Lock Picking

Lock Picking Basics: How Pin Tumbler Locks Work and How They Fail

Why Learn About Lock Picking?

Locks are the most widely deployed physical security mechanism on the planet. They protect homes, offices, server rooms, and evidence lockers. Most people trust them implicitly. That trust is often misplaced.

The majority of locks in use today - the ones on your front door, your filing cabinet, your desk drawer - can be opened without a key in seconds to minutes by someone with basic training and inexpensive tools. This is not a new revelation. Locksmiths have known it for centuries. The lock picking community has been demonstrating it publicly for decades. Yet most people and organizations continue to rely on locks that provide minimal resistance to a skilled attacker.

Understanding how locks fail is essential for anyone involved in physical security. If you are responsible for protecting physical assets - whether that means a data center, an office building, or a research laboratory - you need to understand what your locks actually protect against and where their limits are. Lock picking knowledge is also a core skill in physical penetration testing, where security professionals are hired to test an organization's physical defenses by attempting to bypass them.

How Pin Tumbler Locks Work

The pin tumbler lock is by far the most common lock mechanism in the world. Invented by Linus Yale Sr. in the 1840s and refined by his son Linus Yale Jr. in the 1860s, the basic design has remained fundamentally unchanged for over 150 years.

stateDiagram-v2
    [*] --> Locked: Default State
    
    Locked --> KeyInserted: Insert correct key
    Locked --> PickAttempt: Insert tension wrench + pick
    Locked --> BumpAttempt: Insert bump key + strike
    Locked --> RakeAttempt: Insert tension wrench + rake
    
    KeyInserted --> PinsAligned: Key cuts lift pins to shear line
    PickAttempt --> PinByPin: Set each pin individually
    BumpAttempt --> MomentaryAlign: Impact forces pins to jump
    RakeAttempt --> RandomAlign: Rapid scrubbing sets pins
    
    PinsAligned --> PlugRotates: All pins at shear line
    PinByPin --> PlugRotates: All pins set with tension
    MomentaryAlign --> PlugRotates: Timing + tension catches pins
    RandomAlign --> PlugRotates: Tension catches aligned pins
    
    PlugRotates --> Unlocked: Cam/tailpiece actuates
    Unlocked --> [*]

Lock opening methods - from correct key to various picking techniques, all converging on pin alignment at the shear line.

A pin tumbler lock consists of a cylindrical plug that rotates inside a housing (called the bible or shell). The plug has a keyway - the slot where you insert the key. Running perpendicular to the plug, through holes drilled in both the plug and the housing, are sets of pins. Each pin position contains two pins stacked on top of each other: a key pin (bottom) and a driver pin (top), held down by a spring.

When no key is inserted, the driver pins span the boundary between the plug and the housing (called the shear line). This prevents the plug from rotating. When the correct key is inserted, each key cut lifts its corresponding pin stack to exactly the right height so that the gap between the key pin and driver pin aligns with the shear line. With all pin stacks aligned, the plug rotates freely.

A standard pin tumbler lock has 5 or 6 pin positions. Each pin position can be one of about 7 to 10 different heights (depths). This means a 5-pin lock with 10 possible depths per pin has 100,000 theoretical key combinations (10^5). In practice, manufacturers use fewer depths and avoid extreme combinations that would make keys too fragile, so the actual number of unique keys is lower - typically 20,000 to 50,000 for consumer-grade locks.

The mechanical tolerances in this system are what make lock picking possible. Manufacturing cannot produce perfect cylinders and perfect pins. There are always slight variations - a pin hole drilled a fraction of a millimeter off-center, a plug that is not perfectly round, pins that are not all exactly the same diameter. These imperfections mean that when you apply slight rotational pressure to the plug, one pin position will bind before the others. This is the foundation of all picking techniques.

Single Pin Picking (SPP)

Single pin picking is the fundamental picking technique. It exploits manufacturing tolerances to set each pin individually, one at a time.

