UK and Europe · Public discussion

Hacking kryptonite locks

Started by anonymous coward · · Last activity · 23 posts · 1,389 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
UK and Europe
Published
22 September 2004
Last activity
24 September 2004
Original author
anonymous coward
Posts
23
Discussion status
Public discussion
Total views
1,389
Views / 30 days
0
Topics

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–20 of 23
Posts remain in their original chronological order.

Text size
  1. http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    AC

  2. "anonymous coward" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    You're late. It's been posted here already. Also posted was news of
    Kryptonite's replacement program being announced today.

    What I want to know is has anyone _here_ managed to open one of the older NY
    chain 'disc' locks - ie. older than two years? I've tried on mine but have
    only succeeded in destroying a few pens! I've tried several pens but find
    the barrels of hard plastic pens just break up and the softer rubbery ones
    just get fatter and mangled without getting in far enough to do anything.
    And according to a courier friend the word it is the newer ones made in the
    last two years that are affected, that's when Kryptonite outsourced their
    lock production to China or somewhere. Still, just because I haven't found
    a pen to fit without breaking apart or been able to do it myself doesn't
    mean I'm not worried enough to feel I can't rely on my chain. Bummer!

    Rich

  3. Richard Goodman said:

    "anonymous coward" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    You're late. It's been posted here already.

    Sorry... I swear I did a google search before posting though. Brain must
    have stopped working...

    AC

    Also posted was news of

    Quoted message said:

    Kryptonite's replacement program being announced today.

    What I want to know is has anyone _here_ managed to open one of the older NY
    chain 'disc' locks - ie. older than two years? I've tried on mine but have
    only succeeded in destroying a few pens! I've tried several pens but find
    the barrels of hard plastic pens just break up and the softer rubbery ones
    just get fatter and mangled without getting in far enough to do anything.
    And according to a courier friend the word it is the newer ones made in the
    last two years that are affected, that's when Kryptonite outsourced their
    lock production to China or somewhere. Still, just because I haven't found
    a pen to fit without breaking apart or been able to do it myself doesn't
    mean I'm not worried enough to feel I can't rely on my chain. Bummer!

    Rich

  4. Quoted message said:

    Sorry... I swear I did a google search before posting though. Brain must
    have stopped working...

    That's okay, it's not a "cut off his goolies, shoot him and burn the body"
    offence. Start a h*lm*t thread, though, and that very possibly is ;-)

    Cheers, helen s

    --This is an invalid email address to avoid spam--
    to get correct one remove fame & fortune
    h*$el*$$e*nd**$o$ts**i*$*$m*m$o*n*s@$*a$o*l.c**$om$

    --Due to financial crisis the light at the end of the tunnel is switched off--

  5. anonymous coward said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    There are plenty of people between the categories of regular bicycle
    thieves and honest folk. Mr Slightly Bent and Mischievous Kid are the
    ones we have to be worried about *now* the Krypto info is being widely
    publicised. I've probably got to buy a new lock because of this (if
    Kryptonite-4 is vulnerable?).

    ~PB

  6. ps. In any case, a lot of bike theives have been quite ignorant. They
    normally home in on weaker locks and use brute force. Frankly, I'd rather
    lock picking information wasn't publicised. Most locks can be picked one
    way or another.

    ~PB

  7. "Richard Goodman" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Also posted was news of Kryptonite's replacement program being announced
    today.

    Not as far as I can tell.

  8. anonymous coward said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    I don't have one. How are they *normally* operated?
    I presume you put the key in and turn it clockwise.
    The Bic video didn't seem to show any turning,
    just wiggling and pushing. It looks fake to me.

    The similar locks for laptops can be quickly and harmlessly opened
    with a screwdriver and a paperclip.

    --
    Eiron.

  9. "elyob" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:


    "Richard Goodman" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Also posted was news of Kryptonite's replacement program being announced
    today.

    Not as far as I can tell.

    What I meant was that news that Kryptonite was going to make an announcement
    today was posted, not news of the program itself, if you see what I mean.
    Their web site says it will be up by 5.00pm Pacific Standard Time, which
    would seem to mean early tomorrow morning, our time.

    Rich

  10. Eiron said:
    anonymous coward said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    I don't have one. How are they *normally* operated?
    I presume you put the key in and turn it clockwise.
    The Bic video didn't seem to show any turning,
    just wiggling and pushing. It looks fake to me.

    You are rather assuming that you open a lock with a ley, and by picking,
    in the same way, aren't you?

    A quick explantion of how tumbler locks work (any excuse for an ascii
    art diagram).

    This is a simplified version of a yale type lock (same principles)

    || || ||
    || = || -------- these are pins split into two parts (at '='😉
    = || || they sit in holes in the lock mechanism. In the
    || || = locks normal state these do not line up so the
    \/ \/ \/ cylinder can not be turned and the lock opened

    ||
    || ||
    || || || now the key is inserted the gaps line up and the
    = = = -------- the key can be turned
    || || /\ }
    /\ || __ } ------- this part represents the key (its an exagerated
    __ /\ __ } version of the hills and valleys on a yale key)
    _________ }

    A cylinder type lock work on the same principal however the pins are
    arranged radially in a circle, not in a line.

