Master Key Questions

Feb 15, 2004 Last reply: 22 years ago 68 Replies

X-No-Archive: Yes



Hello All,



Before I ask my questions - I understand there may be some reluctance to discuss this in an open fourm, so if you prefer not to answer this, or speak only in vauge generalities, I compleately understand. Also, I have no intentention of trying to fabricate my own keys -- I have access to everything I need via the normal channels; I'm just curious.



That being said, two questions:


1- How many keys from a master system are typically needed before the master (or submaster) can be determined?


1b - Is this ever a consideration in determining weather to issue another change key vs. a master os submaster?



[I've been issued 12 keys from two different submaster groups (most from one, but a few from the other) and have noiced that there are two cuts common to every key within a the respective group, 1 cut common to all keys, and all of the remaining 4 cuts are duplicated on at least 3-4 keys (e.g (and totally made up) -2-3-4-6, -1-3-2-6,

-2-4-4-5)


2- How common is the Yale ZC keyway/blank? (And how common are 7-pin systems in general?) -- this is the first and only place I've seen this keyway and one of _very_ few where I've seen >5 pins used.

Thanks,



//I


If you are mathematically inclined and understand the basics of masterkeying, you can roughly figure this out. If the system uses rotating constants, you need to understand that as well.

No (AFAIK). It is possible to lay out a system to make this sort of thing harder, especially if there are relatively few different keys.

Where I am, most 'serious' masterkeying is done with 6 pin cylinders or high security systems especially 'Bi-lock' 12 pin cylinders (2 rows of 6 with sidebars, 4 depths).

Would it be fair to say that for a poorly designed MK system that it might be possible to determine the MK from two different change keys, and that for a well designed MK system it can be impossible to determine the MK even if all of the change keys are examined?

I read his query as asking whether the (sub)master could be determined from the keys alone. If that is the correct interpretation, one change key certainly is insufficient.

If one has unhindered access to the lock, then one change key is probably sufficient, and indeed it can often be done with no change keys!

Are you talking about the method published by Matt Blaze?

Does this say anything more than, "Let's not mention Matt Blaze."? If so, it is an attempt at "security by obscurity" that won't be very effective against even a small attempt at searching the internet.

Security-via-obscurity *does* actually work, for just that reason -- it doesn't block the clueful, but it does cut out those who aren't willing to make any effort (which covers most wannabe crooks; if they were willing to actually work at anything they could make better money at less risk by finding a real job.)

And, frankly, I don't consider handing folks all the info on a silver platter to be in their best interest even if they *are* legit, just as I don't solve strangers' homework assignments for them. Stuff you wanted to learn and were willing to make an effort to track down stays with you better than stuff that passed from the lecturer's notes to the student's notes without going through the minds of either.

I looked at the site mentioned above-(Oh, and thanks for mentioning that-LMAO)It had no reference to "Producing a Master Key.Only a method of producing a working control key.I have'nt heard of a control key being called a master or submaster.

GREAT GREAT GREAT GRAND MASTER GREAT GREAT GRAND MASTER GREAT GRAND MASTER GRAND MASTER MASTER CHANGE

OBSCURITY THROUGH SECURITY-LMAO-ROFL-PMPL-SMPL-OMG

goma.

In another news.group I read (rec.woodworking) there is an acronym that people often put in a post when they ask a question - it is "DAGS" It stands for "did a google search" and refers to "Google Groups" which has a good usenet archive - they took over the old dejanews.

---snip only to trim--

Evan, all previous post aside... I agree, when it comes to Matt Blaze's writings.

"'Key" snipped-for-privacy@You.net trolled nothing of value in message <snip the troll>

"'Key" snipped-for-privacy@You.net trolled nothing of value in message <snip the troll>

Blaze is a cancer on the locksmith profession who should be eliminated. Last year I called AT&T and complained. I think he was fired (maybe lots of people called). I was suprised to see him pop up again. May be time for some more calls.

Ed "lockie" NYC Locksmith Security Professional Retired

Ed "lockie" NYC Locksmith Security Professional Retired "

Well Ed I didn't say that he was a 'cancer on the locksmith industry', I said that his research (if you want to call it that) while serving a purpose, should not be published... Matt Blaze is NOT a locksmith, he is a computer nerd who decided one day to play around with some locks... He thought he discovered something new... Well he didn't... He was probably the first person to go PUBLIC with such information but not the first individual to discover the technique he describes...

