Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

141–150 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#141
post #137

>it is hard to find an institution in Poland that has done anything beyond kindly expressing interest in the matter. We are not aware of any action taken either by the Office of Consumer and Competition Protection or by the Railway Transport Office, That the worst part of all that.

The government anti-corruption office is formally investigating this now, which means almost certainly people will end up going to jail. The office of consumer protection doesn't have anywhere near the power these guys have.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#142
post #121

Earlier quoted context omitted.

If an individual did this, they'd go to prison.

Companies are made up of individuals. I'm all for holding everybody who contributed to this malware accountable.

Unfortunately that is why fall guys were invented. I never liked the idea of punishing a company based on their revenue, but in this kind of case that is the only way to get the actual owners of the company to listen and punish the people actually responsible.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#143
post #53

Nevermind malware, not using seL4 should already be a crime in this context.

We have rovers on Mars and satellites and probably nuclear warheads using RTOS of all kinds and in cases even Linux, but sure seL4 is the only OS conceivable for those cases, obviously ! This is a case of fraud, industrial malfeasance and just plain dishonesty. The software component of the story and its security measures are not even at play. Sure they are probably shit (given the date parsing ...) but even FreeRTOS…

>using RTOS of all kinds and in cases even Linux

Absolutely, and thus there's obvious room for improvement.

>This is a case of fraud, industrial malfeasance and just plain dishonesty.

In practice, this amounts to critical infrastructure sabotage, which fits into terrorism.

If the train network experiences issues, the whole country is impacted.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#144
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

If an individual did this, they'd go to prison.

You could very seriously start a war by doing things like this.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#145
post #32

Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".

Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.

> can still require the manufacturers to privately submit to the government all code

I wonder if companies purchasing trains could put code disclosure in the purchase contract? I wonder if, in aggregate, train purchasers or car purchasers could fund an independent code storage vault and pay a small premium to fund that code vault organization?

In other words, if purchasers wanted this and valued this, they would demand it in purchase contracts and fund it.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#146
post #77

Earlier quoted context omitted.

If the manufacturer did it, doesn't it still fit the definition? It's something like "deliberately causing something to fail", regardless of who does it.

While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used

On #2, that's sabotage. Also, on #3, that's sabotage too.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#148
post #72

Seems like deliberate sabotage via software to force the costumer to buy the manufacturer’s services instead of 3rd party (cheaper) ones. Curious to see the court’s decision.

There’s no question that it’s sabotage. The only thing left to prove is the culprit, which is with 99% the manufacturer (motive, means, opportunity) but obviously need to be established in a court who is responsible and criminally culpable. The fact that lawmakers, courts and the public are lost in the tech is a problem, but surely this crime can be fitted into existing criminal code against sabotage… although the me…

"Lawlessness is the condition in which your adversary refers you to a law he made."

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#149
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

It will be stuck in legal hell due to conflicts of interests. Trains already exist, and they need to work - but maintenance/repair companies cannot legally modify software of them due to copyrights. It's a catch22 situation.

I honestly hope that company will be fined to the oblivion, and for criminal charges for that, but i doubt it will happen.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#150
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

If an individual did this, they'd go to prison.

It's funny how, in the western world, as a company, you can commit crimes and take a pat on the wrist, but, as an individual, you get to jail for the same crimes.
Post reply on HN