    At this point it is worth comparing a yale type key to a cylinder key.
    On a yale type key its the hills and valleys that move the pins up and
    down, on a cylinder key its the little scooped out indentations. When
    you compare the two you can see there is much more variation in height
    on the yale type key. This is important because it means you don't have
    to move the pins on a cylinder lock to open it. So picking a cylinder
    lock is going to be easier than picking a yale type lock (this isn't
    imposible but its not really worth the effort other than as an exercsie
    in lock picking) [1]

    Now to the picking part. Opening a lock with a key is easy: you insert
    the key and everything lines up. To pick it you normally have to do this
    one by one - you move one pin up and down whilst jiggling the cylinder
    to see if it will turn, when you've got it right in theory the cylinder
    should turn a little - this also jams the pin open in place - called
    'binding' the pin IIRC. Thus wiggling and pushing is *exactly* what I
    would expect to see if you were picking a cylinder lock with a biro. It
    doesn't prove this film wasn't a fake but nothing about how it was
    picked necessarily suggests it was.

    Paul M

    tallpaul at M L 1 d o t n e t

    [1] A word about yale type locks. The security of the lock and the
    security of the door it locks are not the same thing. The latter is
    determined by the bolt mechanism on the inside of the door. Just as I
    suspect most people wouldn't ride round on cheap, mass-produced in China
    bikes you should never use the lock equivalents such as the Bird brand
    (which can be opened by leaning on them) only those by reputable well
    known manufacturers such as Yale, Chubb, Ingersoll. Unfortunately these
    don't offer much better protection. If you want real security fit a
    Chubb 5 bar mortise or equivalent and nothing less. Oh and remember its
    easier to get round an obstacle rather than through it, and fit window
    locks.

  11. Pete Biggs said:
    anonymous coward said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    There are plenty of people between the categories of regular bicycle
    thieves and honest folk. Mr Slightly Bent and Mischievous Kid are the
    ones we have to be worried about *now* the Krypto info is being widely
    publicised. I've probably got to buy a new lock because of this (if
    Kryptonite-4 is vulnerable?).


    No, if you have to replace the lock it's because the lock is vulnerable
    to being picked, not because you know about it. Do you think this is the
    only way that this knowledge could spread? That 'Mischievous Kids' never
    share information amongst themselves that they keep from adults?

    Remember its alleged that Kryptonite have known about this since 1993.
    If this is true then that is 11 years when bikes could and have been
    stolen because this (or do you think the guy that made the film was
    theonly one to know about this?). Thats 11 years when they did nothing.
    Compared to what? One, two weeks since its been disclosed and Kryptonite
    have been forced to do something about it, and the rest of us can now
    make an informed decision about security.

    That doesn't necesarily mean rushing out and buying a new lock. The lock
    I use on the bike I ride most of the time cost £4 and is vulnerable to
    one good smack with a hammer. Its still appropriate security - the
    bike's only worth £25 at most so its hardly worth spending £30 on a
    lock. In fact its arguable its more appropriate than the more expensive
    locks I own since I don't have a bracket for these to atach them to the
    bike so I might well forget to take them out, and no lock, no matter how
    expensive, is any good if I can't actually use it to lock the bike up.

    All security is a matter of trade-offs - there is no such thing as
    infallible security and only a fool thinks otherwise.

    You might find this article useful reading - it talks about computer
    security but its equally aplicable here:
    http://www.schneier.com/crypto-gram-0111.html

    Paul M

  12. "Richard Goodman" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    What I meant was that news that Kryptonite was going to make an
    announcement today was posted, not news of the program itself, if you see
    what I mean. Their web site says it will be up by 5.00pm Pacific Standard
    Time, which would seem to mean early tomorrow morning, our time.

    It's up there now. To go straight to the point, they say: "To participate
    in the exchange program, please send an email to [email hidden]" (It
    will email back a form to complete and return to them)

    They apparently expect locks to begin shipping in mid-October.

    Rich

  13. I would caution you about making accusations about who knew what and when
    in a public forum. In doing so one must be prepared to back them up or not
    at his or her own peril.

    "Paul M" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:
    Eiron said:
    anonymous coward said:

    http://www.bikeforums.net/

    (Kryptonite locks in the news as they can be opened with a BIC biro.
    Apparently Kryptonite knew since 1993)

    I may be shooting myself in the foot by posting this here as I have 2
    kryptonite locks, but I figure the bike thieves are probably likely to
    know how to do this anyway so it's better that us honest folk do too.

    I don't have one. How are they *normally* operated?
    I presume you put the key in and turn it clockwise.
    The Bic video didn't seem to show any turning,
    just wiggling and pushing. It looks fake to me.

    You are rather assuming that you open a lock with a ley, and by picking,
    in the same way, aren't you?

