Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

151–160 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#151
post #109

Earlier quoted context omitted.

It's not about "not wanting to help". It's about placing logic bombs of "if vehicle is at this gps coordinates of a competitor, engage self-destruct". Hackers actually did extract such coordinates from train firmware.

unless we have the entirety of the context for this code and the 20,000 pages of service manuals, i do not accept at face value that it's this simple

Any kind of GPS coordinates, especially those of competitor facilities in the firmware of a train is proof positive that something really bad is going on.

Context and manuals are just so much smoke and fail to obscure the facts.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#152
post #108
post #60

Earlier quoted context omitted.

Bad culture that views software as a necessary evil or afterthought rather than an important part of the product.

Same as industrial design then. You get the occasional Braun, Herman Miller or Apple, and a vast number of nondescript silver/beige/black boxes. It's probably true of lots of aspects of product design - if it's not driven from the top, it's mediocre.

Yeah, unless the engineers are using the product themselves. People in general seem to take care of their own tools. Much harder to get them to look after a product they don’t use themselves.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#153
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

Because this software is not made by software engineers, it's made by plc programmers, electric circuit designers and whoever did drift into the field. Except for beckhoff to tc3 they haven't made it to object orientation yet, so the field is stuck as a whole in the blue screen mines of yore. Managing complexity with thin standard docs, no version control while the machines grow ever more complex sensor and actuator…

100% agree with this. IMO there are a few efforts to modernize PLC programming but I feel like they are still stuck in the 1990s software development. Take a look at Codesys, got Git support few years ago and in very bad shape. How do you test your code, in the field or buy another Codesys testing plugin....which is in rough shape.

The issue is as machines get way more complex this issue gets worse. Also there are generations of PLC devs that still want to stick with ladder logic. Huge fragmentation.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#154
post #13

Earlier quoted context omitted.

There wasn't just one manufactured failure, but multiple different ones. Refusing to help would also point towards intentional malice. Why would you sell a product, then refuse to assist, unless you've intentionally designed the product to fail so only you would know how to make it work again?

To what end? So they can sell more trains? That makes no sense.

After sales support, as in spare parts and maintenance, is a big part of income for manufacturers of heavy equipment, as such machines run for a loong time given parts and maintenance. To me they really did not want to lose on 'subscription money' in the form of service contracts they missed out on. It came close to the operator coming back to them to fix the trains 3rd party seemingly couldn't.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#155
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

I think the compensation given to software developers by companies that view software as their product has drawn many of the skilled software developers away from jobs that would have once grabbed them because of the fun factor. Companies that make things that contain software are not in markets prepared to pay 2 and 3 times what they were for software. What you are left with is people who are willing to accept that…

> Companies that make things that contain software are not in markets prepared to pay 2 and 3 times what they were for software

The quality of SW has nothing to do with the pay. Notice that FAANG SW developers do not deliver safety critical SW.

There are more things to SW development than writing code.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#156

Earlier quoted context omitted.

Corruption is not just the dark side of Poland, but the entire west IMHO

The west is the least corrupt part of the world. https://en.wikipedia.org/wiki/Corruption_Perceptions_Index#/...

Note from that wikipedia article

>The Index only measures public sector corruption, ignoring the private sector. This, for instance, means the well-publicized Libor scandal, Odebrecht case and the VW emissions scandal are not counted as corrupt actions.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#157
post #131
post #73

Earlier quoted context omitted.

More sanely (not to be confused with likely!) the courts will decide that since this is something only the OEM can do, it must done at no charge as part of normal warranty work.

These trains will be used for decades. Normal warranty wont cover anything of note.

Warranty should cover this - if the manufacture won't let it be fixed by someone else than in should be free.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#158
post #137

>it is hard to find an institution in Poland that has done anything beyond kindly expressing interest in the matter. We are not aware of any action taken either by the Office of Consumer and Competition Protection or by the Railway Transport Office, That the worst part of all that.

When the companies see that this behavior is not punished, they'll basically need to implement their own versions of it to stay competitive!

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#159

I wonder if the solution to all these screwy engine controls (tampering with emissions testing, preventing 3rd party repairs, etc.) is to standardize the interfaces to these systems so they can be replaced. Standardizing the outputs of the sensors would let us swap in and out various components to ensure the system is not cheating the regulators.

F1 does this. All teams are required to run the same, approved, ECU[1]. They can change certain mapping tables and such but it's a sealed unit and they can't replace the firmware. [1]: https://wheelsports.co/formula-1s-standardised-ecu-explained...

This is quite interesting because you can imagine that lobbyists would argue that standardization would “stymie innovation.” If F1 does it why can’t you?

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#160
post #137

>it is hard to find an institution in Poland that has done anything beyond kindly expressing interest in the matter. We are not aware of any action taken either by the Office of Consumer and Competition Protection or by the Railway Transport Office, That the worst part of all that.

When the companies see that this behavior is not punished, they'll basically need to implement their own versions of it to stay competitive!

It’s cute that you think they haven’t done that already…
Post reply on HN