The picker inserts a tension wrench (also called a tension tool or turning tool) into the keyway and applies light rotational pressure to the plug. This pressure is crucial - too much and the pins will not move; too little and they will not stay set. The correct amount of tension is typically described as the weight of a pencil resting on the wrench.

With tension applied, the picker uses a hook pick - a thin metal tool with a curved tip - to push up each pin individually. Because of manufacturing tolerances, one pin position will be tighter than the others. This is the binding pin. When the picker pushes this pin up to the shear line, it "sets" - the slight rotation of the plug traps the driver pin above the shear line. The picker feels a slight give in the tension wrench as the plug rotates a fraction of a degree.

With the first pin set, a new pin becomes the tightest - the new binding pin. The picker finds and sets this pin. The process repeats until all pins are set and the plug rotates fully. An experienced picker can open a standard 5-pin lock in 30 seconds to a few minutes. Competition pickers open practice locks in under 10 seconds.

The skill required for SPP is not primarily in the hands - it is in the sensitivity. The picker must feel the difference between a pin that is binding, a pin that is set, and a pin that is springing freely. This tactile feedback comes through the pick and the tension wrench. Learning to interpret it takes practice, typically weeks to months for basic proficiency and years for expertise.

The tools are simple and inexpensive. A basic lock pick set containing a tension wrench and several hook picks costs $15 to $50. Professional sets with specialty picks, rakes, and bypass tools run $50 to $200. The tools are thin, flat pieces of spring steel that can be carried in a wallet-sized case.

Raking: The Fast Approach

Raking trades precision for speed. Instead of setting each pin individually, a rake pick is inserted fully and then rapidly scrubbed back and forth across all the pins while tension is applied. The random motion of the rake bounces pins up and down. With the right tension, some pins will happen to land at the shear line and get trapped. Multiple passes of the rake progressively set more pins until all are set and the lock opens.

Rake picks come in various profiles designed to maximize the random pin manipulation. The snake rake (also called a city rake or Bogota) has a wavy profile. The ball rake has a series of half-round bumps. The triple peak has three pointed peaks of different heights. Each profile interacts differently with pin stacks, and experienced pickers choose rakes based on the lock they are attacking.

Raking is effective against cheap to mid-range locks because these locks have loose tolerances and standard driver pins. A cheap kwikset or master padlock can often be raked open in under 10 seconds. The technique requires less skill than SPP - a beginner can often rake a basic lock within minutes of first picking up the tools.

The speed of raking makes it the preferred technique for physical penetration testers who need to move quickly. Time spent at a door picking a lock is time exposed to detection. A lock that opens in 5 seconds with a rake versus 2 minutes with SPP represents a significant reduction in risk.

Raking is less effective against higher-quality locks with tighter tolerances and security pins. Security pins (discussed below) are specifically designed to defeat raking by creating false sets that confuse the picking process.

Bump Keys

A bump key is a specially cut key that fits a particular keyway with all cuts filed to the maximum depth. To use it, you insert the bump key one pin-depth short of full insertion, apply slight turning tension, and strike the key sharply with a small hammer or the back of a screwdriver. The impact transfers through the key to the key pins, which transfer it to the driver pins. The driver pins momentarily jump above the shear line. If the tension timing is right, the plug rotates during that brief moment, and the lock opens.

The physics are similar to a Newton's cradle - the impact energy transfers through the bottom pins to the top pins, launching the driver pins upward while the key pins return to their resting position. The separation at the shear line lasts only milliseconds, but that is enough if tension is already applied.

Bump keys are concerning because they require very little skill. Unlike SPP or even raking, bump key use can be learned in minutes from a YouTube video. A set of bump keys covering the most common residential keyways costs $20 to $40. Success rates against locks without anti-bump features are high - 70% to 90% for basic pin tumbler locks.

