Hacker Chronicles

Archives
Subscribe
October 4, 2026

Lock Picking

Welcome to the October issue of Hacker Chronicles!

A quick reminder about this year's read-along: Snow Crash by Neal Stephenson. Get your copy now if you don't have it, or make sure your local library has it. We'll start reading in November, and my review starts in the December issue. 468 pages of legendary cyberpunk.

I'm now eight posts in on Instagram as @hackerfiction. There are quite a few #bookstagram accounts with stuff I like.

In this issue, I explore lock picking. It's well ingrained in hacker culture and I feature it in both my novels Identified and Submerged.

Enjoy!
/John

Writing Update

September was a bit slower than August. I was on a business trip to New York City for a few days and I went to see Iron Maiden in Los Angeles one of the weekends.

I really got into the weeds of a networking attack central to the plot, and in the middle of it I read in the news that some of those things are already happening. That's always a bummer, but a natural thing when writing near-future fiction.

Screenshot of a progress bar showing how John has written 44,263 words toward his target of 60,000.

I now need to write a series of escalations that follow the hack, and I wonder if it'll all fit in the remaining 16k words.

Reviews and Ratings

Thanks to those of you who rated and reviewed Submerged on Goodreads! I appreciate it. Last month I said I thought the threshold for them to show up on Amazon is 10. Unfortunately, Amazon's algorithm is not public and I have not yet reached the threshold. I probably need to hit 20. If you haven't rated it yet, you can help. You don't have to give me a high rating. An honest one is perfect. 🙂


October Feature: Lock Picking

I love lock picking for several reasons. It's not that I'm good at it myself, although I have done some in a lab environment and I own a basic set of picks. Instead it's about this:

  • Security by obscurity. Any computer security expert worth their salt knows that betting on secrecy is a fool's errand. If you hope your system is secure because no one knows how it works, you are effectively betting on no one caring enough to figure out how it works. At least parts of the lock industry have shown again and again that they operate this way. The clearest signal is that they try to legally stop people from explaining how their locks work.
  • The locksmiths. People have locked themselves out or lost their keys since forever. In addition, law enforcement has the legal right to open locked doors under certain circumstances. So we have to have locksmiths, and locksmiths are no magicians. Enabling locksmiths to open locks creates an opportunity for an unauthorized party to do that too. It's the same trade-off as with end-to-end encryption – either it's truly end-to-end, or it's not. As soon as there's a "master key," a back door, an override, or a fallback mechanism, bad guys can find and exploit it. This is of course gold for fiction writers.
  • The hacker itch. Hacker mentality means that you just have to figure out how something obscure works, especially if it's used for security. It's the same curiosity that makes kids crack open and dismantle their electronic toys or gadgets to see how they work. I ruined so many things as a child and my mom was not happy. The worst was when she found me in the bathroom, where I had opened up the power outlet with a screwdriver to check it out.

What follows is not intended as a comprehensive introduction to lock picking. It's more of a "Hey, this is interesting and here are some places to get you started."

Physical Locks

Physical locks have been around for a long time. I mean a long time.

According to Wikipedia, an early example of a tumbler lock was found in the ruins of the Palace of Khorsabad in Iraq, dating to 721–705 BC. But they may date as far back as 2000 BC in Egypt.

Since they needed locks back then, one can only assume that there were thieves trying to break the locks too.

Lock Picks

Picking tumbler locks with physical lock picks is a classic we see in movies.

The correct key moves pins inside the lock into set vertical positions where they allow the tumbler to rotate. To pick the lock you first put rotational tension on the tumbler so that it wants to rotate. Then you use your picks to lift each pin into the right position until the lock turns. For each pin you get right, the tumbler moves ever so slightly, effectively letting you set them one by one.

Here's an instructional video with a transparent padlock that lets you see the internals move (you can mute it; the audio is just generic instrumental rock):

How to Pick a Lock (Basics) on YouTube.
How to pick a lock, the basics (click to go to YouTube).

Lock Pick Guns

A tool used by locksmiths and the police is a lock pick gun. It has a needle that, when triggered, strikes all the pins at once. It's basically the same technique of tension and getting the pins in the right position, but it involves bumping the pins rather than lifting them with a pick.

A lock pick gun

There are also electric lock pick guns that vibrate the needle to get the pins in the right position.

Bump Keys

A crude version of what the lock pick guns do is a bump key. It's a key that fits the lock but has every cut filed to maximum depth.

Bump keys
Bump keys.

You insert it, bump it to move all the pins, and quickly turn the lock. Surprisingly often, that single bump is enough to push the pins past the line where the lock can turn.

