Skip to content

1.3 — Locks, Keys, Safety and Identity

A lock is an unusual object because it is designed around a person who is trying to defeat it. Almost nothing else in your house is. And once you follow the idea far enough it stops being about metal and becomes the much larger question of how anybody proves they are who they say they are.

The lock on your door

How does a key open a pin tumbler lock?

Cross-section of a pin tumbler lock with the correct key inserted, showing each pair of pins pushed so that the joint between them lines up along the shear line
A pin tumbler lock with the correct key in. Each stack has a lower pin (cut to a different length) and an upper driver pin pushed down by a spring. The key raises every stack until every joint sits exactly on the shear line, and only then can the plug turn. Image: Wikimedia Commons.

Inside the lock is a cylinder called the plug that has to rotate to withdraw the bolt. Around it is a fixed shell. The boundary between them is called the shear line, and the whole design is one idea: put obstacles across that boundary, and shape the key so it removes all of them at once.

Drilled through both plug and shell are five or six vertical channels. Each holds two pins stacked one on the other, with a spring above pressing them down. At rest, the upper pin — the driver — straddles the shear line, sticking down into the plug and up into the shell, and the plug cannot turn.

The lower pins are cut to different lengths. The cuts on the key are calculated to raise each stack by exactly the amount that brings its own joint level with the shear line. Get all five right simultaneously and there is a clean gap all the way round, so the plug spins freely. Get four right and one wrong and it will not move at all, which is why a nearly-correct key is worth nothing.

Linus Yale Jr. patented this form in 1861, but the principle is far older: wooden pin locks of exactly this logic have been found in Egypt from around 4000 years ago.

If it needs all five at once, how does lock picking work?

Because no lock is machined perfectly, and the imperfection is enough.

The picker puts light rotational pressure on the plug with a thin wrench. Because the holes are not in a perfect line, one pin stack binds against the edge of its channel slightly before the others. That is the binding pin, and it can be found by feel. Push it up with a pick and at the moment its joint crosses the shear line, the plug rotates a few thousandths of a degree — not enough to open, but enough that the shell now overlaps the top pin and holds it up. It is set. Then the next pin begins to bind, and the process repeats.

Picking works by converting one simultaneous five-part problem into five sequential one-part problems. That is the same insight that breaks a great many security systems, physical and digital: if a wrong answer fails differently from a nearly-right answer, an attacker can solve the parts one at a time. In software the same flaw is called a timing attack, and it is why a password check that stops at the first wrong character is a bug rather than an optimisation.

Why do some keys have a wavy groove down the side instead of teeth on the edge?

That is a dimple or laser-cut key, and the pins are arranged in two or four rows around the plug rather than one row on top. The wavy track steers the key in and the dimples milled into its flat faces lift the pins.

The point is not primarily strength but key control. An ordinary edge-cut blank can be bought anywhere and cut in two minutes by any shop with a duplicator. Dimple and side-milled systems use patented blanks that a manufacturer only supplies to authorised dealers against a card, so a tenant cannot quietly make ten copies. Most of what you pay for in a high-security lock is legal and logistical, not metallurgical.

What actually makes a safe a safe?

Time, not impossibility. Every safe in the world can be opened; safes are rated by how long they resist a specified attack with specified tools. A rating of TL-15 means fifteen minutes of net working time against hand tools and portable power tools by an expert who already knows the design. TL-30 means thirty. TRTL-30 adds a cutting torch.

That is the entire philosophy, and it is worth carrying: the safe is not meant to defeat the burglar, it is meant to outlast the alarm response. The body is usually not thick steel but a composite — steel skins with a fill of concrete carrying hard aggregate that destroys drill bits, sometimes with a glass plate inside wired to a relocking bolt, so drilling through the glass shatters it and fires extra bolts that cannot be retracted even with the correct combination.

Why does a hotel key card stop working when it sits next to your phone?

Almost always it did not. The old magnetic-stripe card could be wiped by a magnet, and phones do contain magnets — but the common failure has a duller cause. Hotel systems write a new code to the card at check-in and the lock accepts the most recent code it has seen; if somebody else is issued a card for the room, or your stay is extended and re-encoded, the earlier card is dead. Modern cards are contactless chips and are not affected by magnets at all.

Proving who you are

How do we know fingerprints are unique?

Strictly, we do not know it — nobody has checked every human hand, and nobody could. What we have is a very strong argument in three parts, and it is worth understanding exactly how strong.

A rolled fingerprint impression showing concentric ridge lines forming a central pocket loop whorl pattern
A rolled print showing a central pocket loop whorl. The overall pattern is one of only three families; the identification comes from the ridge endings and forks scattered through it. Image: Wikimedia Commons.

The first part is how ridges form. Between roughly the tenth and sixteenth week in the womb, a layer of skin on the fingertips grows faster than the layers around it and buckles. Where the buckles start and how they run depends on the exact geometry of the fingertip at that moment, the pressure of amniotic fluid, the position of the hand, and the rate of blood flow — a set of conditions no two fingers ever share, including the two hands of one person and the ten fingers of identical twins. Genes set the broad pattern; the details are set by physical accident. Identical twins have similar-looking prints and different minutiae, and that single fact does most of the work in the argument.

The second part is combinatorics. Identification does not use the swirl you can see. It uses minutiae — points where a ridge stops, or splits in two — of which a full print has 75 to 175, each with a position and a direction. Even a conservative model of how many independent ways those can be arranged gives numbers vastly larger than the number of fingers that have ever existed.

