Full Disclosure mailing list archives
Lock business practices "security-by-obscurity" for 150 years
From: "Richard M. Smith" <rms () computerbytesman com>
Date: Thu, 23 Jan 2003 10:13:00 -0500
http://www.nytimes.com/2003/01/23/business/23LOCK.html?pagewanted=print& position=top January 23, 2003 Master Key Copying Revealed By JOHN SCHWARTZ A security researcher has revealed a little-known vulnerability in many locks that lets a person create a copy of the master key for an entire building by starting with any key from that building. The researcher, Matt Blaze of AT&T Labs-Research, found the vulnerability by applying his area of expertise - the security flaws that allow hackers to break into computer networks - to the real-world locks and keys that have been used for more than a century in office buildings, college campuses and some residential complexes. .... The technique is not news to locksmiths, said Lloyd Seliber, the head instructor of master-key classes for Schlage, a lock company that is part of Ingersoll-Rand. He said he even taught the technique, which he calls decoding, in his training program for locksmiths. "This has been true for 150 years," Mr. Seliber said. Variations on the decoding technique have also been mentioned in passing in locksmith trade journals, but usually as a way for locksmiths to replace a lost master key and not as a security risk. .... _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Lock business practices "security-by-obscurity" for 150 years Richard M. Smith (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years Chief Gadgeteer (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years Georgi Guninski (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years hellNbak (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years Kevin Spett (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years David Howe (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years hellNbak (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years eecue (Jan 23)
- Re: Lock business practices "security-by-obscurity" for 150 years Brian McWilliams (Jan 26)