Most building owners think about keys the way they think about a spare tire: it either works or it doesn’t, and nobody thinks about it until there’s a problem at the worst possible time.
But a key is not really a piece of metal. It’s a physical password. The cuts along the blade encode a number — the bitting code — and that number is the real secret. The brass is just the delivery mechanism. Once you understand that, a lot of things that seem paranoid start to seem obvious. A photograph of a key is not a picture of an object. It’s a copy of a credential.
This isn’t a new revelation, and it isn’t a hypothetical. What has changed is how cheap and ordinary the tools have become.
In 2008, computer scientists at UC San Diego’s Jacobs School of Engineering built a software system called Sneakey to make exactly this point. The program could extract a key’s information from an ordinary photograph, adjusting for a wide range of camera angles and distances, in order to demonstrate that keys are not inherently secret.
The team was explicit about why they published: advances in digital imaging and optics had made it possible to duplicate someone’s keys from a distance without them noticing.
In their demonstrations, the researchers worked from images captured at considerable distance with a telephoto lens, and from low-resolution phone photos. They chose not to release the code, but noted that building something comparable would not be especially difficult for anyone with a working knowledge of computer vision.
That was 2008 — before the modern smartphone camera, before consumer 3D printing was mainstream, and before AI image upscaling. The underlying point has only gotten stronger with time.
Abstract risk is easy to dismiss. This example isn’t abstract:
In 2014, the Washington Post published a story about baggage handling that included a high-resolution photograph of the TSA’s set of master luggage keys. The photo was pulled in August 2015, but by then it had already been used to derive the exact cuts. Within hours of the resulting files being posted publicly, a Montreal system administrator printed one on a hobbyist 3D printer in about five minutes using ordinary PLA plastic and opened a TSA-approved lock with it.
He reported that he made no modifications and it worked on the first attempt. By 2016, researchers presenting at the HOPE conference had accounted for the full set of seven keys.
Here is where most articles on this topic go wrong. They tell you to stop posting photos of your house keys on social media. Fine advice, but it’s not how commercial buildings get compromised.
In a facility, keys leak through channels nobody has thought to audit:
Example: “During a security assessment at a [industry] facility in the Fox Valley last year, we found [specific finding].”
We’d rather be useful than alarming, so here’s the part most vendors leave out: photo-based duplication is a real risk, but it is not your biggest one. In the commercial buildings we work in, unauthorized keys enter circulation mostly through channels far more boring than a telephoto lens:
And the good news is that the fix for the photo risk is the same fix for the other four.
Maybe a key showed up in a social media post, a press photo, or a listing photo for your building. Don’t panic, and don’t skip straight to rekeying everything. Work through it in order:
One reassurance worth repeating: for most standard keys, someone with the photo still needs the right blank, the skill to cut it, and physical access to your door. The odds of all three lining up are low. Rekey the affected openings, and the photo becomes a picture of a key that no longer opens anything.
Stamping DND on a key is the most common key control measure in American commercial buildings and one of the least effective.
The stamp carries no legal force in most jurisdictions and imposes no obligation on a hardware store clerk, a kiosk, or an online service. As practitioners have long pointed out, while a “Do Not Duplicate” marking is no guarantee that a locksmith or technician will honor it, it does even less when duplication happens through an automated channel. The Associated Locksmiths of America has discouraged reliance on the marking for years, precisely because it creates a false sense of control.
The stamp is a request. Key control is an architecture.
Before you can decide whether your key control needs upgrading, you need to know what’s on your keyring right now. You can learn most of it from the key itself in about thirty seconds.
Still not sure? Bring the key in — identifying a keyway takes us seconds, and it tells you which tier you’re actually standing in rather than the one you assumed.
When we assess a facility, we sort every keyed opening into one of five tiers. Knowing which tier you’re in tells you almost everything about your real exposure.
