Attacking the popular Kwikset lock: open in 15 seconds with a screwdriver and a paper clip


Kwikset makes an incredibly popular line of reprogrammable locks that can be easily re-keyed, meaning that landlords don't have to physically change the locks when their tenants move out. Kwikset boasts that their locks are extremely secure, but Marc Weber Tobias and Toby Bluzmanis will present six Kwikset vulnerabilities at DEFCON; their demo includes an attack that opens the lock "in 15 seconds with a screwdriver and a paper clip." Tobias and Bluzmanis have spoken to Kwikset technicians about this, and in recorded conversations, the Kwikset employees insisted that the product was secure, something that can't be taken seriously if you've seen Bluzmanis and Tobias work on them.

Kwikset did not respond to requests for comment from WIRED, but Tobias, in phone calls to technical support for Kwikset, was told repeatedly that the locks were impervious to screwdrivers or wires, and that a screwdriver wouldn’t even fit in the keyway.

“With these ones you cannot even put a flat screwdriver in there,” a technician named Satima on the company’s support line told him during a recent phone call, which Tobias recorded. “There’s racks from up and down direction, not just up” that make it impossible to align the springs in the lock, she said. “There’s no tool that you can just put in the cylinder and pop it open. You can’t put any type of wire or anything like that.”

Another technician told him, “If it was that easy to pick a Kwikset lock, they would be having us doing recalls, [but] there’s nothing like that. It’s business as usual.” Without the key, there’s no way to open the locks, the technician asserted, and “sticking anything foreign inside of the keyway is just going to make it that much harder to open up.”

Millions of Kwikset Smartkey Locks Vulnerable to Hacking, Say Researchers [Kim Zetter/Wired]

Notable Replies

  1. Locks like fences keep honest people honest. I live in the Boston area, and here locks don't do a thing - the doors are easily kicked in thanks to brittle wooden doorway frames of the elderly houses around here.

  2. Always remove the decorative little screws that hold the brass strike plate to the door frame and replace these with 3" drywall screws which you can screw in with a power drill.

    Also put a 3" screw concealed under the strike plate where the bolt would tear through the frame if it were kicked in. Do that first.

    Now your door will require an extra two kicks to break it in, but at least nobody is going to come in just by shoving with their shoulder.

  3. I was once writing a novel in which a character picked a lock. I bought a book on the subject and told my wife to lock me out of the house and not let me in until I picked the lock. I was inside in less than three minutes. If you learn to actually rake a lock, all this isn unnecessary. Only downside, once you learn how, you will never feel safe again in your own home.

  4. I've used many hundred of drywall screws to assemble shelving, benches, and other utility woodworking projects, but I've never managed to sheer off the screw head when screwing them in with an electric drill.

  5. I lock my door with a one-time pad. It's the only secure way to do it.

    The key is the size of a door, though...

Continue the discussion bbs.boingboing.net

28 more replies

Participants