Roger Zoul said:
My guess is that even now this info won't spread far beyond the
internet.
Humm, there was an article in the Minneapolis Star Tribune today about it.
Reid
A community for cyclists, gear, training and racing.
Cycling Equipment · Public discussion
Thread navigation
Go to the original post, the replies on this page, or the latest preserved contribution.
Thread details
The navigation and discussion metadata provide context. Posts remain in their original chronological order.
Roger Zoul said:
My guess is that even now this info won't spread far beyond the
internet.
Humm, there was an article in the Minneapolis Star Tribune today about it.
Reid
On Fri, 17 Sep 2004 16:52:44 -0400, "Roger Zoul"
<[email hidden]> wrote:
[snip]
Quoted message said:As long as this exploit is relatively unknown, "victim" is not a fair term
since the presense of the big ass kryptonite still prevents bikes from being
stolen. My guess is that even now this info won't spread far beyond the
internet.
[snip]
Dear Roger,
That's what CBS was hoping about those forged documents.
Here's the AP article on the Bic pen trick, fresh from the
Daily Blat of Pueblo, Colorado:
http://www.chieftain.com/business/1095457153/1
It's not a bad summary of the internet coverage and appeared
the next morning.
Carl Fogel
Kyle.B.H said:
In Kryptonite's case however, nearly every lock in existence
is actually susceptible...very ugly.
Every lock in existence from every manufacturer can be picked. The
issue is which can be picked very easily. In this case, it is only
newer Kryptonite locks and some similar locks.
It is not every Kryptonite lock in existence that is suseptible to the
pen top picking.
JT
****************************
Remove "remove" to reply
Visit http://www.jt10000.com
****************************
Roger Zoul said:My guess is that even now this info
won't spread far beyond the
internet.
Yeah, it's not like it's being published in any newspapers, right....
JT
****************************
Remove "remove" to reply
Visit http://www.jt10000.com
****************************
Quoted message said:On Fri, 17 Sep 2004 16:52:44 -0400, "Roger Zoul"
<[email hidden]> wrote:[snip]
Quoted message said:As long as this exploit is relatively unknown, "victim" is not a fair
term since the presense of the big ass kryptonite still prevents bikes
from being stolen. My guess is that even now this info won't spread far
beyond the internet.[snip]
Dear Roger,
That's what CBS was hoping about those forged documents.
Here's the AP article on the Bic pen trick, fresh from the
Daily Blat of Pueblo, Colorado:http://www.chieftain.com/business/1095457153/1
It's not a bad summary of the internet coverage and appeared
the next morning.
There was an article in the New York Times today as well. I can't link to
the article on their site without subscribing to it, but if you have or
want a free subscription you can find it by searching for "kryptonite" on
their web site.
It was also in the Boston Globe yesterday:
http://nl.newsbank.com/nl-search/we/Archives?p_action=doc&p_docid=105264925E95AAB2&p_docnum=1
--
Benjamin Lewis
I regret to say that we of the FBI are powerless to act in cases of
oral-genital intimacy, unless it has in some way obstructed interstate
commerce. -- J. Edgar Hoover
Benjamin Lewis <[email hidden]> in
news:[email hidden]:
Quoted message said:Quoted message said:Victims? What garbage. What pathetic garbage.
Apparently this exploit has been know, but not widely publicized, for
at least ten years. It thus seems probable (to me), that someone at
Kryptonite was made aware of the possibility long before now. If this
is the case, and Kryptonite has been knowingly relying on "security
through obscurity", then I think "victims" is a fair term.
espec those who bought one, say, last week (not i)
--
"AWOL/Cheney, 1.? more years, woo hoo!."
"Roger Zoul" <[email hidden]> in
news:[email hidden]:
Quoted message said:As long as this exploit is relatively unknown, "victim" is not a fair
term since the presense of the big ass kryptonite still prevents bikes
from being stolen. My guess is that even now this info won't spread
far beyond the internet.
a woman in her 70's informed me of this, because she read an newspaper
article.
--
"AWOL/Cheney, 4 more years, woo hoo!."
Benjamin Lewis <[email hidden]> in
news:[email hidden]:
Quoted message said:d (apologies for the nested parentheses{no problem, [mister]})))
--
"AWOL/Cheney, ?.? more years, woo hoo!."
Roger Zoul said:Benjamin Lewis wrote:
:: Curtis L. Russell wrote:
::
::: On Fri, 17 Sep 2004 15:22:33 GMT, OliverS
::: <[email hidden]> wrote:
:::
:::: Unfortunately, such lawsuits seem
:::: to end with big fees for the lawyers and very little for the
:::: victims.
:::
::: I own four. They have done what they claim to do. Would I still use
::: it to lock a commuter bike up all day, based on the latest info?
