Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

301–309 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#301
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

It will be stuck in legal hell due to conflicts of interests. Trains already exist, and they need to work - but maintenance/repair companies cannot legally modify software of them due to copyrights. It's a catch22 situation. I honestly hope that company will be fined to the oblivion, and for criminal charges for that, but i doubt it will happen.

> It will be stuck in legal hell due to conflicts of interests. Trains already exist, and they need to work - but maintenance/repair companies cannot legally modify software of them due to copyrights. It's a catch22 situation.

Which is why any government funding for new trains should come with the requirement for open source firmware.

Well better yet would be to abolish or reform copyright to be more aligned with the interests of society at large but international pressure makes that even less likely.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#302
post #281

Earlier quoted context omitted.

A contractor in the UK put a time-lock in the software he was contracted to write because he was concerned about non-payment. He didn't get paid and the software duly stopped working. He was successfully prosecuted under the Computer Misuse Act. He had some justification (unlike the Polish train manufacturer) but it didn't help him avoid prosecution. I've no idea what the law in Poland says.

That’s pretty ridiculous.

Why? Tolerating that kind of behavior is what is ridiculous.

If anything, us software developers should be held liable for more of the damages that we cause.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#303
post #235

Earlier quoted context omitted.

Part of their statement says(loosely translated): "No hacker can tell, based on the content of the digital record alone, who is the author of the digital record in question" Boy oh boy. Either they're not singing their firmware (which is a serious indictment in and of itself) or proving that it was them all along will be trivial, but the ones signing off this message are unaware of this. Overall they got caught with…

"Pants down" situation aside, if the firmware is not signed or verified in any way, then isn't it prone to "neutrino bit reversal", potentially causing Bad Things? I have no idea how those systems work and what guarantees they provide, but this would be hair-raising...

You can have checksums without signatures. Not that either a commonly checked after installation so most systems are still vulnerable to random bit flips.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#305
post #281

Earlier quoted context omitted.

That’s pretty ridiculous.

Why? Tolerating that kind of behavior is what is ridiculous. If anything, us software developers should be held liable for more of the damages that we cause.

So it’s ok when a megacorp like Microsoft does it, but if an individual developer does it then it’s a crime? When you fail to pay for Windows, it turns off various features, does it not? When you stop paying for your MMO, it stops letting you play the game, right? So if I am contracted to develop some accounting software and they fail to pay me, why shouldn’t it stop working?

This is why it would only be a contract dispute; they will argue that the contract did not state up front that if they failed to pay the developer that the software wouldn’t work. The MMO certainly has pages and pages of legalese that everyone knows lets the MMO’s developer get away with anything they want. The independent contractor needs explicit language in their contract to specify exactly what will happen if they aren’t paid on time. That should include late fees, but probably also software that refuses to work until someone fills out a credit card payment form.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#306
post #18

Earlier quoted context omitted.

I think it is because the equipment changed dependent on context. In Dieselgate the cars changed their engine management when they got into a test cycle...

Dieselgate was about cheating environment sensors. This is more like DeereGate, locking out external service shops but even when you are supposed by law to allow them service (and even after providing them 20k page service manuals which they are supposed to follow to make appropriate service, but you lock them out anyway).

That Watergate building name had created quite the meme!

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#307
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

It will be stuck in legal hell due to conflicts of interests. Trains already exist, and they need to work - but maintenance/repair companies cannot legally modify software of them due to copyrights. It's a catch22 situation. I honestly hope that company will be fined to the oblivion, and for criminal charges for that, but i doubt it will happen.

The only practical solution is to re-nationalise this company.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#308

Earlier quoted context omitted.

> No "boot times". They just worked Haha wait until you find out how TVs worked in the 70s and how fast it was to change the channel *sob*

Even in the 90s, you could just power it on and it would show image near-instantly. Warm-up time and channel switch time were all firmly under one second. With the exception of cable TV set-top boxes, which were separate devices and first to include the ridiculous boot times and delays, that still would seem blazingly fast compared to what we have today...

Those "instant ON" TVs worked by sending a small pulse of power through the tube/valve circuitry. There was a legal stink when a Zenith TV set caused the Texas Capitol to burn in 1983. The "expert" testifying for Zenith claimed that no other TV burst into flames like that. The Texas AG had gotten copies of sealed testimony by that exact same expert in dozens of other home fires. The expert got busted for perjury.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#309
post #226
post #217

Earlier quoted context omitted.

Yes, but “Dieselgate” is not appropriate here because that term has “cheating” loaded onto it, which represents a different struggle for companies than vendor lock-in. What this company is doing is related to DRM and arguably closer to what John Deere does with its products.

The example here includes faking a compressor failure, which is a bit beyond ‘vendor lock-in’.

yeah - this is basically stealing
Post reply on HN