    A quick explantion of how tumbler locks work (any excuse for an ascii
    art diagram).

    This is a simplified version of a yale type lock (same principles)

    || || ||
    || = || -------- these are pins split into two parts (at '='😉
    = || || they sit in holes in the lock mechanism. In the
    || || = locks normal state these do not line up so the
    \/ \/ \/ cylinder can not be turned and the lock opened

    ||
    || ||
    || || || now the key is inserted the gaps line up and the
    = = = -------- the key can be turned
    || || /\ }
    /\ || __ } ------- this part represents the key (its an exagerated
    __ /\ __ } version of the hills and valleys on a yale key)
    _________ }

    A cylinder type lock work on the same principal however the pins are
    arranged radially in a circle, not in a line.

    At this point it is worth comparing a yale type key to a cylinder key.
    On a yale type key its the hills and valleys that move the pins up and
    down, on a cylinder key its the little scooped out indentations. When
    you compare the two you can see there is much more variation in height
    on the yale type key. This is important because it means you don't have
    to move the pins on a cylinder lock to open it. So picking a cylinder
    lock is going to be easier than picking a yale type lock (this isn't
    imposible but its not really worth the effort other than as an exercsie
    in lock picking) [1]

    Now to the picking part. Opening a lock with a key is easy: you insert
    the key and everything lines up. To pick it you normally have to do this
    one by one - you move one pin up and down whilst jiggling the cylinder
    to see if it will turn, when you've got it right in theory the cylinder
    should turn a little - this also jams the pin open in place - called
    'binding' the pin IIRC. Thus wiggling and pushing is *exactly* what I
    would expect to see if you were picking a cylinder lock with a biro. It
    doesn't prove this film wasn't a fake but nothing about how it was
    picked necessarily suggests it was.

    Paul M

    tallpaul at M L 1 d o t n e t

    [1] A word about yale type locks. The security of the lock and the
    security of the door it locks are not the same thing. The latter is
    determined by the bolt mechanism on the inside of the door. Just as I
    suspect most people wouldn't ride round on cheap, mass-produced in China
    bikes you should never use the lock equivalents such as the Bird brand
    (which can be opened by leaning on them) only those by reputable well
    known manufacturers such as Yale, Chubb, Ingersoll. Unfortunately these
    don't offer much better protection. If you want real security fit a
    Chubb 5 bar mortise or equivalent and nothing less. Oh and remember its
    easier to get round an obstacle rather than through it, and fit window
    locks.

    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.766 / Virus Database: 513 - Release Date: 9/17/04

  14. DT said:

    I would caution you about making accusations about who knew what and when
    in a public forum. In doing so one must be prepared to back them up or not
    at his or her own peril.

    Erm.. I think you will find I was quoting (the original poster), rather than
    making any such allegations, but in any case I will point you here:
    http://www.bikebiz.co.uk/daily-news/article.php?id=4637
    which appears to show the information has been in the public domain
    since 1992.

    Kryptonite replacement offer is exemplary behaviour, and they are to be
    congratulated for it and as the above article points out they are far
    the only lock manufacturers whose locks are vulnerable to the this
    problem. However as it also points out if this fault has been known
    about since 1992, it does beg the question why hasn't something been
    done about it before. It is, perhaps, unfortunate that Kryptonite have
    been singled out, but they have been selling a product at a premium
    price based upon the consumer perception that they offer a greater
    degree of security so this could be seen as quid pro quo.

    Paul M

    Quoted message said:

    "Paul M" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:
    Eiron said:

    anonymous coward wrote:

    >http://www.bikeforums.net/
    >
    >(Kryptonite locks in the news as they can be opened with a BIC biro.
    >Apparently Kryptonite knew since 1993)

  15. Paul M said:
    Quoted message said:
    Quoted message said:

    I may be shooting myself in the foot by posting this here as I have
    2 kryptonite locks, but I figure the bike thieves are probably
    likely to know how to do this anyway so it's better that us honest
    folk do too.

    There are plenty of people between the categories of regular bicycle
    thieves and honest folk. Mr Slightly Bent and Mischievous Kid are
    the ones we have to be worried about *now* the Krypto info is being
    widely publicised. I've probably got to buy a new lock because of
    this (if Kryptonite-4 is vulnerable?).


    No, if you have to replace the lock it's because the lock is
    vulnerable to being picked, not because you know about it. Do you
    think this is the only way that this knowledge could spread?

    I think it's the way knowledge spreads to the masses and it's the masses
    I'm most worried about. Only a few knew of the method before, now many
    more people do, hence the increased risk.

    Quoted message said:

    That
    'Mischievous Kids' never share information amongst themselves that
    they keep from adults?

    I don't think enough mischievous kids come into contact with hardcore
    bicycle theives for that knowledge to get a hold. Mischevious = "playful
    or naughty". I'm not referring to more serious trouble makers, merely the
    average kid on the street.