::: No. But I got my $ 100 - 140 total investment back in spades. So
::: have most other owners of the locks.
:::
::: Victims? What garbage. What pathetic garbage.
::
:: Apparently this exploit has been know, but not widely publicized,
:: for at least ten years. It thus seems probable (to me), that
:: someone at Kryptonite was made aware of the possibility long before
:: now. If this is the case, and Kryptonite has been knowingly relying
:: on "security through obscurity", then I think "victims" is a fair
:: term.As long as this exploit is relatively unknown,
In addition to the local papers people are listing, it was on CNN.com today.
http://money.cnn.com/2004/09/17/news/midcaps/kryptonite/index.htm
Not relatively unknown anymore, I'm afraid.
-km
--
Only cowards fight kids -- unidentified Moscow protester
the black rose
proud to be owned by a yorkie
http://community.webshots.com/user/blackrosequilts
Dan Daniel <[email hidden]> in
news:[email hidden]:
Quoted message said:For those concerned about the Kryptonite tubular lock vulnerability,
here's an interesting article from a British web site-
and other bicpic bikelock articles are there.
http://money.cnn.com/2004/09/17/news/midcaps/kryptonite/
Kryptonite also said this is the first the company is hearing of the
problem. But according to BikeBiz.com, a British journalist discovered
the pen trick back in 1992. The newsletter said versions of the story
eventually appeared in several publications and on a BBC consumer rights
program
http://www.bikebiz.co.uk/daily-news/article.php?id=4637
In 1992, journalist John Stuart Clark - the cartoonist with
BicycleBusiness magazine, the print version of BikeBiz.com - teamed up
with a Nottingham bike thief to show how easy it was to break in to the
majority of bicycle locks then on the market. One of the methods he
revealed was the Bic pen method.
His article in New Cyclist magazine led to follow-ups in bigger
circulation bicycle magazines such as MBUK, and a BBC consumer rights
programme also carried a feature on the Bic method.
Despite the apparent ease of the method, most bicycle thieves, then and
now, prefer swifter, more strong-arm tactics, such as prising locks open
with car-jacks. Savvy consumers also use more than one type of lock,
thwarting the opportiunist thief only carrying tools for one type of
lock-busting.
The Bic method has therefore been known about for some time (begging the
question why it was never foiled by lock manufacturers) but it soon
disappeared from public view, until last week's posting by Brennan.
example of usenet threads in 92, 93
http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&threadm=
9ef657ec.0409162134.651e28ac%40posting.google.com&rnum=5&prev=/groups%
3Fsourceid%3Dnavclient%26ie%3DUTF-8%26q%3Dkryptonite%2B%257C%2B%
2522high%2Bsecurity%2522%2Block%2Bballpoint
http://makeashorterlink.com/?Y14D61F49
http://seattlepi.nwsource.com/local/191201_bikelocks17.html
"I'm not particularly happy to be talking about this," said Jake Jewett,
co-owner of Counterbalance Bicycles in Queen Anne. "I think doing a
story on this is a bad idea.
"It's going to give some people ideas."
Jewett himself tried the method after he read about it a couple of days
ago. He got into his own Kryptonite lock in 30 seconds. Another attempt,
however, and he couldn't get it to work. He said the store, popular with
bike messengers, counts the U-locks among its top-selling items
[predictable pov of a biz-yuppie. lock companies had (at least) since
1992 to redesign their locks.]
http://www.bikebiz.co.uk/daily-news/article.php?id=4637
The AP writer interviewed Jon Currier, an employee at Belmont
Wheelworks, who said the episode would not have a long-term affect on
Kryptonite because the company has fixed security glitches before.
[that's good.]
[videos listed in this bikebiz article, unknown filesize:]
http://thirdrate.com/misc/krypto.mov
http://biginjapan.com/extranet/asse...ev_disc_web.mov
http://biginjapan.com/extranet/asse...o_ev_speedy.mov
http://www.engadget.com/common/videos/pt/lock.wmv
http://gallery.iamjp.com/ids/albums...eo/MOV00104.MPG
--
"AWOL/Cheney, x.? more years, woo hoo!"
Curtis L. Russell said:OliverS said:Unfortunately, such lawsuits seem
to end with big fees for the lawyers and very little for the victims.I own four. They have done what they claim to do. Would I still use it
to lock a commuter bike up all day, based on the latest info? No. But
I got my $ 100 - 140 total investment back in spades. So have most
other owners of the locks.Victims? What garbage. What pathetic garbage.
Victims? I agree, it's a bit stong.
Seeing as I am now the proud owner of a 1 year old US$108 paperweight,
I'll remain merely one very, very [censored]-off ex*-customer.
Vic.
*If, as I expect, Kryptonite don't come through for their
existing/past cystomers, they won't get another penny from me.