| Tier & System Type | Overview & Features | Actual Key Control |
|---|---|---|
| Tier 1: Standard Keyways | SC1, KW1, and their relatives. Blanks are sold everywhere. Anyone can copy these anywhere, and no policy you write changes that. | None |
| Tier 2: Restricted by Agreement, Off-Patent | A distributor agrees not to sell your blanks to others. This works until it doesn’t. Once a keyway’s patent has expired, aftermarket blanks circulate, and the restriction is a handshake, not a barrier. This is precisely why high-security manufacturers limit blank distribution, and why automated duplication services can copy only those high-security key types whose patents have expired. | Weak and degrading |
| Tier 3: Patent-Protected Restricted Keyways | The blank itself is protected by an active utility patent, so manufacturing an unauthorized blank is patent infringement, not just a policy violation. Keys are cut only by an authorized dealer, only for named individuals on a signed authorization card. | Strong — for as long as the patent runs |
| Tier 4: Certified High-Security Cylinders | Tier 3 key control plus tested resistance to physical and covert attack. Medeco’s current M4 platform is UL 437 Listed and built to resist drilling, picking, and other forms of physical attack. It also carries ANSI/BHMA A156.30 and A156.5 ratings covering strength, durability, key control, and surreptitious-entry resistance. | Strong, plus attack resistance |
| Tier 5: Electronic & Credential-Based Access | Card, fob, mobile, or electromechanical cylinders. The defining advantage isn’t strength — it’s revocability. A lost credential is deactivated in seconds instead of triggering a rekey. See more on our commercial access control page. | Instant revocability (digital control) |
The most common objection we hear to upgrading is that the facility already runs on a master key system and nobody wants to re-issue every key in the building. Good news: you almost never have to.
High-security openings can run as their own small master system alongside your existing one. The usual approach is converting only the openings that matter — exterior doors, server room, pharmacy, records storage — to restricted or high-security cylinders, while interior doors stay on the current system untouched. The people who need access to the protected openings carry one additional key; everyone else notices nothing.
Manufacturers also support full master keying within their restricted platforms, so if you’d rather migrate the whole building over time, the hierarchy you have now — grand master, masters, change keys — can be rebuilt in the new keyway and phased in as budget allows.
The one thing you can’t do is put a high-security cylinder under your existing open-market master key, because that would mean cutting your restricted system on unrestricted blanks — which defeats the point. Bring us your current key schedule and we can usually map the conversion in a single visit.
If you take one procurement insight from this article, take this one.
When key control depends on patent protection, your key control expires when the patent does. A system whose patent lapses in three years gives you three years of real restriction and then quietly degrades to Tier 2 — usually without anyone noticing, because the keys still say “restricted.”
Ask for the expiration date in writing before you buy. It belongs in the spec alongside the ANSI grade. For reference, the Medeco 4 platform’s patented key control is protected to 2040, and the platform was launched in January 2021, meeting or exceeding ANSI/BHMA A156.30 and A156.5 criteria and carrying UL 437 listing. That’s roughly two decades of runway from launch — a very different proposition from a system with four years left.
Because printed copies are now part of the threat model, some current-generation systems defend against reproduction geometrically rather than legally.
The M4 key incorporates a movable element, a shuttle pin, that interacts with a lift pin inside the cylinder, which is specifically intended to deter 3D-printed copies of keys or blanks. Duplication also requires a specific key-cutting machine and access to manufacturer-controlled blanks, with multiple levels of restriction available.
The logic is straightforward: a photograph can capture a shape, and a printer can reproduce a shape. Neither can reproduce a moving part.
You don’t need a consultant to start. You need an afternoon and an honest inventory.
Find out more information about our FREE security analysis here.
If a facility is rekeying frequently, has high staff turnover, uses contractors heavily, or needs to know who opened a door and when, the answer usually isn’t a better key. It’s fewer keyed openings.
Mechanical key control makes an unauthorized copy hard to obtain. It does nothing about a key that was legitimately issued and never came back, and it produces no audit trail. Electronic access control solves both — you revoke a credential in seconds, and you can answer “who opened the east dock at 2:40 a.m.” That’s a different problem than duplication, and it’s the one many facilities actually have.
The right design for most buildings is a hybrid: electronic access on high-traffic and high-consequence openings, high-security mechanical on the rest, and a documented key policy over both.
Not meaningfully. The marking has no legal force in most jurisdictions and no effect on automated duplication channels. Treat it as a courtesy notice, not a control.
No responsible locksmith will say "impossible." The accurate claim is that duplication requires a controlled blank, specialized equipment, and dealer authorization tied to a named individual — which moves duplication from trivial to requiring a deliberate criminal effort with a paper trail. That's the real value.
There's no universal interval. Rekey on events, not on a calendar: lost master keys, involuntary terminations with key access, tenant turnover, post-construction, and any unexplained entry.
Not always, and not everywhere. It's better where you need revocability and audit trails. Mechanical locks still make sense for low-traffic interior openings, and every building needs a mechanical override plan for power and network failures.
At Lappen Security, we have more than 7 decades of experience serving Fox Cities commercial clients. If you need a commercial locksmith service, please contact us today.
Matthew Bent is a Certified Registered Locksmith and has [X] years of experience designing and servicing key control and access systems for commercial, industrial, healthcare, and municipal facilities in the Fox Valley.
Lappen Security Products is an authorized Medeco dealer serving Appleton, Neenah, Little Chute, Green Bay, and the surrounding area.