Live data from Hacker News

VanMoof encryption key exporter

github.com

131–140 of 224 posts

Re: VanMoof encryption key exporter

#131
post #28

Earlier quoted context omitted.

How on earth are they losing money selling a 3000-5000$ _bicycles_ lol. I'm flabbergasted.

They spent a lot of money on expansion, opening stores in places like NYC and Tokyo. I'm also betting that since all the parts in their bikes are custom-produced for them, the production cost of their bikes is quite high as well (that is, they're not making that much money per bike).

Then why do they do it? What is the supposed gain from producing your own parts, when mass produced parts like Shimano are available all over the world? Is it to increase sales of their repair services after the warranty ends?

Re: VanMoof encryption key exporter

#132
post #9

I'm just now hearing about VanMoof failing. This is surprising, considering these bikes seem to have pretty meh build quality and are being priced much higher than one would expect.

I've got an X3 that is rock solid even after me and the bike flying apart in an attempt to avoid collision with a truck. And its design is the primary reason why I decided to start biking again to begin with - I just find it so pleasantly satisfying I just want to ride it. So IDK, but I haven't seen a viable alternative yet.

The S/X3 was the worst bike they made. I regret foolishly 'upgrading' from S3 to X3. The eshifter in it was notorious for reliability.

I'm convinced the S/X3 is why the company is going under.

Re: VanMoof encryption key exporter

#133

A cursory look at the code and this seems legit, nothing that would steal my login credentials. It's a small codebase. I'm curious how long the hardcoded api key here will work, though: https://github.com/grossartig/vanmoof-encryption-key-exporte... used in https://github.com/grossartig/vanmoof-encryption-key-exporte...

I assume that's the key used by the app. So if they kill that key, they also kill all existing applications.

That's the thing with this kind of "protection". If your proprietary app needs to access the server, anybody who can either extract the key from the app with reverse engineering or who can listen in on the communication between app and server will be able to use that API.

It's the same issue as with DVD encryption: If you need to show the movie to people, people need to be able to decrypt it. If this needs to happen offline, then the material needed for decryption must be static and either be on the disk on in the player - where it can be extracted and used by third parties.

Re: VanMoof encryption key exporter

#134

Earlier quoted context omitted.

You don't need an internet connection or the app, but that's the most convenient way - you can enter a PIN on the bike itself to unlock it. I think the appeal (at least for me, I considered one but never got one) is that it makes the bike harder to steal. Someone can't just ride off on it after they cut your lock. I worry about leaving my $600 bike out in public, so I'd be super paranoid about a $2000+ bike.

How does it prevent the thief from riding away? Does it block the pedals using the motor or something?

Kind of. There's a pin in the rear hub that physically engages when locked, preventing the wheel from turning.

Re: VanMoof encryption key exporter

#135

A cursory look at the code and this seems legit, nothing that would steal my login credentials. It's a small codebase. I'm curious how long the hardcoded api key here will work, though: https://github.com/grossartig/vanmoof-encryption-key-exporte... used in https://github.com/grossartig/vanmoof-encryption-key-exporte...

I don't know anything about these bikes; but what is one supposed to do once they retrieve their keys? Does the app/bike provide an alternative method of presenting the key? Are keys rotated, so they need to be downloaded more than once (I assume that's that's the case since this code is intended to be run as a service, in a Docker container)? If so, what happens when their servers do shut down and there is no API? A…

The keys in this case are used for bluetooth comms locally between somebody's device and their bike.

These are ordinarily used by the VanMoof app to unlock the bike and control the bike's settings.

There are already some third-party apps (Moofer, Mooovy) to allow alternate access to those settings – including some hidden ones.

With a few tweaks those third-party apps should be able to support direct key upload, rather than having to log in and proxy authentication through to VanMoof's API.

Re: VanMoof encryption key exporter

#136
post #124
post #23

Earlier quoted context omitted.

What did Van Moof make, exactly? Do you think they were normal bikes? They made expensive e-bikes with theft recovery features. They have features that make it possible to trace and locate them, and Van Moof would actually do this. For people who spend €3-4k on an easily stolen object that the police won't care about, that's a unique selling point.

An AirTag is $30. So yeah, what did they make?

You're implying that about $30 is enough to build something airtag-like into a bike? Can you describe how? I'd be happy to learn just for myself (I'd love to do something like that with my expensive bike) but you get bonus points if the scheme is usable for a business, ie. doesn't rely on Apple's benevolence or ignorance.

Re: VanMoof encryption key exporter

#137
post #80

Earlier quoted context omitted.

> This is not expensive at all. I mean, you can get a regular bike for €300, €700 if you want to splurge. But of course, the downside of that would be that you'd get more exercise.

