Live data from Hacker News

Give Me the Green Light Part 1: Hacking Traffic Control Systems

redthreatsec.com

21–30 of 94 posts

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#21
post #20

Can you turn all the lights at a given intersection green at the same time?

Generally no, this is something from fiction.

I'm mostly familiar with North American traffic signal control, and in those traffic cabinets there is a device known as an "MMU" (Malfuction Management Unit) which acts as a safety monitor for the rest of the traffic cabinet.

That device will catch so-called "conflicts" (two conflicting directions green at the same time) and put the intersection into a fail-safe state (usually flashing red/yellow lights).

There are of course some edge cases where this is technically possible (as long as the cabinet door is open in CalTrans TEES cabinets, you can actually remove the MMU entirely and do whatever you want), and I'm not familiar with safety mechanisms used in other localities.

(Note: I work in the industry, not for any of the companies in this article, and my views are my own).

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#22
This has been bothering me for a while.

Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger.

Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). Nobody would be happy about that, no matter what color hat I have on.

Security is a twin-engine racket, based on the pillars of

- assumed intellectual superiority

- the actual protection racket part

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#23
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

We do have that now, as of 2022! The new Justice Department policy now instructs prosecutors not to prosecute security researchers who acted in good faith for the public benefit and who avoided any harm to individuals or the public. https://www.justice.gov/opa/pr/department-justice-announces-...

That checks off federal cases, but there are still options for a corporation under what are normally much stricter state laws in the USA. For instance, in Illinois you can get up to 5 years in prison for violating the ToS of a web site.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#24
This is a great introduction to the mess that is traffic signal controllers!

The reality is perhaps even worse than the article suggests. The majority of signal controllers support the NTCIP "standard" MIBs in addition to the "proprietary" MIBs that are provided through FreeTheMIBs. These "standard" MIBs are defined in standards like NTCIP 1202[1], which are freely available online through the NTCIP group.

These standard MIBs let you set/get all kinds of fun settings... put the lights into flash, change timing settings, set "preempts" to give yourself a green light, and more.

The standard also strongly suggests that all vendors use a default SNMP community name of "public". That means, for any traffic controller you happen to find on a network, you can almost certainly change tons of scary settings without even needing to _exploit_ anything!

I've been working in the industry for quite some time, and it's genuinely scary how poorly secured some of this infrastructure is and how slowly things move when issues are found.

(Disclaimer: I work in the industry, not for any of the companies discussed in the article, and all these views are my own and not those of my employer)

[1]: https://www.ntcip.org/file/2019/07/NTCIP-1202v0328A.pdf

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#25
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

Company makes HW that can potentially harm people, if someone logs in to it remotely and turns all lights green at once. It's possible to find the vulnerability in 15 minutes of getting remote access to the device without any prior knowledge, that gives admin access to the HW. Company rejects the report based on flmisy reasons via a lawyer, threatening with a felony prosecution.

But the person finding the vulnerability and notifying the company is the smug one. :)

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#26
post #20

Can you turn all the lights at a given intersection green at the same time?

Generally no, this is something from fiction. I'm mostly familiar with North American traffic signal control, and in those traffic cabinets there is a device known as an "MMU" (Malfuction Management Unit) which acts as a safety monitor for the rest of the traffic cabinet. That device will catch so-called "conflicts" (two conflicting directions green at the same time) and put the intersection into a fail-safe state (u…

How about switching lights in quick succession, enough to cause real-world issue, but avoiding the direct conflict?

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#27
post #25
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

Company makes HW that can potentially harm people, if someone logs in to it remotely and turns all lights green at once. It's possible to find the vulnerability in 15 minutes of getting remote access to the device without any prior knowledge, that gives admin access to the HW. Company rejects the report based on flmisy reasons via a lawyer, threatening with a felony prosecution. But the person finding the vulnerabili…

There are electrical junction boxes all over my neighborhood, that direct power to the stoplights and residential buildings (?). They have a simple padlock, and could be opened in 30 seconds with a lockpick or bolt cutters.

Nobody tries! Not even to test it out! The question isn't "How easy is it to break in?", but rather "Should I be tampering with this?"

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#28
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

Could you help me understand what you are suggesting is done instead?

To me, it seems like you're suggesting that vulnerabilities are just left in play until someone malicious comes along and decides to do some real damage. But that seems so silly that I must be missing some alternative that you're thinking about.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#29
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

I assume that any piece of technologically backed infrastructure is a potential target for state-level actors. If rando security researcher finds the vuln in 15 minutes, I guarantee China already has it.

Anyone operating infrastructure hardware is negligent if they won't take basic measures to harden it against disclosed threats.

I’m not worried about malfeasant citizens mucking with the traffic lights, there are simpler ways to make mayhem. But in the event of a war, you can bet every unpatched vulnerability in your infrastructure will be used against your country.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#30
post #26

Earlier quoted context omitted.

Generally no, this is something from fiction. I'm mostly familiar with North American traffic signal control, and in those traffic cabinets there is a device known as an "MMU" (Malfuction Management Unit) which acts as a safety monitor for the rest of the traffic cabinet. That device will catch so-called "conflicts" (two conflicting directions green at the same time) and put the intersection into a fail-safe state (u…

How about switching lights in quick succession, enough to cause real-world issue, but avoiding the direct conflict?

Now you start to get into the differences between the various standards :)

In NEMA TS2 (and the more modern ITE ATC), the MMU does enforce a yellow clearance time - you need the light to turn yellow for a period of time before a conflicting phase goes green. Usually this is a few seconds. Changing phases rapidly would likely confuse drivers, but in _theory_ shouldn't cause a collision if people respect yellows.

(believe it or not, in some localities a "red clearance" time - all red - is not required and lights will go from yellow in one direction to green in another.)

In CalTrans TEES, I do not believe the standard calls for the MMU to enforce clearance times - the attack you describe would potentially be possible.

Post reply on HN