Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

111–120 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#111
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

I don't think fixing the software failure will improve DB's punctuality

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#112
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

I think the compensation given to software developers by companies that view software as their product has drawn many of the skilled software developers away from jobs that would have once grabbed them because of the fun factor. Companies that make things that contain software are not in markets prepared to pay 2 and 3 times what they were for software. What you are left with is people who are willing to accept that…

I think you are correct. Because the pay is so miserable the talent pool is mostly vba developing engineers from inside the company. Because of that they can’t hire good technical leads that know or can enforce good practices or design good architecture. The result is a giant mess of software in trains planes and automobiles

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#113
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

> No "boot times". They just worked

Haha wait until you find out how TVs worked in the 70s and how fast it was to change the channel *sob*

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#114

Earlier quoted context omitted.

I think the compensation given to software developers by companies that view software as their product has drawn many of the skilled software developers away from jobs that would have once grabbed them because of the fun factor. Companies that make things that contain software are not in markets prepared to pay 2 and 3 times what they were for software. What you are left with is people who are willing to accept that…

Facebook, Amazon, Netflix, Google, Twitter are not selling software but they are able to attract a lot of skilled developers

They all are selling software, with SaaS model.

You can compare this situation with Boeing. And issues they had with software of 737max.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#115
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

That is also my impression as well. The softwareization of trains has led to deep regressions in both basic reliability and interoperability/flexilibity. Many modern trains suffer from software issues for basic driving [0] and delays when getting the software approved [1]. But the loss of compatability is in my opinion the worst regression. Modern EMUs basically only work together with other EMUs of the same batch. Even the same model ordered by two different companies often don't work together and basically forget about trying to use EMUs of different companies or ordered over a decade apart together. Meanwhile pre-digital everything it was common to use e.g. trams of different generations together and rewire them to work with each other. Older train cars work together without issues, good luck trying to use an IC2 and a Railjet together (or a RailJet and ICE-L). Even certain locomotives and train cars would often only work with each other.

It is way harder for different computerized systems to work together due to the higher complexity and more obfuscation (a traditional logic circuitboard is often easily reverse engineered. Reverse engineering software is a very specialized task). This is also very noticeable in other sectors, where interoperability has become much worse due to moving to proprietary digital protocols.

This is in part due to the difficulty in getting software approved as compared to previous tech (due to software being so intransparent) but also because of truly lacking quality. One of the reasons Bombardier was so deep in trouble was bad software, even leading to a contract of over 40 ordered trains just being cancelled ([2]).

In my opinion building reliable (and understandable) software is way harder than building logic or even mechanical systems. I don't know what the solution is, but it's been a problem for a long time.

[0]: https://www.vrt.be/vrtnws/de/2013/02/12/belgische_bahn_storn... [1]: https://www.augsburger-allgemeine.de/augsburg/Neue-Zuege-auf... [2]: https://de.wikipedia.org/wiki/Bombardier_Talent_3#%C3%96BB

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#116

Dieselgate isn't a good comparison because in Dieselgate the equipment functioned normally from the user's point of view.

functioned normally? Intoxicating people with fumes is hardly what the user wants.

Some car users even do special modifications for "rolling coal", so that they can intoxicate other people with fumes.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#117
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

> No "boot times". They just worked Haha wait until you find out how TVs worked in the 70s and how fast it was to change the channel *sob*

Even in the 90s, you could just power it on and it would show image near-instantly. Warm-up time and channel switch time were all firmly under one second. With the exception of cable TV set-top boxes, which were separate devices and first to include the ridiculous boot times and delays, that still would seem blazingly fast compared to what we have today...

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#118

In a properly functioning country the responsible persons should already be imprisoned. Some governmental agencies were aware of that for at least half a year, but failed to act. The fact that source code was not immediately dumped and analyzed is the evidence of malevolence, corruption and intentionally putting people's lives at risk. Welcome to the dark side of Poland - where citizens don't matter.

"the responsible persons" ... hmmm. Who would that be? The programmer who implemented the code? Do you think they thunk these tricks up? They was just following orders. The manager of the programming team, who set these tricks as things that needed to be implemented? Again, just following orders. The "Cxx" Title people who directed that there be "some protection" in some way that got implemented as what we see? Did t…

That would be at least everyone knowingly involved with who is a professional engineer.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#119
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

Sometimes low-tech is just better. Here in Finland we got Sr1 electric trains from the Soviet Union in the 70's, and after some renovations the model is likely to stay in use at least until 2030.

Simply of old designs is often a blessing as long as the drawing and documentation is readable and good. It can be hard to get replacement electronics for 1970s designs so sometimes you have to design new components but the functionality was relatively simple back then so it’s possible to build a 1:1 replacement

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#120
post #4

But was this sabotage by an insider at the manufacturer, or something deliberate by the manufacturer?

Considering that the "sabotage" was intended to bring the company extra revenue by having non-faulty parts replaced and by requiring maintenance to be carried out by them and never third parties, it aligns with the company's own interests too much so to say "some employee did this without authorization".

"Deliberate by manufacturer" 100%.

The scarier part is that had this happened in the United States, DMCA would likely have protected them from prosecution, and the government might be liable for damages.

Post reply on HN