- I'll buy another Abus Granite X-Plus for home use (I keep one at
work, so I don't have to tote a heavy lock around on a day-to-day
basis).
Roger Zoul said:My guess is that even now this info won't
spread far beyond the internet.
People were coming into my bike shop all day today, asking for a lock you
can't open with a pen.
I don't work in a very high-end bike shop, either.
the black rose <[email hidden]> wrote in
news:[email hidden]:
Quoted message said:Roger Zoul wrote:
Quoted message said:Quoted message said:As long as this exploit is relatively unknown,
In addition to the local papers people are listing, it was on CNN.com
today.http://money.cnn.com/2004/09/17/news/midcaps/kryptonite/index.htm
Not relatively unknown anymore, I'm afraid.
And the Boston Globe, and New York Times....
--
Mike Barrs
Looks like it's true - they just updated their web page with this info:
http://tinyurl.com/6wnf8
KRYPTONITE OFFERING FREE UPGRADE WORLDWIDE FOR CONSUMERS’ HIGH END
TUBULAR CYLINDER LOCKS
Unprecedented Offer Intended to Address the Needs of Loyal Consumers
Canton, MA September 17, 2004 - Kryptonite today announced it will
provide free product upgrades for certain locks purchased since
September 2002, in response to consumer concerns about tubular cylinder
lock technology. Consumers can visit the company’s Website
(www.kryptonitelock.com) on Wednesday afternoon, September 22, 2004, to
learn how they can participate in the security upgrade program.
Consumers who have purchased an Evolution lock, KryptoLok lock, New York
Chain, New York Noose, Evolution Disc Lock, KryptoDisco or DFS Disc Lock
in the last two years are eligible for a product upgrade free of charge
from Kryptonite. Customers will need to have either registered their key
number, registered for the Kryptonite anti-theft protection offer or
have proof of purchase to qualify.
Specifically, Kryptonite will provide for free cross bars featuring the
company’s new disc-style cylinder lock technology to consumers who have
purchased Evolution and KryptoLok series products. In addition the
company will replace for free recently purchased Evolution Disc Locks on
New York Chain and New York Noose with its “Molly Lock”, a heavy duty
solid steel padlock. Kryptonite also will upgrade recently purchased
disc locks.
Consumers who have had one of the Kryptonite locks mentioned with a
tubular cylinder for longer than two years will be eligible for a
sizeable rebate on the upgraded products. This program will be
administered through Kryptonite dealers and distributors.
A distributor and dealer swap program will be rolled out through direct
communication from Kryptonite to all its partners.
Full details about this unprecedented program will be available on
Kryptonite’s website by afternoon Eastern Standard Time, Wednesday,
September 22, 2004, at www.kryptonite.com
--
My bike blog:
http://diabloscott.blogspot.com/
I wonder how far back the defective locks go. More than 2 years,
maybe? I've been looking at every Kryptonite lock I came across today,
and none of them had the Ace II cylinder they once used. I get the
impression from reading up on lock picking on the web that those are
harder to beat, even may be resistant to the bic pen for several
reasons that include a thicker post in the center that won't admit the
pen barrel easily. If lock pickers have a hard time with this model,
why did Kryponite stop using it? I'm just glad I still have my old
Kryptonite 5 locks for both my bikes.
You got to be very careful if you don't know where you're going, because you might not get there.
- Yogi Berra
the black rose wrote:
|| Roger Zoul wrote:
||| Benjamin Lewis wrote:
||||| Curtis L. Russell wrote:
|||||
|||||| On Fri, 17 Sep 2004 15:22:33 GMT, OliverS
|||||| <[email hidden]> wrote:
||||||
||||||| Unfortunately, such lawsuits seem
||||||| to end with big fees for the lawyers and very little for the
||||||| victims.
||||||
|||||| I own four. They have done what they claim to do. Would I still
|||||| use it to lock a commuter bike up all day, based on the latest
|||||| info?
|||||| No. But I got my $ 100 - 140 total investment back in spades. So
|||||| have most other owners of the locks.
||||||
|||||| Victims? What garbage. What pathetic garbage.
|||||
||||| Apparently this exploit has been know, but not widely publicized,
||||| for at least ten years. It thus seems probable (to me), that
||||| someone at Kryptonite was made aware of the possibility long
||||| before now. If this is the case, and Kryptonite has been
||||| knowingly relying on "security through obscurity", then I think
||||| "victims" is a fair term.
|||
||| As long as this exploit is relatively unknown,
||
|| In addition to the local papers people are listing, it was on
|| CNN.com today.
||
|| http://money.cnn.com/2004/09/17/news/midcaps/kryptonite/index.htm
||
|| Not relatively unknown anymore, I'm afraid.
Definitely so. So, if you believe that this exploit has been there 10 years
already then there has been few victom so far. Of course, that's about to
change bigtime!
