Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

181–190 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#181
post #159

Earlier quoted context omitted.

F1 does this. All teams are required to run the same, approved, ECU[1]. They can change certain mapping tables and such but it's a sealed unit and they can't replace the firmware. [1]: https://wheelsports.co/formula-1s-standardised-ecu-explained...

This is quite interesting because you can imagine that lobbyists would argue that standardization would “stymie innovation.” If F1 does it why can’t you?

One could easily argue that F1 hasn't innovated much in the last decade or so. The coolest stuff we get is clever aero and advantageous workarounds that get outlawed extremely fast.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#182

Earlier quoted context omitted.

Here it's more like the software - any software - is a problem . I agree with GP, and my experience confirms that adding software to something that used to work without it almost universally makes it worse in every aspect, understandability and repairability being just two major ones. On top of that, taking anything that run on old-school industrial/embedded firmware and replacing that with software using modern prac…

That again is a problem of leadership and not of software.

> That again is a problem of leadership and not of software.

SW has an input problem and a testability problem. On one hand, the inputs to the SW are not limited (iMessage happily accepts any image file) and testing is limited to some known inputs. Software vulnerability assesment (worst case analysis) is usually performed outside of the development process at very high costs and limited outcome.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#183

Title is a bit misleading, because this *gate is not about faking ecology, and trying to pass certification in artificial conditions, as dieselgate was, but simulating fake failures instead. The company hardcoded algorithms that would report failures of parts that work correctly (like a compressor), if it detected that train has been repaired by another company (based on location readings), and stop the train from ru…

It's an example of fraudulent / malicious behavior found by decompiling industrial logic controllers, with incontrovertible evidence of illegality. Obviously no two situations are ever going to be the exact same, but I think it's clear why the analogy was made.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#184
post #159

Earlier quoted context omitted.

F1 does this. All teams are required to run the same, approved, ECU[1]. They can change certain mapping tables and such but it's a sealed unit and they can't replace the firmware. [1]: https://wheelsports.co/formula-1s-standardised-ecu-explained...

This is quite interesting because you can imagine that lobbyists would argue that standardization would “stymie innovation.” If F1 does it why can’t you?

Most of F1's "innovation" is around finding ways to beat the rules, not necessarily coming up with new technologies.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#186

I wonder if the solution to all these screwy engine controls (tampering with emissions testing, preventing 3rd party repairs, etc.) is to standardize the interfaces to these systems so they can be replaced. Standardizing the outputs of the sensors would let us swap in and out various components to ensure the system is not cheating the regulators.

There are devices for automobiles that intercept sensor data and feed back fake data to the ECU to bypass emissions controls. It's a fairly simple to do.

I have a buddy with a WRX that absolutely should not pass smog, has no cats, big turbos, tune, etc, but it has no codes, passes every time without issue because the sensor data is synthetic that governs those things.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#187
post #150

Earlier quoted context omitted.

It's funny how, in the western world, as a company, you can commit crimes and take a pat on the wrist, but, as an individual, you get to jail for the same crimes.

Sadly, the general populace didn’t hire lobbyists to represent them. Our representatives were supposed to be built into the system, but that unfortunately made them part of the game, rather than some of the players.

Can’t you create an NGO that will collectively represent and lobby on behalf of the group, hiring lobbyists from membership fees and other fundraisers? Holy hell, maybe create a political party?

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#188

Earlier quoted context omitted.

Sadly, the general populace didn’t hire lobbyists to represent them. Our representatives were supposed to be built into the system, but that unfortunately made them part of the game, rather than some of the players.

Can’t you create an NGO that will collectively represent and lobby on behalf of the group, hiring lobbyists from membership fees and other fundraisers? Holy hell, maybe create a political party?

Me personally? No, I don’t think I have the connections, patience, or talent for that. If I did I’d probably do it for a big company instead, they pay better than “we the people,” I think.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#189

In a properly functioning country the responsible persons should already be imprisoned. Some governmental agencies were aware of that for at least half a year, but failed to act. The fact that source code was not immediately dumped and analyzed is the evidence of malevolence, corruption and intentionally putting people's lives at risk. Welcome to the dark side of Poland - where citizens don't matter.

"the responsible persons" ... hmmm. Who would that be? The programmer who implemented the code? Do you think they thunk these tricks up? They was just following orders. The manager of the programming team, who set these tricks as things that needed to be implemented? Again, just following orders. The "Cxx" Title people who directed that there be "some protection" in some way that got implemented as what we see? Did t…

> Again, just following orders.

I seem to recall there was a trial in the forties of some relevance to Poland about this sort of thing.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#190
How is this different from companies like Apple or John Deere that DRM components and brick the device if repaired by "unauthorized" technicians?

(I think both are equally egregious personally, but I know there's a lot of support here for Apple, so I'm curious how people reconcile these. I don't want to make this a religious war about Apple, but those practices in general regardless of which company is doing it).

Is it the secrecy that makes it different? i.e. if the train company were honest about it then it would be ok?

Or is it the scale that matters? Trains are big and expensive, while phones are small and cheap, so it's ok? (that wouldn't work for John Deere but would for Apple)

Post reply on HN