    Quoted message said:

    Remember its alleged that Kryptonite have known about this since 1993.
    If this is true then that is 11 years when bikes could and have been
    stolen because this

    Exactly. Kryptonite locks were not picked in large numbers, indicating
    the knowledge was only held by a select few. I've used my lock for over
    fifteen years without getting it picked. Now I think I shoud change it
    because every Tom, [censored] and Harry knows how to pick it, or soon will, if
    the information is correct.....

    I do accept the other explaination as to why the knowledge wasn't
    wide-spread might be valid: that the method doesn't work! Or that only
    very few pens on the market work. (I haven't found one that fits my lock
    yet).

    ~PB

  16. Pete Biggs said:

    Paul M wrote:

    Quoted message said:
    Quoted message said:

    No, if you have to replace the lock it's because the lock is
    vulnerable to being picked, not because you know about it. Do you
    think this is the only way that this knowledge could spread?

    I think it's the way knowledge spreads to the masses and it's the masses
    I'm most worried about. Only a few knew of the method before, now many
    more people do, hence the increased risk.

    Quoted message said:

    That
    'Mischievous Kids' never share information amongst themselves that
    they keep from adults?

    I don't think enough mischievous kids come into contact with hardcore
    bicycle theives for that knowledge to get a hold. Mischevious = "playful
    or naughty". I'm not referring to more serious trouble makers, merely the
    average kid on the street.

    But you assume that only 'hardcore bicycles thieves' would have this
    knowledge if it hadn't been made public. I see nothing to warrant this. If
    any thing I think that lock picking is a subject far more likely to
    interest 'mischievous kids' than hardcore bicycle thieves. Its precisely
    the sort of thing that bored, smart, curious kids get into - hence its
    prevalence as a subject of interest in hacker culture. Bike thieves
    already have plenty of reliable methods of breaking locks without
    bothering to fiddle around picking them. The ability to pick a lock with a
    ball point pen case is precisely the kind of thing that gets you kudos in
    the playground.

    Quoted message said:
    Quoted message said:

    Remember its alleged that Kryptonite have known about this since 1993.
    If this is true then that is 11 years when bikes could and have been
    stolen because this

    Exactly. Kryptonite locks were not picked in large numbers, indicating
    the knowledge was only held by a select few.

    It indicates nothing of the sort. There are plenty of reasons why this
    might be - primarily among them would be the fact that bike thieves
    already have plenty of other methods for stealing bikes as I point out
    above.

    I've used my lock for over

    Quoted message said:

    fifteen years without getting it picked. Now I think I shoud change it
    because every Tom, [censored] and Harry knows how to pick it, or soon will, if
    the information is correct.....

    It *may* give them the knowledge, but it does not necessarily give them
    the inclination. In fact given the forums this information has been
    circulating in I think a stronger claim could be made that the effect has
    been to warn cyclists of this vulnerability.

    You have stated that its the masses that you are afraid of but have given
    no reason as to why. I haven't used this information to go out and steal
    bicycles and neither have you, rather we have used the information to
    review our security information. Why impute to others behaviour that you
    have not shown yourself?

    Rather I think the people we have to be worried about now are the people
    we had to be worried about before - bicycle thieves. The majority of theft
    is committed by a small number of people. There is certainly a degree
    (probably a wide degree) of social contact among them and hence the
    potential for knowledge sharing. Thus it would only need that information
    to get to one or two people before it could spread to a high percentage of
    people we need to be worried about (even if their numbers relative to the
    general population). This mechanism can operate regardless of public
    disclosure, and lack of public disclosure certainly doesn't prevent.

    I am not arguing that public disclosure does not entail an increased risk
    - it does, however this is outweighed by the benefits - allowing us to
    make informed choices about security. It would be wrong to do so merely on
    the basis of perceived risk, however. The fact that you have used the same
    lock successfully for 15 years could tell us one of two things (if we
    assume it is vulnerable to being picked) with a third given. Either nobody
    has tried to steal your bike (which tells us nothing about the security of
    the lock - except perhaps as a deterrent) or they have and the lock
    offered sufficient protection against the methods used. It is a given that
    no one has (successfully) tried to pick it with the pen method. The
    probability of the bike being stolen has not changed because you know its
    vulnerable to the third - that depends on the thieves knowledge not yours.
    It certainly hasn't gone from 0 to 100%. Your perception of the risk has
    changed something like this.

    The fact that it has offered a reasonable degree of protection in the past
    indicates that it may well do so in future, what we now know however, is
    that a vulnerability exists which negates this existing protection. We
    should base our security on the knowledge of this vulnerability (which is
    an objective phenomena) not just on our perception of the risk. We can
    only do so if *we* know about it (we don't know what the thieves know)
    which is precisely why I argue in favour of the disclosure. It is also the
    motivation of the person who first made the film. Both of us have a
    background in computer security - The argument about disclosure is a well
    trodden one in computing. You would be hard put to find anyone who is
    against it except perhaps those with a vested interest (e.g.
    manufacturers), at least amongst those who truly know about it.

