Earlier quoted context omitted.
This is the kind of thing that will destroy a nation's manufacturing industry overnight. Who in their right mind would buy kind of equipment from a Polish company knowing that this kind of nonsense is both widespread and that their legal system has no solution? Hoestly, "Dieselgate" is not a fitting corollary for this travesty. This is considerably more sinister. Hopefully whatever happens from here will be an agent…
Aren’t we all doing this when we buy software from the cloud?
Dieselgate, but for trains – some heavyweight hardware hacking
261–270 of 309 posts
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#262My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…
> No "boot times". They just worked Haha wait until you find out how TVs worked in the 70s and how fast it was to change the channel *sob*
Audio effects and synthesizers all have software driven versions that sound effectively identical to analog and are typically cheaper. Yet, analog has been hanging on due to the simplicity and immediacy.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#263Earlier quoted context omitted.
I'm not a fan of Apple's practices, but there's some aggravating elements to this. Apple doesn't brick your device if it it spends time at a repair location, for instance. Apple also doesn't simulate failures on synthetic dates to force repair.
I wouldnt be so sure, one can think of https://en.wikipedia.org/wiki/Batterygate as an example of a little bit of "bricking"
In battery gate, 1-2 year old devices were starting to reboot at low state-of-charge (typically My feeling is that Apple owed customers like me some compensation. But, it is clear that the performance throttling was not just an arbitrary "fuck you". Rather, it was a misguided attempt to save the cost of warranty battery replacements in a way they thought customers wouldn't notice.
The current situation couldn't be more different. Here, the manufacturer has added software from the factory to create fake error codes. The hardware is working perfectly fine, but when the train sits in certain locations for too many days, it will pretend to have a hardware failure. During certain months of the year, the train will fake a hardware error. There is no possible explanation for this, except as a "fuck you" to the customer who wants to use 3rd party service.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#264Earlier quoted context omitted.
Sometimes it may not be obvious but the feature still might seem super suspicious. For example, suppose that the malware discussed in this article was broken down into two sub-features assigned to different people: geofencing detection, and bricking the train. The person writing the "bricking the train" part should have realized that there is practically no legitimate reason for that code to be written, and if they a…
> The person writing the "bricking the train" part should have realized that there is practically no legitimate reason for that code to be written Hey Janusz, can you build a safety feature that prevents the train from operating under certain conditions. We don’t know all the conditions yet, so leave it flexible.
Hey Czesław, I cannot leave it flexible, because it's a train that can run over 100km/h with 500 passengers inside, so I need to know the details to perform the required safety analysis. All in all, my name will be in the commit log if someone runs... git blame.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#265Title is a bit misleading, because this *gate is not about faking ecology, and trying to pass certification in artificial conditions, as dieselgate was, but simulating fake failures instead. The company hardcoded algorithms that would report failures of parts that work correctly (like a compressor), if it detected that train has been repaired by another company (based on location readings), and stop the train from ru…
> The company hardcoded algorithms that would report failures of parts that work correctly (like a compressor), if it detected that train has been repaired by another company (based on location readings), and stop the train from running This isn't correct by my understanding - there's actually two separate things here: - The company made their trains stop functioning after spending 10 days at competing maintenance lo…
- The 10 days limit was their initial attempt, no GPS involved
- After it turned out the trains were immobilized in the "wrong" location, they added GPS geofencing
- The compressor failure was supposed to happen every day till the end of the year, starting on the scheduled maintenance date. (This might as well be bad coding.)
Again, I could get some details wrong, especially that the articles I read were kinda all over the place (subjectively, IMHO).
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#266Earlier quoted context omitted.
> If the owner of the train wants to modify the software then there is probably nothing stopping them. This of assumes that the owner of the train company has the skills to do this. In reality they probably would need outside help and that company might fall foul of copyright issues. (when they are distributing the modified code back to the train company, for example) But the real problem of course is that all of thi…
Performing a task for someone, whether directly or as a third party contract, generally doesn't invoke copyright.
Rather, the companies with botched trains should demand from Newag to remove their locks, for free, and on the side sue them.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#267I'm solely consuming EN content. And if it's from another country, it's only whats leaked by big media. It make me wonder how much good content could be translated.
I think you're saying, how much other good content is out there that I'm missing out on because I only read English, and it's a good point. However, English has become the (now ironically named) lingua franca of, at least, the more educated parts of the world, and many people who are most comfortable in their native languages are still often translating their best work into English in order to see it more widely read…
The original language which was actually called wasn’t really French it was a creole/pidgin language used in the Mediterranean mainly based on Italian and Occitan dialects.
Greeks and others just called all Western European Franks even though they didn’t really interact with people who actually spoke French (only used in the Northern half of modern France back then) that much.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#268My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…
I don't think fixing the software failure will improve DB's punctuality
Of course I'm half joking, but I wouldn't be surprised if software problems contributed to the delays (which tend to chain, as trains need to wait for each other, etc).
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#269Earlier quoted context omitted.
> The person writing the "bricking the train" part should have realized that there is practically no legitimate reason for that code to be written Hey Janusz, can you build a safety feature that prevents the train from operating under certain conditions. We don’t know all the conditions yet, so leave it flexible.
OK, let's try how it goes: Hey Czesław, I cannot leave it flexible, because it's a train that can run over 100km/h with 500 passengers inside, so I need to know the details to perform the required safety analysis. All in all, my name will be in the commit log if someone runs... git blame.
GIT_AUTHOR_NAME=Czeslaw GIT_AUTHOR_EMAIL=czeslaw@januszex.com git commit
(obviously, just kidding)
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#270I'm solely consuming EN content. And if it's from another country, it's only whats leaked by big media. It make me wonder how much good content could be translated.
And I only learnt about this whole train "vendor lock-in" from HN. Otherwise I either wouldn't know about it, or I would learn about it weeks or months later.