Opinions of those without a clue

Jul 17, 2003 Last reply: 23 years ago 13 Replies

Ya know... I tried to avoid the Matt Blaze thread from the beginning because I knew it would just be the same old tied argument by computer people who think that fixing a physical security problem is as cheap and simple as fixing a software security problem, and by people who think that everyone (for some reason) is somehow "entitled" to any information at all. (Like some kind of intellectual welfare.)



The simple fact is; these guys (some I suspect using multiple aliases to make it appear as though they have more allies, therefore bolstering their case) are never going to see/understand our side of the matter. (No, guys. It's not to protect our "turf". It's to protect our customers and the general public.)



I'm again tiring of a subject that keeps coming up in this group. Only the ":players" change.



The only reason I even jumped into this thread is because someone attacked a personal friend of mine.



Folks (locksmiths), it just ain't worth the effort to argue with these guys. Maybe if we ignore them they'll just go away and we can get back to the usual of helping people with real problems and the occasional witty come-backs to the "How can I break into the lockers at school? crowd.



As for me... I've allowed my self to be drawn into this thread. Unfortunately though, it's gone from coming to the defense of a good friend, to pointless arguing with those without the knowledge or understanding to allow them the ability to change their minds on the subject.



We are now to a point (AGAIN) of arguing just to argue. I'm done arguing. And _that_ literally is "For Christ's sake".


Bobby


Blind belief, sincerity and loyalty to a friend are nice, but they must never be used as substitutes for facts. Facts cannot be altered by opinions.

Numerous examples exist where widely publicized methods of attack against locks and security systems prompted security improvements not a crime wave.

Lever, pin and other tumbler designs replaced warded locks that could be easily compromised.

Hardened shackles, false gates, improved case designs, pick resistant cylinders, etc. were added to padlocks as a direct result of well-known methods of attack.

The spring latch was replaced by the deadlatch because "loiding" (from the word: celluloid) was a well-known attack.

Deadbolts were lengthened and improved with rotating hacksaw resistant center pins.

Rotating collars were added to protect rim and mortise lock cylinders against wrench attacks.

Hardened pins, armor plates, etc. were added to various lock cylinders to thwart drill attacks.

Armor plate was added to safe and vault doors to protect against drill attacks.

Relockers were added to safes to protect against "punch jobs" and various drill attacks.

Time locks and multiple dial combination locks were developed as a direct result of personnel risk factors.

The GSA ordered replacement of conventional mechanical combination locks with the X-07 and its successor designs to protect against well-publicized information security breaches perpetrated by government employees.

Various types of CCTV and access control systems with audit features were developed to improve security monitoring and recordation.

Master keyed high security lock cylinder designs that are not vulnerable to the same attacks as the conventional pin tumbler locks discussed by Matt Blaze were developed long ago.

Hinges, door and frame enhancements, etc. were developed to thwart various brute force attacks.

Various national security vulnerabilities have been discussed openly ever since

9/11and many security improvements have been made. Examples include: New airport customer, baggage, employee and service vendor security measures, beefed up cockpit doors, improved employee background evaluations, improved identification screening, etc.

Security research is continuously identifying vulnerabilities and developing strategies to improve the protection of networks and private computers against various types of highly publicized cyber-attacks.

A recent TV news story showing how a simple drill attack could defeat ATM machines has prompted the manufacturer to improve the design.

I could go on, but everyone in the locksmithing industry should know all this. All of these security vulnerability precedents, and many more, have been publicized over the years and the result in every case has been IMPROVED SECURITY.

The reaction to Matt Blaze's work is a "tempest in a teacup" and is totally out of proportion to reality. Alarmist conjecture, by some locksmiths, that attempts to predict an imagined downside that has no historical precedent to support it is, at best, nothing more than imaginative childish nonsense; at worst, it is undignified malicious stupidity that tarnishes the professional image of locksmiths and the security industry as a whole.

