Please create an account to participate in the Slashdot moderation system


Forgot your password?
Books Book Reviews

Book Reviews: Lockpicking Books From Deviant Ollam 123

benrothke writes "It is well known that the password, while the most widespread information security mechanism, is also one of the most insecure. It comes down to the fact that the average person can't create and maintain secure passwords. When it comes to physical locks, the average lock on your home and in your office is equally insecure. How insecure it in? In two fascinating books on the topic, Deviant Ollam writes in Practical Lock Picking, Second Edition: A Physical Penetration Testers Training Guide and Keys to the Kingdom: Impressioning, Privilege Escalation, Bumping, and Other Key-Based Attacks Against Physical Locks that it is really not that difficult. When it comes to information security penetration tests done on the client site, the testers will most often have permission to be inside the facility. On rare occasions, the testers need to find alternative means to gain entrance. Sometimes that means picking the locks." Keep reading to learn if you'll be picking locks soon.
Practical Lock Picking, 2nd ed. / Keys to the Kingdom
author Deviant Ollam
pages 296 / 256
publisher Syngress
rating 9/10
reviewer Ben Rothke
ISBN 978-1597499897 / 978-1597499835
summary Two excellent books on the fundamentals of lockpicking
All of the information in the books is long known to professional locksmiths. For those whose responsibilities include physical security, it is hoped that they are at least at the level of the locksmiths, and have designed their physical security plant accordingly.

Ollam is a member of The Open Organization Of Lockpickers (TOOOL), a group whose goal is to advance the general public knowledge about locks and lock picking. TOOL'S mantra is that the more that people know about lock technology, the better they are capable of understanding how and where certain weaknesses are present. This makes them well-equipped to participate in sport picking endeavors and also helps them simply be better consumers in the marketplace, making decisions based on sound fact and research. In these books, Ollam stays true to that mantra.

The two books have some overlap. Practical Lock Picking is meant as a beginners guide to lock picking, and is intended to be a hands-on guide with hundreds of pictures and diagrams.

Ollam writes in a clear-cut and systematic manner, describing all of the details needed. Nearly every page includes pictures and diagrams to illustrate the point. In 6 easily readable chapters, Ollam covers the core areas needed to gain a comprehensive understanding of the topic of lock picking. By the end of the book, you won't be a locksmith or even close. But for those that have locksmithing in their blood, or want to get greater insights, the book will be a great resource that will help them get there.

Chapter 1 starts the book on the fundamentals of pin tumbler and wafer locks; which are two of the most common types of locks in use. Ollam notes that while there are a multitude of lock designs on the market today produced by many different manufactures, the bulk of these locks are not in widespread use. With that, he notes that if the reader can understand the basics of just a few styles of locks, he is confident that the reader should be open top open with great east at least 75% of the locks they are likely to encounter, and even more as you become more skilled with them.

After the introduction, chapter 2 gets into the basics of lock picking and how to exploit weaknesses that most locks have. Many of these weaknesses are due to errors in the manufacturing process, which the book details. Information security guru has observed that "security is a tax on the honest majority". He writes that security often does not keep that bad guys out. Similarly, insecure physical locks will do little to keep the bad guys out, which Ollam so persuasively writes about.

In chapter 5, Ollam details what he terms quick-entry tricks, which is done via shimming, bumping and bypassing. Lock bumping has gotten a lot of media exposure in the last few years, but has been around for nearly 100 years. Specifically, it is a pin tumbler lock picking technique using a special bump key. Not that there is a universal bump key that can open all locks. Rather the bump key must correspond to the lock in question. Ollam shows that if one has such a key, many of these locks can quickly be compromised.

The book closes with an appendix that provides a list to the types of tools and toolkits necessary to pick locks.

After completing Practical Lock Picking, one should check out Keys to the Kingdom: Impressioning, Privilege Escalation, Bumping, and Other Key-Based Attacks Against Physical Locks, which is a great follow-on reference.

The main difference between the two is that the latter provides a lot of details on impressioning, which is a covert technique to create a usable key for a lock without picking the lock or taking it apart, in addition to some other types of more sophisticated attacks.

Chapter 2 of the book is on soft medium attacks and is particularly fascinating. Ollam writes of mold-and-cast attacks, which is a technique of opening a lock by covertly copying a legitimate key by making a cast of it in a soft material, then using it to imprint and fabricate a working key. Such a technique was used in real-life and detailed in the 1979 movie The First Great Train Robbery. Ollam writes how the movie was very true to the methods and technology available at that time, when the train robbery occurred in the 1850's.

The chapter walks the reader through the Quick-Key duplication kit method, in which most common key forms can be replicated with the kits molding and casting forms. The kit Ollam references is for the serious student of the craft, as it costs over $700- and can only be purchased from a firm in Germany.

