Pete Biggs said:PaulM wrote:
Quoted message said:Quoted message said:But you assume that only 'hardcore bicycles thieves' would have this
knowledge if it hadn't been made public. I see nothing to warrant
this.
The fact that locks weren't picked in large numbers is enough to warrant
that, I think.
I don't think you can safely draw any conclusions from this fact. It is
one explanation, but there are others: it could be that there are
easier more relaible methods, or easier targets.
Quoted message said:Quoted message said:If any thing I think that lock picking is a subject far more
likely to interest 'mischievous kids' than hardcore bicycle thieves.
Its precisely the sort of thing that bored, smart, curious kids get
into - hence its prevalence as a subject of interest in hacker
culture.
They're not the ordinary kids on the street I'm thinking of. The geek
kids don't tend to mix with the street kids!
I'd like to know which kids you are thinking of. As a teenager I
certainly fell
into the category of either street kid and geek kid at various times,
and sometimes both. In any case this is an assumption you are making
and assumptions are bad things to base security on.
Quoted message said:
The pen method is not fiddly, apparently. That is the crucial point.
It's supposed to be incredibly easy. Which again does make me wonder how
the knowledge managed to stay underground for so long. I must admit I'm
confused.
Using words like apparently and supposed is something of a give away
here. The only conclusion we can safely draw from the film I've seen
(the original one) is that it can be done is a short time period given
that you know how to do it. (to be really safe we should say 'for that
brand of lock and pen'😉 It doesn't say that this method is easy,or
foolproof, and the fact that others here have tried and failed cetainly
suggests other wise.
Even if we assume that it does mean these things it says nothing at all
about the utility of this method versus others or the likelihood of it
being applied.
Quoted message said:Yes but I suspect it still didn't happen very much for some reason.
Quoted message said:
Quoted message said:It indicates nothing of the sort. There are plenty of reasons why this
might be - primarily among them would be the fact that bike thieves
already have plenty of other methods for stealing bikes as I point out
above.
I do wonder why they bother with more difficult methods than using a pen.
Because they are in fact easier/quicker/more reliable/don't require you
to carry around a carrier bagfull of pens in different sizes?
Quoted message said:
There are plenty of lazy/casual/low-risk-taking opportunists who steal
only when it is very easy to steal. I've had plenty of lift-off
accessories stolen from my bikes over the years, and I've had unlocked
bikes stolen. I don't see why some of the same thieves wouldn't steal my
locked bike if they knew how to *easily* overcome the lock.
But we don't know that they can *easily* overcome it. I not sure its
relevant though. The point about lift off thefts is that was no obstacle
to the theft.
Take wheels, for example. Its perfectly possible to remove a non-quick
release wheel if you carry around a spanner/allen keys. This does not
alter the fact that swapping from a quick release to a solid axle with
nuts is a good preventative measure against wheel theft. Just the fact
that you would have to carry and use tools is likely to deter the thief
enough that the will move on and look for a bike with a quick release,
despite the fact that it would be perfectly easy for them to steal it.
Sadly such a theft did occur outside my house on sunday, but perhaps we
can redeem something by using it as illustrative example. There were a
large number of bikes locked up outside my house (12 or so) the theft
only stole 1 wheel (from the most valuable looking bike) despite the
fact that several of the bikes were vulnerable in this way (More so, in
fact,since the bike in question was chained beneath two others). Why was
this so, when there was nothing about the physical security of these
bikes that would have prevented all thier wheels bing stolen?
The answer, I would suggest, is that the thief made a simple judgement
about the realtive value of the wheels versus the risk of getting caught
stealing them and acted accordingly. The moral of thi story should,
pehaps, therefore be that there is more to security than than just
physical security - its all about manging risks.
(as an aside there is a bike workshop in my house so I was at least able
to provide a non-qick release repalcement for a minimal donation).
Quoted message said:Quoted message said:I am not arguing that public disclosure does not entail an increased
risk
- it does, however this is outweighed by the benefits - allowing us to
make informed choices about security.
That's fine for those who can instantly afford to replace their locks with
something better. That leaves an awful lot of people who's bikes are
suddenly more vulnerable in the meantime while they find the money or
time.
What I'm struggling to understand is why to think it's a necessity to
instantly replace the lock unless you believe the probability of this
happening has jumped from next to nothing to something far more
substantial - I don't think you can draw this conclusion from the mre
fact of disclosure in the abscence of other evidence or a causal mechanism.
I certainly fall into the latter category of people and haven't rushed
out to replace my lock and am happy to use it in the knowledge that the
degree of physical security is exactly the same as it was before (though
the possibility of it being defeated might have changed). You have
chosen to do so and have therefore, hopefully gained the reassurance
that your lock is no longer vulnerable, I haven't and don't have this
assurance but I have saved the cash, neither of us has had our bikes
stolen. People are free to draw their own conclusions.