The bump key problem became widely publicized around 2006 when Dutch television broadcast a demonstration of locks being bumped open. Lock manufacturers responded with anti-bump features, but adoption has been slow. The majority of residential locks installed before 2010 have no bump resistance. Many current economy-grade locks still lack anti-bump features.

Other Bypass Techniques

Picking is not the only way to bypass a lock. Several techniques avoid the pin tumbler mechanism entirely.

Shimming attacks padlocks by sliding a thin piece of metal (a shim) between the shackle and the locking pawl. The shim depresses the latch mechanism, releasing the shackle without touching the pin tumbler at all. Cheap padlocks with spring-loaded latches are particularly vulnerable. Double-ball locking mechanisms in better padlocks resist shimming.

Bypass tools interact with the mechanism behind the lock rather than the pin tumblers. A bypass tool for a common Kwikset residential lock slides through the keyway and directly actuates the tailpiece that the plug would normally turn. The pin tumblers are irrelevant - the bypass tool reaches past them to operate the locking mechanism directly.

Impressioning creates a working key from a blank. The attacker inserts a blank key, applies rotational pressure, and wiggles it. The binding pin positions leave marks on the blank. The attacker files those positions down slightly, reinserts, and repeats. After several iterations, the blank has been filed into a working key. The process takes 10 to 30 minutes and leaves no evidence of forced entry - the attacker has a key that works.

Decoding reads the pin positions without removing the lock. Various tools can feel or measure the depths of the key pins through the keyway, allowing the attacker to cut a working key or simply pick more efficiently with knowledge of the exact pin heights.

Destructive entry - drilling, pulling, or prying - is the last resort. It is fast and reliable but leaves obvious evidence. Physical penetration testers avoid destructive entry because the goal is typically to demonstrate that covert entry is possible. Real attackers may also prefer covert methods to avoid detection.

Security Pins and Anti-Pick Features

Lock manufacturers have developed several countermeasures against picking, raking, and bumping. The most common are security pins - modified driver pins that interfere with the picking process.

Spool pins are driver pins with a narrowed middle section, shaped like a spool or bobbin. When a spool pin is pushed to the shear line during picking, its wider top catches on the edge of the plug hole, creating a false set - the plug rotates further than expected, but the lock does not open. The picker must reduce tension (allowing some set pins to drop) to work the spool pin past the ledge. Spool pins make raking very difficult because the false sets confuse the random process.

Serrated pins have small grooves cut around their circumference. Each groove can catch at the shear line, creating multiple false sets per pin position. The picker must carefully distinguish the true shear line set from the false groove sets - requiring more sensitivity and patience.

Mushroom pins combine features of spool and serrated pins. They are wider at the top with a tapered middle section. Like spool pins, they create false sets, but their shape makes the counter-rotation technique used to defeat spool pins less effective.

Anti-bump features include spring modifications and pin weight changes that prevent the energy transfer that bump keys exploit. Some manufacturers use lightweight top pins that do not receive enough energy from a bump to clear the shear line. Others use additional locking elements that are not vulnerable to bumping.

A quality lock combining spool pins, serrated pins, tight manufacturing tolerances, and anti-bump features is significantly harder to pick than a basic lock. An experienced picker might still open it, but it could take 10 to 30 minutes instead of 30 seconds, and raking becomes unreliable.

High-Security Lock Designs

High-security locks go beyond security pins with fundamental design changes that resist picking, bumping, drilling, and other attacks.

Medeco locks use pins that must be both lifted to the correct height and rotated to the correct angle. The key has angled cuts that simultaneously lift and rotate each pin. Picking requires controlling two dimensions per pin instead of one, dramatically increasing difficulty.

Abloy Protec2 uses a disc detainer mechanism instead of pin tumblers. Rotating discs must be aligned to specific angles by the key's sidebar cuts. The mechanism has no springs (eliminating bump attacks) and requires specialized disc detainer picks. The tolerances are extremely tight, making picking very difficult even with proper tools.

