As I've said elsewhere, I think the FAQ actually addresses these issues
> in sufficient depth to cover most of your points. I understand your
> arguments, but unfortunately they're mostly of limited applicability to
> the actual physical security environment.
I don't think the alt.locksmithing FAQ addresses these issues in any depth at all, certainly not sufficiently so to help someone develop an informed opinion one way or the other. The only thing I can find is an assertion that the arguments that apply to software don't apply to locks, which seems to be based on a rather dubious understanding of the costs of maintaining and distributing software.
I think it would be enormously useful for someone to do a better job at articulating the case for obscurity in physical security systems. Right now, it seems to be mostly locksmiths who even understand what the arguments are. Perhaps there are compelling reasons for it that might even apply to systems in domains that currently embrace openness. Or perhaps the arguments are weak and don't even hold water for locks -- we won't know unless someone can state understandably what they are. I've concluded that the arguments as I understand them are faulty and weak, but I'm willing to be persuaded that I'm wrong. After all, computer security and cryptology researchers face these issues often - perhaps even more often than locksmiths do. We would welcome the kind of moral certainty about how to handle security vulnerabilities that some locksmiths seem to have.
> Finally (and I think most importantly), obscurity impedes progress.
> Only if it is obscure to practitioners of the art. If they all have the
> info available, progress is not impeded.
But they don't. Knowledge about locks and how they fail is useful for progress in more than just locksmithing, whether locksmiths understand that or not. Lock users, for one, to say nothing of other kinds of security practitioners (such as cryptographers).
And, in fact, it is generally no problem to obtain locksmithing
> information if you are willing to invest some time, effort, and money
> rather than expecting the world to be handed to you on a platter.
That's certainly my experience -- I've been able to learn quite a bit about locks from the open literature, including many of the more jealously guarded "secrets" about how to defeat them. It required concerted effort, though, and if I had been less interested I would probably have given up. But if it's true that the only barrier to obtaining locksmithing information is time, effort and money, how can one argue at the same time that obscurity benefits security here? Surely potential criminals would have an even keener interest in investing that kind of time, effort and money, even more than would-be locksmiths or lock users. If it's really just a matter of time, effort and money, then it seems that obscurity here is more like an attempt by a trade guild to monopolize and protect the value of its body of knowledge than a necessity for the "protection of the public," as some claim.