{"id":838,"date":"2009-02-06T23:12:04","date_gmt":"2009-02-07T07:12:04","guid":{"rendered":"http:\/\/cubist.cs.washington.edu\/Security\/?p=838"},"modified":"2009-02-13T00:48:45","modified_gmt":"2009-02-13T08:48:45","slug":"security-review-the-bike-and-its-lock","status":"publish","type":"post","link":"https:\/\/secblog.cs.washington.edu\/Security\/2009\/02\/06\/security-review-the-bike-and-its-lock\/","title":{"rendered":"Security Review: The Bike and its Lock"},"content":{"rendered":"<p><span style=\"color: #ff0000;\">EDIT: It appears that I goofed with the &#8220;more&#8221; tag when I first posted this, so I&#8217;ve included the rest of the article below.<\/span><\/p>\n<p>Since the days of waking up at 5am to watch the Tour de France live with my dad at eight years old, I&#8217;ve been a big fan of bikes. I&#8217;ve since grown to love riding them, and spent several years as an avid road racer. While I&#8217;m somewhat of an anomaly, many of you also rely on cycling for transportation to class, to work, and elsewhere. Unlike cars, which are just slightly harder to steal, bikes are the candy-from-a-baby in the world of theft. One magazine article I read several years ago had a &#8220;professional bike thief&#8221; (probably a security professional who learned methods of theft in his research) attempt to steal a bike secured by one each of every available bike lock on the market at the time. In public. The result? All but a single lock could be circumvented so quickly that nobody in the area even noticed that it was not unlocked by normal means.<\/p>\n<p>I have to say, I am particularly bitter about bike security. A few years ago I was living in Stevens Court with a few friends. A past summer job at Gregg&#8217;s Greenlake Cycles had yielded an absurdly cheap employee purchase of a Lemond Tourmalet, a <em>very<\/em> nice road bike. I wasn&#8217;t using it to commute to school (who locks up a bike like that around the Ave?), but I did have it in our apartment so I could go riding. One day I came home and it had been stolen from my living room. My roommates had left the front windows wide open and the door unlocked. Go go speed racer, go.<\/p>\n<p><!--more--><\/p>\n<p>Ahem&#8230;anectodes. So back to bike locks. Here&#8217;s the breakdown:<br \/>\n<strong>Assets:<\/strong><\/p>\n<ul>\n<li>The bike: This one is fairly straightforward. The main asset is the bike itself.<\/li>\n<li>The value of the bike, either monetary or functional.<\/li>\n<\/ul>\n<p><strong>Adversaries\/Threats:<\/strong><\/p>\n<ul>\n<li>Many bike thefts are crimes of opportunity. Often, adversaries are not hardened criminals, but those taking advantage of an easy gain.<\/li>\n<li>Scalpers are the most common pre-meditated bike thiefs. They steal bikes for resale of the bike or its parts. Especially on more expensive bikes, the parts are, separately, worth more than the bike as a complete product. A 10-speed Shimano Dura-Ace component set (just shift levers, gears, chain, brakes, and derailleurs) could run almost $1,500. A pair of good Ksyrsium road wheels (not tires, just the wheels) can cost $1,100.<\/li>\n<li>Generic thiefs.<\/li>\n<\/ul>\n<p><strong>Potential Weaknesses:<\/strong><br \/>\nBikes are incredibly difficult to secure. Part of this has to do with the way they are built. Each bike component is just screwed or bolted on. Bikes need to be light and mobile so emphasis is not on security. Often security is a non-consideration. Moreover, due to the common use cases (transportation, recreation, or racing), it is impractical to transport heavy-duty security mechanisms along with the bike.<\/p>\n<ul>\n<li>Parts are not well-secured. They can be removed quickly and easily with conventional tools.<\/li>\n<li>With the exception of the frame, most components are either plastic, carbon, or very lightweight metal alloys that can be snapped or cut with hands or the most basic of implements.<\/li>\n<li>Because the various components all come apart, it is impossible to secure all of the securable and valuable parts of the bike without multiple locks.<\/li>\n<li>Most locks are just for show. Cable locks can be cut with wire or bolt cutters. Chains can be dealt with using bolt cutters of varying strengths. Hacksaws can cut most any cable, chain, or lock bolt, since all but the most expensive locks use cheap, unhardened, and generally low-quality steel. Finally, many of the locks themselves are insecure. Keyed locks are often easy to pick. Circular locks were shown crackable with a mere ball-point.