    Quoted message said:

    I do accept the other explaination as to why the knowledge wasn't
    wide-spread might be valid: that the method doesn't work! Or that only
    very few pens on the market work. (I haven't found one that fits my lock
    yet).


    There is another post of mine in this thread that explains (briefly) why I
    consider that this is a credible threat - I am happy to add more detail if
    you need it. The fact that you haven't been able to do it is really
    neither here nor there, it not you you have to worry about. You might not
    have the knowledge to break into your computer, by way of an example,it
    would be foolish to assume that because you don't that I couldn't.

    Paul M

  17. PaulM said:
    Quoted message said:
    Quoted message said:

    No, if you have to replace the lock it's because the lock is
    vulnerable to being picked, not because you know about it. Do you
    think this is the only way that this knowledge could spread?

    I think it's the way knowledge spreads to the masses and it's the
    masses I'm most worried about. Only a few knew of the method
    before, now many more people do, hence the increased risk.

    Quoted message said:

    That
    'Mischievous Kids' never share information amongst themselves
    that they keep from adults?

    I don't think enough mischievous kids come into contact with hardcore
    bicycle theives for that knowledge to get a hold. Mischevious =
    "playful or naughty". I'm not referring to more serious trouble
    makers, merely the average kid on the street.

    But you assume that only 'hardcore bicycles thieves' would have this
    knowledge if it hadn't been made public. I see nothing to warrant
    this.

    The fact that locks weren't picked in large numbers is enough to warrant
    that, I think.

    Quoted message said:

    If any thing I think that lock picking is a subject far more
    likely to interest 'mischievous kids' than hardcore bicycle thieves.
    Its precisely the sort of thing that bored, smart, curious kids get
    into - hence its prevalence as a subject of interest in hacker
    culture.

    They're not the ordinary kids on the street I'm thinking of. The geek
    kids don't tend to mix with the street kids!

    Quoted message said:

    Bike thieves
    already have plenty of reliable methods of breaking locks without
    bothering to fiddle around picking them.

    The pen method is not fiddly, apparently. That is the crucial point.
    It's supposed to be incredibly easy. Which again does make me wonder how
    the knowledge managed to stay underground for so long. I must admit I'm
    confused.

    Quoted message said:

    The ability to pick a lock
    with a ball point pen case is precisely the kind of thing that gets
    you kudos in the playground.

    Yes but I suspect it still didn't happen very much for some reason.

    Quoted message said:
    Quoted message said:
    Quoted message said:

    Remember its alleged that Kryptonite have known about this since
    1993. If this is true then that is 11 years when bikes could and
    have been stolen because this

    Exactly. Kryptonite locks were not picked in large numbers,
    indicating the knowledge was only held by a select few.

    It indicates nothing of the sort. There are plenty of reasons why this
    might be - primarily among them would be the fact that bike thieves
    already have plenty of other methods for stealing bikes as I point out
    above.

    I do wonder why they bother with more difficult methods than using a pen.

    Quoted message said:

    I've used my lock for over

    Quoted message said:

    fifteen years without getting it picked. Now I think I shoud change
    it because every Tom, [censored] and Harry knows how to pick it, or soon
    will, if the information is correct.....

    It *may* give them the knowledge, but it does not necessarily give
    them the inclination.
    In fact given the forums this information has been
    circulating in I think a stronger claim could be made that the effect
    has been to warn cyclists of this vulnerability.

    You have stated that its the masses that you are afraid of but have
    given no reason as to why. I haven't used this information to go out
    and steal bicycles and neither have you, rather we have used the
    information to review our security information. Why impute to others
    behaviour that you have not shown yourself?

    There are plenty of lazy/casual/low-risk-taking opportunists who steal
    only when it is very easy to steal. I've had plenty of lift-off
    accessories stolen from my bikes over the years, and I've had unlocked
    bikes stolen. I don't see why some of the same thieves wouldn't steal my
    locked bike if they knew how to *easily* overcome the lock.

    Quoted message said:

    Rather I think the people we have to be worried about now are the
    people
    we had to be worried about before - bicycle thieves. The majority of
    theft is committed by a small number of people. There is certainly a
    degree (probably a wide degree) of social contact among them and
    hence the potential for knowledge sharing. Thus it would only need
    that information to get to one or two people before it could spread
    to a high percentage of people we need to be worried about (even if
    their numbers relative to the general population). This mechanism can
    operate regardless of public disclosure, and lack of public
    disclosure certainly doesn't prevent.

    I am not arguing that public disclosure does not entail an increased
    risk
    - it does, however this is outweighed by the benefits - allowing us to
    make informed choices about security.

    That's fine for those who can instantly afford to replace their locks with
    something better. That leaves an awful lot of people who's bikes are
    suddenly more vulnerable in the meantime while they find the money or
    time.

    And where does it stop? Surely right at the top with the very best lock.
    Not everyone can afford that, period. The most secure locks won't
    necessarily be the most practical in every way either.

    We can broaden this out to society in general. Make security ever tighter
    to deal with the select few criminals by making everything more
    impractical for most of us. I don't want to go far down that road.