The third part is two centuries of failure to find a counterexample. Systematic collection began with William Herschel in Bengal in the 1850s, who took handprints on contracts and later compared prints of the same men taken decades apart to show they do not change. Francis Galton published the statistical case in 1892; Azizul Haque and Hem Chandra Bose, working under Edward Henry in Calcutta, built the classification system that made large collections searchable. Across hundreds of millions of records since, no two different people's full prints have ever been shown to match.

The honest summary: uniqueness of full prints is as well supported as an unprovable claim can be. Matching of partial smudged prints is a different and much weaker thing, and that distinction is where real forensic errors have happened — most famously in 2004, when the FBI matched a partial print from the Madrid train bombings to an American lawyer who had never been to Spain.

Why do we still sign things?

Because a signature is cheap, and until recently there was nothing better that a shopkeeper could check in four seconds.

As a security mechanism it is weak. It can be traced, it varies with your own mood and hurry, and almost nobody who accepts one is trained to examine it. What keeps it alive is the second thing a signature does, which is legal rather than technical: it marks the moment you assented. A court is not asking whether the squiggle is unforgeable. It is asking whether the person intended to be bound, and the signature is evidence of intent — which is why an electronic tick-box or a typed name is now accepted as a signature in most jurisdictions.

What is a seal, and why did wax work?

A seal solves a different problem from a lock. A lock stops access; a seal makes tampering visible. You are not preventing the letter being opened. You are guaranteeing that if it was, the recipient will know.

Wax works because a matrix carved with a design produces an impression that is easy to verify and hard to reproduce without the matrix, and because the wax must be destroyed to open the letter. Modern versions are everywhere and use the same logic: a tamper-evident strip on a medicine bottle, the foil under a jar lid, the numbered plastic strip on a shipping container, the security tape on a laptop that leaves the word VOID behind.

The digital descendant is a cryptographic signature, which is genuinely the same idea with the weakness removed: the recipient can verify it with a public key, and altering one byte of the document invalidates it. That mechanism is covered properly in Volume I.

What is actually stored when a phone stores your fingerprint?

Not a picture of your finger. The sensor extracts the minutiae — positions and angles of ridge endings and forks — and converts them into a mathematical template. The template is not reversible into an image in any useful way, and on modern phones it never leaves a separate hardware chip: the main processor sends a request and gets back yes or no, never the data.

This matters more than it sounds. A password can be changed after a breach and a fingerprint cannot. That is the fundamental asymmetry of biometrics, and the reason the industry moved to on-device templates rather than a central database of prints.

The security you meet every day

Why is a PIN only four digits when a password must be twelve characters?

Because they are protected by completely different things.

Four digits give ten thousand combinations. Guessing at random you would expect to succeed in about five thousand tries, which any computer does instantly. The security is not in the number. It is in the fact that the card is swallowed after three wrong attempts, and that you need the physical card as well. Three guesses out of ten thousand is a 0.03 per cent chance, and the attacker only gets one card.

A password has no such limit. It sits in a database that may be stolen wholesale and attacked offline at billions of guesses per second, with no counter to trip and no card to hold. So all the strength has to live in the secret itself.

The general rule is worth keeping: how strong a secret must be depends entirely on how many guesses the attacker is allowed. Where you can limit attempts, short secrets are fine; where you cannot, they are worthless.

Why does a shop check the hologram, and what stops it being copied?

A hologram records the interference pattern of light rather than an image, so the surface stores information about direction as well as brightness. That is why the picture shifts as you tilt it, and why a photocopy or a flat print of a hologram is obviously dead — a copier records only brightness.

Reproducing a real one requires the original master, a laser setup and an embossing die, which is not impossible but moves counterfeiting from a printer in a room to a small factory. That is the whole aim of most anti-counterfeiting: not to make forgery impossible but to make it require capabilities that a casual forger does not have and an organised one cannot hide.

What does the hallmark on gold jewellery actually certify?

Purity, tested by an independent assay office rather than by the seller. In India the BIS hallmark carries the BIS mark itself, a purity grade (22K916 means 22 carat, 91.6 per cent gold), and since 2021 a six-character alphanumeric HUID code unique to that piece, which can be checked in an app.

The reason the system exists is that you cannot judge gold purity by looking, weighing, or biting it. Density is close between alloys, colour is adjustable, and a plated base metal passes every casual test. Assay marking is one of the oldest consumer protections in existence — English hallmarking dates from a statute of 1300 — and it works by moving the trust from the party with an incentive to lie to a party with none.

Why do banks send a one-time code, and why is a text message the weakest way to do it?

The code is a second factor: something you have, added to something you know. Even if your password is stolen, the attacker cannot produce the code.

Sending it by SMS is the weakest common form for three reasons. The message travels through the phone network, which was not designed with this in mind and has been abused to intercept messages. It can be read on a locked screen. And most importantly, an attacker can persuade your mobile operator to move your number to their SIM — a SIM swap — after which every code goes to them. An authenticator app avoids all three, because it never receives anything: the app and the server share a secret once, and both compute the same six digits from that secret plus the current time.

What comes next

Locks and identity are about who is allowed through. The next page is about actually going somewhere — the train under you, the aircraft above you, and the reason there is a red button in every commercial taxi in some Indian cities that was not there ten years ago.