Chapter 3 on master-keyed systems is particularly interesting as Ollam shows how a master key privilege escalation attack can often be easily done. Master-key systems make the logistics of granting access easier. But with that ease of use, comes the potential for abuse, as that single key will now have global access to the physical site.

Ollam writes that dedicated attackers who have the ability to spend a bit of time will often have the ability to compromise the code for the top master key (the one with the most access privileges) in nearly all master-keyed systems, even with only a small amount of preliminary information and a small number of blank keys.

In the same way that passwords often provide very little network security, Keys to the Kingdom shows that much of the security provided by physical locks is an illusion, given the ease at which these keys can be manipulated and copied.

Practical Lock Picking, Second Edition: A Physical Penetration Testers Training Guide is a great introduction to the topic of lock picking, while Keys to the Kingdom: Impressioning, Privilege Escalation, Bumping, and Other Key-Based Attacks Against Physical Locks takes that base knowledge and builds upon.

For those who perform physical penetration testing, these two books will prove to be invaluable. For those that simply want to understand what their locks are and aren't doing, they will find these to be a fascinating read.

Ben Rothke is the author of Computer Security: 20 Things Every Employee Should Know.

You can purchase Practical Lock Picking, Second Edition: A Physical Penetration Testers Training Guide and Keys to the Kingdom: Impressioning, Privilege Escalation, Bumping, and Other Key-Based Attacks Against Physical Locks from Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.
This discussion has been archived. No new comments can be posted.

Book Reviews: Lockpicking Books From Deviant Ollam

Comments Filter:
  • by MagdJTK ( 1275470 ) on Wednesday December 05, 2012 @04:01PM (#42195259)

    "insecure physical locks will do little to keep the bad guys out"

    I think this is unfair. The lock on my front door has a 100% record of keeping bad guys out. That's because it's intended to deter casual thieves, not secret agents. Knowing what your security is protecting against and choosing the right level is important. And I could buy the best lock in the world and someone could just smash a window...

  • by crazyjj ( 2598719 ) * on Wednesday December 05, 2012 @04:02PM (#42195269)

    Any place with any real security is going to have a LOT more than just key locks in place. It's the same layered security stuff that applies to network security. The userid/password is just ONE PART of the security. If someone isn't watching for abnormal behavior on the network too, you're already asking for trouble.

  • by localman57 ( 1340533 ) on Wednesday December 05, 2012 @04:16PM (#42195409)
    Lisa, I'd like to buy your rock.
  • by localman57 ( 1340533 ) on Wednesday December 05, 2012 @04:25PM (#42195497)

    Along with this is the question of whether you think of society in terms of wolves or sheep. Ask someone if it's a good idea to put your name and address on your keys. People who see society as sheep will say yes, so that your keys can be returned if you lose them. People who see wolves will understand that now the bad guys have not only your key, but the address of the house it goes to.

    I had a discussion with someone at my office about this with regard to their car. He had no problem leaving his keys in the ignition because it was a piece of shit car, and our small town is relatively sparcely populated with criminals. He didn't care if his car got stolen. I told him if i were a criminal, I'd leave his piece of shit car, and take his keys and the address from the registration in the glove compartment. Then i'd watch his house till he left for work the next day, and go in and help myself to whatever I wanted. He stopped leaving his keys in the car...
  • by Paracelcus ( 151056 ) on Wednesday December 05, 2012 @04:48PM (#42195821) Journal

    If you live in a condo complex/apartment building it's more than likely that the doorway to your unit/apartment is in a common (publicly accessible) hallway with Sheetrock walls that can be easily breached with a fist! Why have a heavy door with a Medico lock in a shitty wall? or between sidelights (flanking glass panels)? or an iron gate in front with ground level glass windows on the sides/sliding glass doors in back?

    Why have a pick proof padlock when a cordless 4" angle grinder with a carbide cut off wheel can go through a boron shackle in seconds?

  • by mlts ( 1038732 ) * on Wednesday December 05, 2012 @05:27PM (#42196385)

    The same reason I use pick-resistant padlocks on storages: Someone getting the lock off will leave a signature.

    Yes, the angle grinder will knock a boron shackle off in seconds flat, there will be some sort of proof of forced entry, either because the lock is missing, or the fact that there are obvious cuts on the wall. When placing a claim with an insurance company, it is a LOT easier to get them to play when there are obvious signs that someone forced their way in, as opposed to a picked/bumped lock which in some cases gives zero signes of entry.

    Insurance companies are a lot more likely to pay when the adjuster comes by and sees chainsaw marks on a wall, as opposed to no signs of any forced entry whatsoever.

    Then, there is the criminal aspect. If a thief picks a lock and enters... they may score a trespass charge, but no B&E. Forcing their way in, that is a definite felony, assuming they ever get caught.

    So, I'll keep my high security locks. Yes, they are by-passable, but they give protection in another arena, the legal one.

Mr. Cole's Axiom: The sum of the intelligence on the planet is a constant; the population is growing.