    Quoted message said:

    It would be wrong to do so
    merely on the basis of perceived risk, however. The fact that you
    have used the same lock successfully for 15 years could tell us one
    of two things (if we assume it is vulnerable to being picked) with a
    third given. Either nobody has tried to steal your bike (which tells
    us nothing about the security of the lock - except perhaps as a
    deterrent) or they have and the lock
    offered sufficient protection against the methods used. It is a given
    that no one has (successfully) tried to pick it with the pen method.
    The probability of the bike being stolen has not changed because you
    know its vulnerable to the third - that depends on the thieves
    knowledge not yours. It certainly hasn't gone from 0 to 100%. Your
    perception of the risk has changed something like this.

    Of course it depends on the theives' knowledge, but where I disagree is
    that the knowledge, if sufficiently publicised, will turn more people into
    bicycle thieves. Unlocked bikes are certainly more vulnerable to theft
    than locked ones, that's for sure, and they are very, very likely to be
    stolen promptly if left in many areas. That proves there are potential
    bicycle thieves around in large numbers.

    Quoted message said:

    The fact that it has offered a reasonable degree of protection in the
    past indicates that it may well do so in future, what we now know
    however, is that a vulnerability exists which negates this existing
    protection. We should base our security on the knowledge of this
    vulnerability (which is an objective phenomena) not just on our
    perception of the risk. We can
    only do so if *we* know about it (we don't know what the thieves know)
    which is precisely why I argue in favour of the disclosure.

    I understand the logic but I wish the result could have been acheived in
    another way with less risk to us in the meantime. More and better
    pressurisation on the manufactures, for example. I know that was tried
    but I like to think it could have been tried harder, perhaps with stronger
    efforts to blackmail!, for want of a better word.

    ~PB

  18. Pete Biggs said:

    PaulM wrote:

    Quoted message said:
    Quoted message said:

    Bike thieves
    already have plenty of reliable methods of breaking locks without
    bothering to fiddle around picking them.

    Quoted message said:

    The pen method is not fiddly, apparently. That is the crucial point.
    It's supposed to be incredibly easy. Which again does make me wonder how
    the knowledge managed to stay underground for so long. I must admit I'm
    confused.

    I recall this method being discussed about ten years ago in very
    guarded language in motorcycle newsgroup postings which were careful
    to use "x-no-archive: yes" to keep the info out of the archives. A
    number of folk claimed to have written to the manufacturers then. The
    knowledge presumably stayed underground because all those who knew
    about were either keeping it secret for thieving purposes, or keeping
    it secret to stop too many thieves getting to hear of it.

    If the manufacturers had actually taken heed and quietly fixed it,
    which isn't hard, then this thing need never have happened. It seems
    only a very public shaming was enough to make them get off their butts
    and do something.

    Quoted message said:
    Quoted message said:
    Quoted message said:

    > Remember its alleged that Kryptonite have known about this since
    > 1993. If this is true then that is 11 years when bikes could and
    > have been stolen because this

    I've known about for about that long. And apart from newsgroup
    posters, I've mentioned it over the years, without giving away crucial
    details, to many fellow bikers, both motor and pedal, and have come
    across a few who also knew about it.

    Quoted message said:

    I do wonder why they bother with more difficult methods than using a pen.

    You need the right size of tube, and the right kind of
    plastic. Different locks have slightly different cylinder sizes. Bike
    thieves are often stupid and impetuous and unthinking, and after
    trying a few wrong pens without understanding they'd give it up as a
    silly rumour.

    Quoted message said:

    I understand the logic but I wish the result could have been acheived in
    another way with less risk to us in the meantime. More and better
    pressurisation on the manufactures, for example. I know that was tried
    but I like to think it could have been tried harder, perhaps with stronger
    efforts to blackmail!, for want of a better word.

    They were really stupid, because they could have fixed it quietly and
    just phased out the pickable locks. Now their hand has been forced,
    their reputation tarnished, lots of folk will go for other locks by
    other makers losing them market share, and they've lost a fortune with
    their replacement programme. Someone in the company must have
    convincingly made a case that they didn't need to bother fixing it --
    it's cheaper to make the pickable locks. Or else someone in the
    company decided to sit on the information rather than alarm folk
    uneccessarily. I wonder if he's going to get sacked?

    --
    Chris Malcolm [email hidden] +44 (0)131 651 3445 DoD #205
    IPAB, Informatics, JCMB, King's Buildings, Edinburgh, EH9 3JZ, UK
    [http://www.dai.ed.ac.uk/homes/cam/]

  19. Pete Biggs said:

    PaulM wrote:

    Quoted message said:
    Quoted message said:

    But you assume that only 'hardcore bicycles thieves' would have this
    knowledge if it hadn't been made public. I see nothing to warrant
    this.

    The fact that locks weren't picked in large numbers is enough to warrant
    that, I think.

    I don't think you can safely draw any conclusions from this fact. It is
    one explanation, but there are others: it could be that there are
    easier more relaible methods, or easier targets.

