Earlier quoted context omitted.
Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.
An organisation that is prepared to write "sabotage" software would have no problem deploying software that is different to the software they submit.
Dieselgate, but for trains – some heavyweight hardware hacking
101–110 of 309 posts
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#102Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".
Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#103Earlier quoted context omitted.
If the manufacturer did it, doesn't it still fit the definition? It's something like "deliberately causing something to fail", regardless of who does it.
While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#104Nevermind malware, not using seL4 should already be a crime in this context.
This is a case of fraud, industrial malfeasance and just plain dishonesty. The software component of the story and its security measures are not even at play. Sure they are probably shit (given the date parsing ...) but even FreeRTOS would make an amazing OS *IF USED PROPERLY *.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#105Earlier quoted context omitted.
Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.
That would work only on paper. The financial interests involved are huge.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#106Earlier quoted context omitted.
While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used
Newag was required by contract to provide accurate service manuals so that competitors could safely maintain the trains. This was not a "just take your car to dave, he knows some stuff". For SPS and other competitors this was like "you need to show every certification that exists and certify all your tools to prove that indeed you can service those cars, or you will be foreclosed due to fines". Plus, they were provid…
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#107Newag issued a statement since, denying all allegations and saying that it was their competition which "hired hackers to slander them". I've met q3k because we used to work at the same company and briefly on a project together. Not the kind of person I would suspect of participating in a conspiracy of this sort and Newag's statement generally reads like "we didn't think we would get caught".
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#108Earlier quoted context omitted.
What is the cause then?
Bad culture that views software as a necessary evil or afterthought rather than an important part of the product.
It's probably true of lots of aspects of product design - if it's not driven from the top, it's mediocre.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#109Earlier quoted context omitted.
I don't think it's assholeish for someone who's not getting compensated in any way to not help out. It's a business. They have an active incentive to NOT help.
It's not about "not wanting to help". It's about placing logic bombs of "if vehicle is at this gps coordinates of a competitor, engage self-destruct". Hackers actually did extract such coordinates from train firmware.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#110Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".
I'm all for free and open source software, but what would you suggest here? That train operators will download code from the internet and install it on their trains?
In most OECD countries food needs to be labelled with a full list of ingredients.
Your GP can read scientific papers about the efficacy and risks of a new treatment.
(Yes, many papers are paywalled but that's irrelevant compared to secrecy)