Mul-T-Lock Bypass!! What the Hell is Matt Blaze Doing!?!?!?!

May 23, 2005 Last reply: 21 years ago 36 Replies

ME, if I know that there is a 'weakness' in a lock, will say there are possible/definite issues WITH THAT LOCK.. but would NEVER SAY.. if you do "THIS", the lock will fail to be secure, no matter WHO it is..

--Shiva--

A University examinations officer would rather the cabinet containing exam papers is obviously forced open than someone gaining access without leaving a mark followed by rumors going round the students.

A phone company supervisor wants to be assured that a set of pay phone keys held together with a long shackle padlock are all there at the end of a shift.

A casino operator wants to be assured that no one is discreetly unlocking pokies to take cash or fiddle the odds. A Medeco, Abloy or Bi-lock provides that assurance even though the machine may be moderately easy to break open.

A prison warden wants to ensure a guard hands back a complete set of keys at shift end without someone having to check each key - hence the ring is welded up.

An electricity utility wants to be assured that no one has tampered with a meter, so puts a seal on it.

In the first three examples the user relies on very high security locking mechanisms even though a break in by physical force is not that difficult. In the fourth the ring is secure against equipment usually found within a prison, (except in the locksmith's shop), and the last, entry is easy but it is almost impossible to conceal it.

It is horses for courses.

agree... can't forget the undesirable lurkers :-)

I use even a high security padlock to secure my bicycle; not due to security as the first reason, but just for convenience - I like it to carry only one key for house, storage room, bikes. My wife and me even think about re-fitting her Land Rovers (defender 90) locks with Euro cylinders, just for same convenience to be able to use the same key.

regards - Ralph

Because security through obscurity is ALWAYS a bad choice. Security through intelligent design and peer evaluation is always the better choice.

Would you want to buy a lock which is only secure because flaws aren't disclosed to you?

For the record, I have a mul-t on my door, and I'm quite happy with it

- I doubt there are many thieves around here that are going to pick the lock on my door, instead of say, smashing in the window.

since ALL these 'discussions' are based on the computer world, please send me a list of ALL the flaws of the security of Windows XP, including what the 2 service packs and any other patches have done to weaken it as well..

am awaiting your's and others answers..

Now, its been my observation, that the SECOND a 'security pack' is released the attacks ON OTHER computers goes up-because some 'lazy' hacker types, see what the 'fix' alters and then knows EXACTLY what to go after on those computers not yet patched, OR in some cases, that ARE patched and produce a NEW HOLE..

So, why dont we demand a SECURE operatingsystem for our computers/... Anyone know of one? its sure not XP..

--Shiva--

XP _is_ secure in most cases, but only then when the user knows what to do. I do run two NT-servers, and several NT-workstations, and I never ever had any critical situation, no viruses, no intruders. The problem is not the machine; it is sitting in front of the machine!

regards - Ralph

IMO, as long as its not connected to the internet, it IS secure-otherwise.. out of the box, its equal to a wide open store front screaming, I AM WIDE OPEN.. and unlocked...

now, its my understanding that NT is a different thing..and that is not used very often for 'home users' so, your statement can possibly be correct..

99.999999999% of people with a computer, are treating XP like a car.. it SHOULD BE ready to use..but, its not

--Shiva--

It is very easy to change this, it just has to be done.

With NT the whole family NT3, NT4, w2k and XP is meant.

regards - Ralph

then, we disagree..

and very few folks know or can easily find out what they must do to XP to make it safe..

friend is finding out how little XP will now run, and wishes he had never upgraded to it. plus I have had to 'fix problems' on it a couple of times.. the registry is real easy to get errors in it.

--Shiva--

Here in germany it is enough to buy one of the fancy computer magazines and follow their tips step by step.

regards - Ralph

I could tell you how, but there's a no information policy in this forum :-)

depends on the question asked. there ya go comparing computer security with physical security again :-)

Nice brains batman !!!

Maybe he's not very good on the IT side - certainly isn't on the physical security side ...

It has nothing to do with the difference between computer security and physical security. The principles still remain exactly the same.

It's been said, but i'll say it again.. security through obscurity or secrecy alone is no security at all!

The exact reason that so many locks/safes are poorly designed and can easily be accessed by someone with the knowledge and without the key is because of this long standing motto of burying your heads in the sand and praying that the knowledge of these flaws does not leak out into the ears of the thief who might be standing outside your door this instant.

It is exactly like the open source vs closed source debate in the software world:

On one side, you have those, who are often large corporations with profits at stake, who promote closed source software, who claim that their software is more secure only because no outsiders with malicious intent can view its coding. This is basically security by obscurity, plain and simple, or the lazy man's avenue to security. They try to hush up and restrict the information flow about the exploits instead of simply ensuring that they don't exist in the first place by taking extra coding measures. I would compare this group to the many people on this forum, many probably locksmiths by profession, who want to keep quiet about the design flaws in locks/safes in the hopes that no thieves will find out about them and exploit them.

On the other side, you have those who believe in an open source environment, where knowledge and source code is open to view freely by the public. This group tends to be made up more of the end users or consumers who actually use the software. They believe that revealing these exploits in software publically and publishing them for the world to see encourages their creators to quickly fix the flaws, and in the future, to take heavier steps to ensure security since the world is watching.

Let's face it. The companies who mass produce locks and safes have no incentive to implement more security measures into their products just as long as the public is kept in the dark about their severe and numerous holes in security. As long as the end user thinks their valuables are safe and sound, they will continue to buy these insecure locks and (un)safes. Meanwhile, thieves in "the know" will still be able to vandalize and plunder them at will. On the other hand, if public knowledge about the flaws is revealed, these companies will have no choice but to take the initiative to begin securing these devices more thoroughly, or else very few people would have any reason to purchase them. Speaking as a person who owns three safes and more locks than I can count, I would feel much more comfortable with the latter event happening rather than the former. How about you?

[snip]

The counter argument you're going to get here will be based on the misunderstanding that since locks have a physical manifestation that is easy to see, the cost of replacing a lock is enough greater than the cost of replacing software that there is a difference *in kind" rather than in degree. For people who don't understand both economics and the business of software, it's an easy mistake to make. The "Open Source" argument is nice, but not needed here. Simple economics and knowledge of how the software business works will suffice. Remember too that patents were created just as much to ensure that knowledge got out eventually, as to protect inventors. The trade off was supposed to be that in exchange for not taking the risk that someone else might figure out your secrets, you had to tell you secrets and the gov protected them for a finite time.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required