    Quoted message said:
    Quoted message said:

    If any thing I think that lock picking is a subject far more
    likely to interest 'mischievous kids' than hardcore bicycle thieves.
    Its precisely the sort of thing that bored, smart, curious kids get
    into - hence its prevalence as a subject of interest in hacker
    culture.

    They're not the ordinary kids on the street I'm thinking of. The geek
    kids don't tend to mix with the street kids!

    I'd like to know which kids you are thinking of. As a teenager I
    certainly fell
    into the category of either street kid and geek kid at various times,
    and sometimes both. In any case this is an assumption you are making
    and assumptions are bad things to base security on.

    Quoted message said:


    The pen method is not fiddly, apparently. That is the crucial point.
    It's supposed to be incredibly easy. Which again does make me wonder how
    the knowledge managed to stay underground for so long. I must admit I'm
    confused.

    Using words like apparently and supposed is something of a give away
    here. The only conclusion we can safely draw from the film I've seen
    (the original one) is that it can be done is a short time period given
    that you know how to do it. (to be really safe we should say 'for that
    brand of lock and pen'😉 It doesn't say that this method is easy,or
    foolproof, and the fact that others here have tried and failed cetainly
    suggests other wise.

    Even if we assume that it does mean these things it says nothing at all
    about the utility of this method versus others or the likelihood of it
    being applied.

    Quoted message said:

    Yes but I suspect it still didn't happen very much for some reason.

    Quoted message said:


    Quoted message said:

    It indicates nothing of the sort. There are plenty of reasons why this
    might be - primarily among them would be the fact that bike thieves
    already have plenty of other methods for stealing bikes as I point out
    above.

    I do wonder why they bother with more difficult methods than using a pen.

    Because they are in fact easier/quicker/more reliable/don't require you
    to carry around a carrier bagfull of pens in different sizes?

    Quoted message said:


    There are plenty of lazy/casual/low-risk-taking opportunists who steal
    only when it is very easy to steal. I've had plenty of lift-off
    accessories stolen from my bikes over the years, and I've had unlocked
    bikes stolen. I don't see why some of the same thieves wouldn't steal my
    locked bike if they knew how to *easily* overcome the lock.

    But we don't know that they can *easily* overcome it. I not sure its
    relevant though. The point about lift off thefts is that was no obstacle
    to the theft.

    Take wheels, for example. Its perfectly possible to remove a non-quick
    release wheel if you carry around a spanner/allen keys. This does not
    alter the fact that swapping from a quick release to a solid axle with
    nuts is a good preventative measure against wheel theft. Just the fact
    that you would have to carry and use tools is likely to deter the thief
    enough that the will move on and look for a bike with a quick release,
    despite the fact that it would be perfectly easy for them to steal it.

    Sadly such a theft did occur outside my house on sunday, but perhaps we
    can redeem something by using it as illustrative example. There were a
    large number of bikes locked up outside my house (12 or so) the theft
    only stole 1 wheel (from the most valuable looking bike) despite the
    fact that several of the bikes were vulnerable in this way (More so, in
    fact,since the bike in question was chained beneath two others). Why was
    this so, when there was nothing about the physical security of these
    bikes that would have prevented all thier wheels bing stolen?

    The answer, I would suggest, is that the thief made a simple judgement
    about the realtive value of the wheels versus the risk of getting caught
    stealing them and acted accordingly. The moral of thi story should,
    pehaps, therefore be that there is more to security than than just
    physical security - its all about manging risks.

    (as an aside there is a bike workshop in my house so I was at least able
    to provide a non-qick release repalcement for a minimal donation).

    Quoted message said:
    Quoted message said:

    I am not arguing that public disclosure does not entail an increased
    risk
    - it does, however this is outweighed by the benefits - allowing us to
    make informed choices about security.

    That's fine for those who can instantly afford to replace their locks with
    something better. That leaves an awful lot of people who's bikes are
    suddenly more vulnerable in the meantime while they find the money or
    time.

    What I'm struggling to understand is why to think it's a necessity to
    instantly replace the lock unless you believe the probability of this
    happening has jumped from next to nothing to something far more
    substantial - I don't think you can draw this conclusion from the mre
    fact of disclosure in the abscence of other evidence or a causal mechanism.

    I certainly fall into the latter category of people and haven't rushed
    out to replace my lock and am happy to use it in the knowledge that the
    degree of physical security is exactly the same as it was before (though
    the possibility of it being defeated might have changed). You have
    chosen to do so and have therefore, hopefully gained the reassurance
    that your lock is no longer vulnerable, I haven't and don't have this
    assurance but I have saved the cash, neither of us has had our bikes
    stolen. People are free to draw their own conclusions.

    Quoted message said:

    And where does it stop? Surely right at the top with the very best lock.
    Not everyone can afford that, period. The most secure locks won't
    necessarily be the most practical in every way either.

