picks I’ve created grabbags of about 250gram (50 picks) for the Dutch Hackerspaces. Because every Hackerspace needs lockpicks.

Lockpicks, ~4000 of them!
Lockpicks packed and labelled. Ready to be shipped by Hackermail (Inter-hackerspace delivery service)

The full story can be found on: https://bitlair.nl/Projects/Lockpicks_for_Dutch_Hackerspaces Happy picking!