Benjamin Lewis wrote:
|| Roger Zoul wrote:
||
||| As long as this exploit is relatively unknown, "victim" is not a
||| fair term since the presense of the big ass kryptonite still
||| prevents bikes from being stolen.
||
|| I disagree. I don't believe it is a reasonable or fair thing to
|| force your customers, unknowingly, to risk, while painting big
|| pictures of the invulnerability of your locks.
I don't think people were being forced to do anything. I'm just saying that
I don't think that people were victims since the presense of that heavy ass
lock very likely had the value of preventing bikes from being stolen.
Apparently that value has been lost, and even with an ungrade that lock is
more likely to be challenged in the future.
||
||| My guess is that even now this info won't spread far beyond the
||| internet.
||
|| It already has. Just think of the percentage of cyclists who have
|| internet access these days. It's been on the news, and Mountain
|| Equipment Co-op and other bike stores have removed these locks from
|| shelves. I assume that this is happening at stores in the States as
|| well. Someone claimed in another post (sorry, don't remember which
|| thread, or even which cycling mailing list and newsgroup I read this
|| in. It's hard to keep straight, since this news is being discussed
|| in every single one of about 6 I'm subscribed to (the first
|| reference I saw was from bikeforums, which I do not personally read
|| (apologies for the nested parentheses))) that distributors have got
|| "stop selling these locks" memos from Kryptonite.
Well, I can't argue that point anymore since apparently internet aware
cyclist have made it well known now. That's a good think.
BTW, I have no idea of the percentage of cyclist who have internet access
these days. I would assume it follows that of the general population.
Quoted message said:the presense of that heavy ass lock very likely had the value of
preventing bikes from being stolen.
The Evolution 2000 was never a "heavy ass lock".
It is a two pound (at most) side key entry coke machine key U-lock
with a plastic dust slide over the keyhole.
Not a New York Chain.
More than adequate for casual commuter or messenger parking in low
crime, heavily trafficked areas.
Not a deterrent for overnight street parking in the ghetto of your
choice.
--
_______________________ALL AMIGA IN MY MIND_______________________
------------------"Buddy Holly, the Texas Elvis"------------------
__________306.350.357.38>>[email hidden]__________
Kyle.B.H said:
"Blair P. Houghton" <[email hidden]> wrote in message
news:[email hidden]...Quoted message said:Kyle.B.H said:Hopefully one of Kryptonite's execs did this case in B-school. They have
noQuoted message said:
Better case: Intel's FDIV bug.Intel set up a $400 million fund to cover returns of Pentium
chips with this very-well-publicized bug (most chips have
literally hundreds of bugs that are known to the public
but never make CNN). They wrote that $400M off, which
was ignored by the market as the publicity had already
discounted the stock. After three years, they had spent
about $100 million of it, and the returns had slowed to
a trickle. They booked the spare $300M as revenue, and
the stock popped.So yeah, if Krypto's execs are serious B-school types,
they'll be looking at this as a way to get even on the
media hype.The problem is, the life of a krypto lock is much longer than that of a
Pentium, and the problem with them actually can affect someone, unlike the
Pentium glitch. I think Krypto will offer a trade-in, but it won't be free.
The FDIV bug could invert an airplane mid-flight.
The only reason Intel offered the extra return service
was because of the PR hit it was taking.
This is also the only reason Krypto is bothering with
replacements for old parts.
Any other situation, they'd redsign the lock and offer the
new model with the fix as a marketing bullet.
--Blair
"It's not about how much you care,
it's about how many of you care."
Blair P. Houghton said:Kyle.B.H said:Hopefully one of Kryptonite's execs did this case in B-school. They have no
Better case: Intel's FDIV bug.
Intel set up a $400 million fund to cover returns of Pentium
chips with this very-well-publicized bug (most chips have
literally hundreds of bugs that are known to the public
but never make CNN). They wrote that $400M off, which
was ignored by the market as the publicity had already
discounted the stock. After three years, they had spent
about $100 million of it, and the returns had slowed to
a trickle. They booked the spare $300M as revenue, and
the stock popped.
Hmmph. The company I was working with back then had just bought a new
box, and we immediately filed for an update. Dell rep: "You really
only need this if you're doing rocket science." Our guy: "We're doing
finite element analysis for a rocket payload." Dell: "OK, we'll put
you on the list for a replacement."
Never got anything from them. Dell claimed Intel didn't ship them
replacement parts.
So yeah, it's a great publicity gig. But then again, the last time I
had any input into computer purchases, we bought a dozen AMD boxes...
Pat
Email address works as is.
Active in the last 60 minutes
0 users · 0 guests ·0 bots ·0 total
No signed-in users are active right now.
No known search crawlers active right now.