While what he wrote could be considered truly shocking that he in essence 'let the cat out of the bag' he is protected under the laws of the land... He is free to write about whatever he chooses and you are free to criticize him about it... That is how free speech works... I just don't understand how people can cry out so loudly against something and then think that they are the only ones 'with the right' to discuss something (on any topic)... Ed "lockie" no one appointed you the 'high ruler of standards' over what can and can not be written about locks or the security industry...

Evan the maintenance man

I tried to post this in my last msg but it didn't go through.

Check this out from the LOCKNYC mailing list. I'm cutandpasting so I'll try again if it don't work. Any way here goes.

Did you look through the course outline? It is almost entirely on computer and network security. Are you really sure it is of poor quality? (IMHO Matt Blaze is an internationally recognized authority in those areas.)

AFAIK, *all* of the experts in the computer and network security field agree that publishing security flaws is a good idea (subject to a short delay, perhaps a few weeks, after notifying the vendor of the flaw). E.g. look at the policies and practices at

formatting link
The thought is that keeping flaws/vulnerabilities a secret primarily benefits the bad guys, and leaves the good guys vulnerable.

Many of us (including me) feel that locking hardware is not a perfect analogy to the above area, and so that those policies aren't totally suitable. I've corresponded with Matt Blaze on this, and I think he has come to understand our feelings, but doesn't totally agree. He didn't change my mind - but I'm not an extreme "security by obscurity" type.

There is a limit to protecting locking hardware by "security by obscurity." As an example, Kwikset KIK has a well known vulnerability, which I won't mention here. But any enterprising criminal can easily buy one of these at their neighborhood hardware store, and take it apart and discover all of its secrets - and then share them with all friends.

Security is a serious business - and Matt Blaze seems to be in that business.

One might object to one item in the last course area * Miscellaneous and fun topics o Alarm systems o Mechanical locks and physical security o Identity cards o Airport security o Human-scale protocols

but otherwise to what would you object (would you object to "Reverse Turing tests" or to a treatment of attacks against "BGP/DNS", or what?)

It shouldn't have been all that hard to track down contact information for the department at the university - since that is given in the title of the course outline - but here is a place to write - and I hope that letters to him give a well reasoned clear presentation about objections. (I don't care if you agree with me or not, but I'd prefer that letters aren't rants which make locksmiths look silly.) Fernando C.N. Pereira snipped-for-privacy@cis.upenn.edu Andrew and Debra Rachleff Professor of Computer and Information Science Chair, Dept. of Computer and Information Science

Just a question, would most people rather be unaware of a flaw, and have their machine (or lock) only taken advantage of by a "well read" thief, or would you prefer you (and not so well read thieves) know about flaws so you can plan around them??

Personally, being the well read type, I prefer knowing flaws. I've been in charge of corp. security for info systems, as well as entry systems, and I don't want to make excuses that "I didn't think this could happen" I would much rather tell my bosses that "we have covered all the known flaws and holes in the system, and if someone gets in, they damned well had to work for it". You *can't* stop everyone, but knowing flaws sure helps stop the uncreative people.

My $.02

MS just announced a SERIOUS 'security flaw' in their 'core software' for mist all versions... now the funny is they knew it 6 months BACK...(so they said)

#2 is some people WILL get the patch, and install it, to see whats changed, THEN go after the UNpatched machines, far easier...its like they were 'given the key'

--Shiva--

I agree, I want the info NOW- not 6 months or a year after the fact... but this goes (in their case) back to a problem of 'indifference'

IF there is a 'possibility, then I think the worst...

Its similar to the guy and the house locks- he wants unpickable, un copyable, etc... then puts it on a $100 door with a glass in the door...

--Shiva--

I don't know anything about Medeco locks but General Motors used sidebar locks starting in 1935. I hardly think Medeco invented the side-bar locking concept. "

Leon:

GM locks are of the disc wafer type...

Although my knowledge is incomplete in this area -- as far as I know Medeco was the FIRST *Cylinder type* pin tumbler lock to use the 'side bar' mechanism... Maybe Medeco did not invent the concept of 'side bar' locks but like I said to my knowledge they were the first company to apply such technology to pin tumbler cylinder locks...

Evan the maintenance man

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required