    But security isn't a matter of bigger and better locks, its a matter of
    managing risks, and there are no guarantee's - tht is what insurance is
    for. As I stated before I use a cheap £4 lock on my bike that is
    substantially more vulnerable than a kryptonite d-lock. There is nothing
    wrong with this as a security practice. The security of my bike is
    dependent on its (low) value and (un)attractiveness. Putting on a £40
    would not necessarily give any substantial rise in security - certainly
    nothing like a factor of 10. Arguably it might make it less secure
    since it could lead people to assume that it is more valuable than it
    appears.

    Quoted message said:

    We can broaden this out to society in general. Make security ever >
    tighter to deal with the select few criminals by making everything more
    impractical for most of us. I don't want to go far down that road.

    Neither do I. But (good) security is not about pileing on more and more
    features - its about managing risks. Thinking that it is so is a
    collary of an easy, but fatal mistake in security - basing security on
    things working not on them failing. This may seem paradoxical, it does
    make sense.

    With my existing bike I am fairly confident about the conditions under
    which it would fail - which is just anout any slightly determined
    effort. What I am making is a cost-benifit analysis of the cost of the
    security vs the cost of replacing the bike when it fails. In this case
    its practically zero (the bike was built of 2nd hand bits we had lying
    around the workshop) so I consider it worth spending £4 to stop someone
    walking away with it, but not anything more.

    I'm also currently building up another much more expensive bike I will
    be spending proportionally more on a lock for it. I don't expect it to
    categorically prevent it being stolen only to prove a deterrent relative
    to the value of the bike. I also expect it to ( or at least be vunerable
    to) fail- so I will also get insurance, as well as utilising other
    security measures, like keeping the existing bike for short urban
    trips/leaving locked up for long periods. In fact I may never need a
    lock at all (this is the case with my road bike).

    Similarly you would be wrong to assume that your new lock will prevent
    your bike being stolen - only that it is not vulnerable to this
    particular method - the fact that it is so says nothing about its
    susceptability to other methods.

    In the end what we do is balance the costs of risk versus the value of
    what we are trying to protect, and hopefully account for failure. We do
    this on our knowledge of the risks and of value. This varies on a case
    by case basis. A look at your message headers and a quick google shows
    you are using a client that has at least 8 vulnerabilites 4 of them
    unpatched. I would consider this a totally unacceptable risk. Either you
    don't (because you don't value computer security) or you don't have
    the requisite knowledge. Similarly I suspect your bike is more valuable
    than mine which it is why you chose to rush out and get a new lock - a
    perfectly good decision - while I have only very basic security in place
    - I am still making an informed decision based on my knowledge - which
    does vary form the first case, quite possibly, and why I think the risks
    of disclosure acceptable - because it always adds to my knowledge, but
    not necessarily my vulnerability.

    Quoted message said:


    Of course it depends on the theives' knowledge, but where I disagree is
    that the knowledge, if sufficiently publicised, will turn more people into
    bicycle thieves. Unlocked bikes are certainly more vulnerable to theft
    than locked ones, that's for sure, and they are very, very likely to be
    stolen promptly if left in many areas. That proves there are potential
    bicycle thieves around in large numbers.

    Unfortunately it doesn't - only that unlocked bikes will get stolen
    (which is tautological) it could be that exisiting thieves go for the
    low hanging fruit first.

    Quoted message said:

    We can

    Quoted message said:

    only do so if *we* know about it (we don't know what the thieves know)
    which is precisely why I argue in favour of the disclosure.

    I understand the logic but I wish the result could have been acheived in
    another way with less risk to us in the meantime. More and better
    pressurisation on the manufactures, for example. I know that was tried
    but I like to think it could have been tried harder, perhaps with stronger
    efforts to blackmail!, for want of a better word.


    Unfortunately real life experience tends to show otherwise (as another
    poster has pointed out in this case, and extensively in the case of
    computer security. One of the problems is that manufacturers have a
    vested interest in not making things safer in as much as this can cost
    more and cuts into profit - disclosure will certainly cost Kryptonite a
    lot - and unfortunately there interest and the interst of users can be
    diametrically opposed. The only guarantee I can see that things like
    this do get is if they are disclosed to the public and manufacturers
    lose any advantage in trying to keep things secret. Coupled with the
    fact that security is really about managed risk and we can only do this
    with knowledge I think the case for disclosure is compelling, though not
    without (some increased) rsik. The web page I pointed you goes into the
    benifits and risks of this, and why the former outweighs the latter.
    Bruce Schneier is an acknowledged expert on security and has a lot of
    very smart things to say about it.

    Paul M

  20. DT said:

    I would caution you about making accusations about who knew what and when
    in a public forum. In doing so one must be prepared to back them up or not
    at his or her own peril.

    Point taken.

    The allegation was widely reported - including in the link that I posted,
    that I see this page has since been changed.

    http://news.google.co.uk/news?hl=en&ned=uk&ie=UTF-8&q=kryptonite+1992&btnG=Search+News

    http://www.google.co.uk/search?hl=en&ie=UTF-8&q=kryptonite+1992+lock+pick&btnG=Search&meta=

    AC

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.