I mean, you can also easily spend >2k on a bike. In terms of e-bikes the prices for Vanmoof and their competitor Cowboy aren’t particularly cheap, but they aren’t incredibly out of line either.

> I mean, you can also easily spend >2k on a bike.

And what you would have is an expensive bike. $2k is an expensive bike.

The fact the market offers a $3,000,000 car doesn't mean a $100,000 car isn't an expensive car.

Re: VanMoof encryption key exporter

#138
post #61

Earlier quoted context omitted.

That’s a common waiting time at my local bike shops to be honest. The difference is that you can do most stuff on a normal bike yourself with off the shelf parts (supply chain woes permitting).

What is local for you? In Amsterdam a 6 minute waiting time is more common if you have a regular bike.

Not OP, but I live in Munich and have heard of both six-week and one-day waiting times this summer. It depends on part availability. One day is common, six weeks not unheard of. A friend waited almost that long when two strange and unusual screws had to be replaced, the wrong ones arrived from the manufacturer, etc. The quick routine procedures failed her, the result was slow.

Just from what I hear, it seems that there are more cases of unavailble parts this summer than a few years ago. Maybe the supply chains haven't quite settled after covid, even now.

The person who mentioned six weeks didn't specify whether Van Moof has a six-week average or whether it's a 99th percentile.

Re: VanMoof encryption key exporter

#139
post #122
post #91

Earlier quoted context omitted.

They are expensive for what is essentially a commuter bike. I think they simply chose a wrong strategy, because if you have a cheap(ish) bike and a good U-lock, you can leave it anywhere without much stress. It will most probably not be stolen (because the value of the bike is low), and if it does get stolen, then it is cheap to replace - you can buy at least 5 commuter bikes for the price of a fancy one. In fact, in…

They wouldn't be expensive for that price if they used quality parts and assembled them well (I don't think VanMoof offered a good deal because those crucial aspects were lacking). The market for a quick city e-bike is a bit different than the one for a throwaway commuter bike. People pay for being faster and enjoying the ride. Accordingly, I would make sure such a bike is insured against theft and use a quality lock…

Having a non-removable battery is a big mistake IMHO, because that's a not insignificant chunk of the value of the bike. Also, it's just a normal e-bike, limited to 25kmh, I wouldn't call that "quick" :) If you want a real quick commuter then get one with a 45kmh limit, that is the point when it kind of stops being a bike and turns into a vehicle. But I think the target market is different in this case, I wouldn't leave a vehicle like that outside my property overnight, that means I need to have a garage or easy living room access. None of this matters for a simple commuter bike.

Re: VanMoof encryption key exporter

#140
post #63
post #3

Don’t buy products made by VC funded firms! Especially not if it’s a real product and you value repairability and service. VanMoof made losses the size of their revenue. They made bikes… where’s the natural monopoly to be chased there?

While I think you're right, you could have said the same thing about Tesla cars - but it worked out in that case. The problem with VanMoof was that they prioritized growth over quality - which may be a side effect of taking VC money, but is plain dumb if you're selling physical goods that are expensive to fix. Just talk to anyone with a VanMoof or see the subreddit: Nearly every bike they sold required multiple repai…

I was thinking about Tesla while posting. It's the natural counter argument. That's why I specifically mentioned the target market (in my opinion): bikes. (One of the reponses above is critical of my target market definition. Hey, I'm Netherlands-based. Two wheels is a bike. Whether € 10 or € 10k. I can understand that theft and bike services are more of a US value proposition.)

The thing is I think Tesla pulled off a near miss with their repairs, waiting times and general inavailability of spare parts. That was a very big issue for a few years. Tesla got a helping hand (in several European countries at least) in tax breaks for the electric early adopters. With the tax brakes came the premier buyer: lease companies (say NED / BEL). You know what lease companies are good at? Supply chain management on behalve of their customers. If a Tesla was out for repairs for a month, the lease company had to deliver a temporary car. The tax brakes for the consumers kept the demand up, no matter the service record. No tax incentives helping VanMoof.

Second is that I think the disruption Tesla caused in the car market at that time was a lot larger than that of VanMoof. As others point out: VanMoof didn't leapfrog (e-)bike market and didn't get a temporaty moat. They were actually a late to pivot to electric. Their earliest models were based on non-electric, affordable and robust (as a buyer at that time: they weren't robust at all). Then by playing the high margin-high marketing angle they just weren't a viable option in the price range where quality starts to matter.

All in all: Tesla got a temporary technological head start with some favourable tax headwind giving them just enough runway to manage the supply chain. VanMoof had no technological head start, no tax incentives and crashed and burned on the supply chain.

Post reply on HN