Mul-T-Lock uses telescoping pins - a pin within a pin. Each pin position requires two different heights to be set simultaneously. The keys have cuts on multiple levels. Picking requires manipulating both the inner and outer pins at each position, roughly doubling the work and skill required.

ASSA Twin combines standard pin tumblers with a sidebar mechanism. The key must simultaneously lift all pins to the correct height and align a separate set of sidebar elements. Even if an attacker picks all the pin tumblers, the sidebar prevents the plug from rotating.

These high-security locks are rated UL 437, which requires resistance to picking for 10 minutes or more under controlled test conditions. They cost $100 to $400 per lock compared to $10 to $30 for a standard residential lock. For protecting critical infrastructure, the price premium is minimal relative to the value of what they protect.

The legality of possessing lock picking tools varies significantly by jurisdiction. Understanding the local laws is essential for security professionals and hobbyists.

In the United States, laws vary by state. Most states allow possession of lock picks without restriction. Some states (like Mississippi, Nevada, Ohio, and Virginia) consider possession of picks alongside evidence of criminal intent as prima facie evidence of a crime. A few states (Tennessee, Illinois) restrict possession more strictly.

In Canada, possessing lock picks is not illegal per se, but possessing them in the context of committing or planning a crime (carrying them during a burglary, for example) adds charges. The relevant section is 351(1) of the Criminal Code.

In the United Kingdom, lock picks are not prohibited items, but carrying them in public without a reasonable excuse could be problematic under Section 25 of the Theft Act 1968, which covers "going equipped for stealing."

In Germany and most EU countries, possession is legal. Lock picking is a recognized hobby (locksport) with active communities and competitions.

In Japan, the "Law Concerning the Prohibition of Possession of Special Unlocking Tools" (2003) makes possession of lock picks illegal without a professional reason. This is one of the strictest laws globally.

In Australia, laws vary by state. Victoria and South Australia restrict possession; other states are more permissive.

For professional penetration testers, written authorization from the client (a "get out of jail free" letter) is essential. This document should specify exactly what physical security testing is authorized, which facilities are in scope, and the dates of authorized testing. Even with authorization, testers should carry identification and the authorization letter at all times during an engagement.

Lock Picking in Physical Penetration Testing

Physical penetration testing evaluates an organization's physical security by attempting to bypass it using the same techniques an attacker would use. Lock picking is one tool in a larger toolkit that includes social engineering, tailgating, badge cloning, and technical bypasses.

In a physical pentest, the tester's goal is typically to gain unauthorized access to a secure area - a server room, an executive office, a records storage area. The tester documents the method used, the time required, and any alarms or controls that were triggered (or not triggered) along the way.

Lock picking in a pentest context is about more than just opening locks. The tester evaluates the entire physical security posture: Are the locks on critical doors appropriate for the threat level? Are the locks installed correctly (many high-security locks are rendered ineffective by poor installation)? Are there bypass opportunities that make the lock irrelevant (hinges on the outside, gaps around the door frame, shared drop ceilings)?

The finding that a critical door's lock can be picked in 30 seconds is valuable. But the finding that the same door has a 2-inch gap at the bottom that allows an under-door tool to reach the interior handle is arguably more important, because it means the lock is entirely irrelevant to the door's security.

Physical security assessment pairs well with wireless security testing. A server room door might have a good lock but an RFID badge reader with known vulnerabilities. Or the lock might be fine, but a BLE-enabled smart lock on a nearby access point might be exploitable. Comprehensive physical security testing examines all the access control mechanisms, both mechanical and electronic.

The BLEShark Nano is useful in this context for scanning for BLE-enabled locks and access control systems in the target environment. Identifying what wireless devices are present and what data they broadcast is a key reconnaissance step in any physical security assessment.

Get the BLEShark Nano - $49.99
Back to blog

Leave a comment