<\/li>\n<li>People don&#8217;t bother. Many bikes are left unsecured, especially if the owner anticipates a short stop.<\/li>\n<li>Human error causes locking to fail. Many fail to grasp the detachability of the various bike components or underestimate the time it would take for a good thief to disassemble impeding components. You&#8217;ll see many lone wheels still locked to racks, or a frame by itself without any wheels, the fork and drivetrain stripped.<\/li>\n<\/ul>\n<p><strong>Potential Defenses:<\/strong><\/p>\n<ul>\n<li>The greatest defense for a bike locked in public is to not be worth stealing. Nobody will ever waste their time trying to jack a cheap, old, or poorly maintained bike. If you&#8217;re commuting, especially in sketchy parts of time (*cough* the ave *cough*), don&#8217;t do it with a $2,500 road bike. Get yourself a used bike at a garage sale and ride that. If you are going to ride a nice bike, obfuscate it. Paint it over with an ugly color and bad paint job. Scratch it up. Plaster it with stickers. Get it dirty. None of these will work spectacularly well, but it never hurts.<\/li>\n<li>By a GOOD lock. This is especially true if you don&#8217;t heed the advice above. I would have no problem spending $100 on a bike lock for a nice bike. The very best bike lock out there will not stop a thief, but the best lock used correctly may impede them enough that they are deterred in a given context. So what is a good lock? Usually the way to go is either a good U-lock or fat, FAT chain and lock. If you actually care, I would recommend either the Kryptonite New York Fahgettaboudit Chain (https:\/\/www.kryptonitelock.com\/products\/ProductDetail.aspx?cid=1001&amp;scid=1002&amp;pid=1168) or U-Lock (https:\/\/www.kryptonitelock.com\/products\/ProductDetail.aspx?cid=1001&amp;scid=1000&amp;pid=1095). If you do get a U-lock, make sure it&#8217;s brand new and doesn&#8217;t have a tubular lock (the kind that gets insta-picked with a pen).<\/li>\n<li>Lock the bike properly. The frame MUST be locked to a secure beam. Ideally, you want to lock the frame, back wheel, and front wheel. With a single good lock, however, this is impossible. I, personally, simply lock the back wheel and frame with a single lock (carrying two locks is far too impractical&#8230;but I may come back to find a missing front wheel one of these days).<\/li>\n<li>Don&#8217;t take a bike to a known sketchy area in the first place.<\/li>\n<\/ul>\n<p>Conclusions:<\/p>\n<p>The bottom line is that if a crew with a van and power tools wants your bike&#8230;it&#8217;s just going to go. Sorry. If a single good bike thief with hand tools wants your bike, there&#8217;s also a good chance it won&#8217;t be there when you come back. The good news is that by far, most thefts are NOT committed by experts, but rather by fools taking advantage of an opportunity that you&#8217;ve given them. Take your lock seriously, lock your bike properly, and hope for the best.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>EDIT: It appears that I goofed with the &#8220;more&#8221; tag when I first posted this, so I&#8217;ve included the rest of the article below. Since the days of waking up at 5am to watch the Tour de France live with &hellip; <a href=\"https:\/\/secblog.cs.washington.edu\/Security\/2009\/02\/06\/security-review-the-bike-and-its-lock\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":97,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,7,13,5],"tags":[35,182,181],"class_list":["post-838","post","type-post","status-publish","format-standard","hentry","category-announcements","category-ethics","category-physicalsecurity","category-security-reviews","tag-bike","tag-cycling","tag-locks"],"_links":{"self":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts\/838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/users\/97"}],"replies":[{"embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/comments?post=838"}],"version-history":[{"count":6,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts\/838\/revisions"}],"predecessor-version":[{"id":844,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts\/838\/revisions\/844"}],"wp:attachment":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/media?parent=838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/categories?post=838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/tags?post=838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}