Wireless Locks

When the hacker community gets serious about a line of hacking, they eventually create tools you can go buy. That has totally happened for wireless hacking.

For wireless locks specifically, two tools are often mentioned.

The Proxmark3 for radio-frequency identification (RFID) security analysis:

First version of Proxmark3 originally designed by Jonathan Westhues
First version of Proxmark3 originally designed by Jonathan Westhues.

The Flipper Zero for emulating RFID and NFC (near-field communication) tags, radio remote controls, etc:

Flipper Zero running Sub-GHz radio scanning mode
Flipper Zero running Sub-GHz radio scanning mode.

Hotel Locks, and the Saflok Research 2024

A special case of wireless locks are hotel locks. Hotels and short-term rentals have to issue keys per guest, and guests can change daily, or even more often at places that charge by the hour.

You need reprogrammable locks, and you need to be able to revoke and expire keys, since guests forget to return key cards and keys get downloaded to smartphones. Reprogrammable sounds like catnip for hackers.

Saflok is one of the most common hotel room lock systems. If you've stayed at hotels, you've probably used them. Saflok is part of Dormakaba's series of electronic hotel locks. Dormakaba is a Swiss company.

Saflok SR3
Saflok SR3 from the vendor's website.

Research presented at Defcon 32 in 2024 showed that Safloks were hackable, and there was plenty of security by obscurity making them vulnerable. One interesting detail is that there is a "deadbolt override" feature. Yes, the hotel room deadbolt is software-controlled.

On the researchers' website, they say:

"… the identified weaknesses allow an attacker to unlock all rooms in a hotel using a single pair of forged keycards. Over three million hotel locks in 131 countries are affected."

Here's the full talk:

DEF CON 32 - Unsaflok: Hacking millions of hotel locks - Lennert Wouters, Ian Carroll on YouTube. DEF CON 32 - Unsaflok: Hacking millions of hotel locks by Lennert Wouters and Ian Carroll (click to go to YouTube).

The lock vendor, Dormakaba, did not have a disclosure process at the time, so the researchers had to message their security officer on LinkedIn to report the problem. From there, Dormakaba took it seriously.

It took over a year until the first hotel could upgrade their system to fix the vulnerabilities. Now Dormakaba has this message on their support page:

"An immediate mitigation solution is available for a security vulnerability associated with both the key derivation algorithm and the secondary encryption algorithm used to secure the underlaying[sic] card data. This vulnerability affects Saflok systems (System 6000â„¢, Ambianceâ„¢, and Communityâ„¢)."

PIN or Code Locks

My novel Identified features two hacks and one other break-in against PIN or code locks, if I remember correctly. I won't spoil it here, but I potentially have a fourth one coming up in my next novel Yield.

At the heart of it, these are electronic locks just like the wireless ones. But hacking the computers that underpin (hah!) them requires a physical connection to the lock.

At the same Defcon conference in 2024, there was an excellent talk on the kind of locks you find in gym lockers and safes, and these days in homes too:

DEF CON 32 - Open Sesame: how vulnerable is your stuff in electronic lockers by Dennis Giese and braelynn, on YouTube. DEF CON 32 - Open Sesame: how vulnerable is your stuff in electronic lockers by Dennis Giese and braelynn (click to go to YouTube).

They talk about how such locks allow direct communication via 1-Wire with, for instance, "manager keys." It uses a binary protocol of high and low voltage in fixed time slots and can achieve transfers of 16.3 kbit/s.

Example communication over 1-Wire.
Example communication over 1-Wire.

Once you've connected to such a lock, you can potentially read its memory to get its current PIN, or reset it.

I think the visual of high and low voltage over 1-Wire is direct enough to possibly work in written fiction. It would be cool to see the vulnerability and hack that way.

Final Remarks

Lock security benefits from scrutiny. I hope hackers and the lock industry can come together on that front. But the locksmith requirement creates an immense challenge. We all expect there to be an override, and most people probably think that only professionals or accredited people can use the override. But that's never the case.

I also looked into whether military locks are any different. There are special locks, but it's not clear to me that the basics are better there. In 2019, fellow hacker fiction writer Cory Doctorow wrote in BoingBoing Security researcher cracks high-security lock used for ATMs, Air Force One, military bases. That research was presented at Defcon, and the lock vendor was … Dormakaba.

Hacking locks is exciting for me as an author. It's both a real part of hacker culture and a physical hack that can be part of a good story.


Currently Reading

Believe it or not, I'm still reading Three Men in a Boat by Jerome K. Jerome. I'm seriously considering giving up on it, even though I'm more than halfway through. It's not even a long book.

Don't miss what's next. Subscribe to Hacker Chronicles:
Older → Election System Hacking