Sponsors

Are safe locks a myth ?

Posted by Darshan Patil Tue, 26 Sep 2006 16:31:00 GMT

Security is hard to achieve. It is always good to secure things be it computers, your network and even your house. It is good to guard against most breaches. However, if someone really wants to breach your security system, they will succeed. You have raised the barrier to entry but there is still a small group of individuals who can breach it. Take this video for instance. It shows a group of individuals open locks using a technique called bumping. I’ve seen this done before by a locksmith but this video shows normal people doing it. It is unbelievable how simple it is to open locks with this method.

In this method, a key blank that fits the target lock is specially cut, with the shoulder of the key filed down to allow the key to be inserted slightly farther into the lock than normal. The key is inserted into the target lock to normal depth, and by striking the head of the key while applying slight torsion, the lock can be opened in seconds. This technique leaves no sign of forced entry.

Now I would not go out and say, locks are useless. They do serve their purpose. However as this video shows hiring the right people or knowing the right skills can render the lock useless.

Stay safe.

References:

  1. Bumping
  2. MIT Guide to lock picking

Hacking ATMs for fun and profit

Posted by Darshan Patil Sat, 23 Sep 2006 02:24:00 GMT

ATMs are all over the news now. Recent events have caused them to be thrust in the spotlight. I read about this first in this article.

Hacking an ATM is very simple.
  1. Find an ATM
  2. Look at the model
  3. Search the internet for the manual for that model
  4. Read the manual
  5. See how you can enter the machine’s administration mode
  6. Enter the administration mode. Do stuff

I don’t blame the manufacturers for having super easy default passwords on the machines and easy ways to get to the admin mode. Most of their clients are greedy, dumb store owners who want to install one of these so they can make money off the hefty transaction fees. Come to think of it I’ve paid $15 once for ATM fees. Ridiculous ! These ATM machine owners are supposed to change the password when they get the machine, but most of them don’t because they dont bother to read the manual. All they want is the machine to work and earn them some income. Its just like asking your average computer user to keep changing passwords. They don’t. Most of the times its mainly because everyone thinks, who is going to target me ? Anyway back to the article.

Here is a video of how it’s done.

Now kids at home, do not try this or try to get your hands on one of the manuals. I am not posting links for the manuals because obviously if you are dumb enough to try this, you are dumb enough to get caught.

Even after all these recent incidents, the ATM vendors haven’t taken their manuals offline. They are all freely downloadable. I found a manual in about 10 minutes of searching.