Your entire post only serves to state that there are many levels of security already available. It does no good to anyone to undermine that security which everyone who needs to know already knows is minimal.

Gotta agree with you, Bob. I've already killfiled one of the threads when it became clear that we'd run out of new things to say and were basically down to repeating the same arguments in new words.

Admittedly, among engineers that behavior is actually a mark of respect

-- it translates as "I think you should be bright enough to understand this, so if you don't agree I must have misphrased it; let me try again." But if there really is a basic disagreement, it eventually boils down to... "Is too!" "Is not!" "Says you!" "So's your mother!" "Nyaah, nyaah, nyaah." ... which isn't exactly helpful.

IS THERE ANYONE who is still undecided (or at least open-minded) on this question?

OF THOSE, IS THERE ANYONE who feel that further discussion would help

*them* decide? (As opposed to people who still want to change someone else's mind.)

IF NOT, MOVE TO CLOSE DEBATE because everyone is just preaching to their own choirs.

It's new to the newcomers. And some of us still want to try to educate them.

Of course what we, and they, should be doing is referring this question to the FAQ and/or the archives and NOT debating it further unless someone has a point not already discussed in those files.

Disagree, mildly.

Some folks are willing to listen to and consider the issues... and whether or not they eventually agree with the overall position they're generally worth talking to so they at least have a full understanding of the trade-offs.

Some aren't.

It isn't always easy to distinguish which you're dealing with until you've talked to them a bit.

As a general point, note that _attacking_ people tends to make them react by defending their position even when they might have been receptive to more constructive criticism.

-snip-

-snip-

Yes. 3 of four posters here who seem to all be agreeing with and supporting each other have NEVER posted anything else to Usenet and their posts all seem to originate with AOL. Boy what a coincidence.

formatting link
snipped-for-privacy@aol.com&ie=UTF-8&oe=UTF-8&h l=en&btnG=Google+Search

formatting link
snipped-for-privacy@aol.com&btnG=Google+Search

formatting link
snipped-for-privacy@hotmail.com+&btnG=Google+Search

Now now there is always lubricants to argue about.

"Your entire post only serves to state that there are many levels of security already available."

Those "levels of security" represent improvements made to correct vulnerabilities that were widely publicized.

"It does no good to anyone to undermine that security which everyone who needs to know already knows is minimal."

On the contrary, exposing defects is not undermining security. If a lock or security system is vulnerable to attack, because of certain inherent characteristic deficiencies, it is already undermined and no amount of secrecy will correct de facto design or application flaws.

All arguments consistently recommending "Security-Through-Obscurity" as a wise long-term strategy have been repeatedly discredited. Nothing will change that.

So aside from tumblerfumbler, nospamzapper and texsecure how many other screennames are on your AOL account? You must have to delete them periodically to avoid hitting the max. LOL

Publicized where? Since it was so widespread you should have no problem providing sources.

They are all vulnerable to some form of attack as has been explained ad nausum. Most people with those that are the most vulnerable have those because they have chosen to have them.

Your opinion for which you post NO supporting ecidence whatsoever. Where as there is plenty of evidence some of which I have already posted which clearly indicates that indiscriminate publicizing of security flaws leads to rampant attacks by those who would otherwise be incapable.

To all,

I've been following this thread fom the start and it's been interesting to say the least but that's about the lowest thing I've ever seen, one person posting under 3 or 4 different names to try and support his side of the argument.... Pretty lame I'd say. My first and last post on the subject.

Leon Rowell p.s. I only use one name and it's my real one....

Putyourspamhere wrote:

[rolling up sleeves] WD-40!

Sure - but will increasing the distribution of how to take advantage of the vulnerability help or hurt the users?

Why are you ignoring the short-term effects? Or are you denying them?

PB Blaster, AND WD-40, AND TRI Flo --Shiva-- nuk pu nuk

ESPECIALLY in a FORD ignition... JOB SECURITY...

--Shiva-- nuk pu nuk

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required