Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

21–30 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#21
post #14
post #13

Earlier quoted context omitted.

To what end? So they can sell more trains? That makes no sense.

>The train manufacturer, Newag, also competed in the tender to carry out the maintenance, but the manufacturer’s bid was about 750k USD higher and the tender was eventually won by SPS, which offered to carry out the maintenance of 11 trains for around 5.5 mln USD.

Just thinking outloud. But if you made it so your competitor couldn't fulfill their servicing contract, then the entity taking out the contract might just very well come to you to solve the problem. You might not win the contract on price, but win it by default because you made it impossible for anyone else to complete it.

That is until your scheme is uncovered because you left the GPS coordinates of your competitors workshops in your code.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#22
post #18

Dieselgate isn't a good comparison because in Dieselgate the equipment functioned normally from the user's point of view.

I think it is because the equipment changed dependent on context. In Dieselgate the cars changed their engine management when they got into a test cycle...

Dieselgate was about cheating environment sensors. This is more like DeereGate, locking out external service shops but even when you are supposed by law to allow them service (and even after providing them 20k page service manuals which they are supposed to follow to make appropriate service, but you lock them out anyway).

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#23
post #14
post #13

Earlier quoted context omitted.

To what end? So they can sell more trains? That makes no sense.

>The train manufacturer, Newag, also competed in the tender to carry out the maintenance, but the manufacturer’s bid was about 750k USD higher and the tender was eventually won by SPS, which offered to carry out the maintenance of 11 trains for around 5.5 mln USD.

Every once in a while there comes a point where the discussion of high-currency-shorthand pops up:

>5.5 mln USD. U$5.5m? Not saying I'm more correct than anyone else, but the former seems outlandishly long.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#24
In a properly functioning country the responsible persons should already be imprisoned. Some governmental agencies were aware of that for at least half a year, but failed to act. The fact that source code was not immediately dumped and analyzed is the evidence of malevolence, corruption and intentionally putting people's lives at risk.

Welcome to the dark side of Poland - where citizens don't matter.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#25
post #17

Earlier quoted context omitted.

There wasn't just one manufactured failure, but multiple different ones. Refusing to help would also point towards intentional malice. Why would you sell a product, then refuse to assist, unless you've intentionally designed the product to fail so only you would know how to make it work again?

The manufacturer lost the bidding process, so quite reasonably (if you look at it in a limited fashion) said "Fine, let SLS do the work, you're on your own". Arsehole-ish, but not illegal. All the hidden lockouts on the other hand....

They knew that SLS would not be able to do it.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#27

In a properly functioning country the responsible persons should already be imprisoned. Some governmental agencies were aware of that for at least half a year, but failed to act. The fact that source code was not immediately dumped and analyzed is the evidence of malevolence, corruption and intentionally putting people's lives at risk. Welcome to the dark side of Poland - where citizens don't matter.

Corruption is not just the dark side of Poland, but the entire west IMHO

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#28
My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland had similar problems in 2018 [1].

As a computer scientist, I find this embarrassing. Just compare these modern trains to the old trains built in East Germany [2] during the 80ies that were pulling old West German carriages [3] from the 50ies here until recently. Minimal or no usage of digital electronics. No "boot times". They just worked. And if they didn't, the train driver usually knew where to hit the engine with a hammer to fix it. You cannot expect a train driver to hack into the train firmware and fire up gdb to find out why it doesn't move.

[0] https://www.sueddeutsche.de/wirtschaft/deutsche-bahn-ic-1.47...

[1] https://bahnblogstelle.com/33872/twindexx-swiss-express-soft...

[2] https://de.wikipedia.org/wiki/DR-Baureihe_243

[3] https://de.wikipedia.org/wiki/N-Wagen

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#30
Great advert for free and open source software.

As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job.

Can't trust the software. Can't trust the institutions that write the software.

All very "late stage capitalist software development".

Post reply on HN