Quoted message said:And where does it stop? Surely right at the top with the very best lock.
Not everyone can afford that, period. The most secure locks won't
necessarily be the most practical in every way either.
But security isn't a matter of bigger and better locks, its a matter of
managing risks, and there are no guarantee's - tht is what insurance is
for. As I stated before I use a cheap £4 lock on my bike that is
substantially more vulnerable than a kryptonite d-lock. There is nothing
wrong with this as a security practice. The security of my bike is
dependent on its (low) value and (un)attractiveness. Putting on a £40
would not necessarily give any substantial rise in security - certainly
nothing like a factor of 10. Arguably it might make it less secure
since it could lead people to assume that it is more valuable than it
appears.
Quoted message said:We can broaden this out to society in general. Make security ever >
tighter to deal with the select few criminals by making everything more
impractical for most of us. I don't want to go far down that road.
Neither do I. But (good) security is not about pileing on more and more
features - its about managing risks. Thinking that it is so is a
collary of an easy, but fatal mistake in security - basing security on
things working not on them failing. This may seem paradoxical, it does
make sense.
With my existing bike I am fairly confident about the conditions under
which it would fail - which is just anout any slightly determined
effort. What I am making is a cost-benifit analysis of the cost of the
security vs the cost of replacing the bike when it fails. In this case
its practically zero (the bike was built of 2nd hand bits we had lying
around the workshop) so I consider it worth spending £4 to stop someone
walking away with it, but not anything more.
I'm also currently building up another much more expensive bike I will
be spending proportionally more on a lock for it. I don't expect it to
categorically prevent it being stolen only to prove a deterrent relative
to the value of the bike. I also expect it to ( or at least be vunerable
to) fail- so I will also get insurance, as well as utilising other
security measures, like keeping the existing bike for short urban
trips/leaving locked up for long periods. In fact I may never need a
lock at all (this is the case with my road bike).
Similarly you would be wrong to assume that your new lock will prevent
your bike being stolen - only that it is not vulnerable to this
particular method - the fact that it is so says nothing about its
susceptability to other methods.
In the end what we do is balance the costs of risk versus the value of
what we are trying to protect, and hopefully account for failure. We do
this on our knowledge of the risks and of value. This varies on a case
by case basis. A look at your message headers and a quick google shows
you are using a client that has at least 8 vulnerabilites 4 of them
unpatched. I would consider this a totally unacceptable risk. Either you
don't (because you don't value computer security) or you don't have
the requisite knowledge. Similarly I suspect your bike is more valuable
than mine which it is why you chose to rush out and get a new lock - a
perfectly good decision - while I have only very basic security in place
- I am still making an informed decision based on my knowledge - which
does vary form the first case, quite possibly, and why I think the risks
of disclosure acceptable - because it always adds to my knowledge, but
not necessarily my vulnerability.
Quoted message said:
Of course it depends on the theives' knowledge, but where I disagree is
that the knowledge, if sufficiently publicised, will turn more people into
bicycle thieves. Unlocked bikes are certainly more vulnerable to theft
than locked ones, that's for sure, and they are very, very likely to be
stolen promptly if left in many areas. That proves there are potential
bicycle thieves around in large numbers.
Unfortunately it doesn't - only that unlocked bikes will get stolen
(which is tautological) it could be that exisiting thieves go for the
low hanging fruit first.
Quoted message said:We can
Quoted message said:only do so if *we* know about it (we don't know what the thieves know)
which is precisely why I argue in favour of the disclosure.
I understand the logic but I wish the result could have been acheived in
another way with less risk to us in the meantime. More and better
pressurisation on the manufactures, for example. I know that was tried
but I like to think it could have been tried harder, perhaps with stronger
efforts to blackmail!, for want of a better word.
Unfortunately real life experience tends to show otherwise (as another
poster has pointed out in this case, and extensively in the case of
computer security. One of the problems is that manufacturers have a
vested interest in not making things safer in as much as this can cost
more and cuts into profit - disclosure will certainly cost Kryptonite a
lot - and unfortunately there interest and the interst of users can be
diametrically opposed. The only guarantee I can see that things like
this do get is if they are disclosed to the public and manufacturers
lose any advantage in trying to keep things secret. Coupled with the
fact that security is really about managed risk and we can only do this
with knowledge I think the case for disclosure is compelling, though not
without (some increased) rsik. The web page I pointed you goes into the
benifits and risks of this, and why the former outweighs the latter.
Bruce Schneier is an acknowledged expert on security and has a lot of
very smart things to say about it.
Paul M