Live data from Hacker News

Give Me the Green Light Part 1: Hacking Traffic Control Systems

redthreatsec.com

61–70 of 94 posts

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#61

Earlier quoted context omitted.

Now you start to get into the differences between the various standards :) In NEMA TS2 (and the more modern ITE ATC), the MMU does enforce a yellow clearance time - you need the light to turn yellow for a period of time before a conflicting phase goes green. Usually this is a few seconds. Changing phases rapidly would likely confuse drivers, but in _theory_ shouldn't cause a collision if people respect yellows. (beli…

> (believe it or not, in some localities a "red clearance" time - all red - is not required and lights will go from yellow in one direction to green in another.) This was definitely true in the past, I feel like the concept of a 'red clearance time' is something that only became common within the last 5-10 years. Do you think it has become (with rare exceptions) ubiquitous at this point?

I'd like to think it's become ubiquitous - it has been a while since I've seen a signal without a red clearance configured.

However, the Federal Highway Administration in the US (which sets guidelines, but most states define actual rules at the state level) still says in their Signal Timing Manual [1]

> The use of a red clearance interval is optional, and there is no consensus on its application or duration. [...] there may not be safety benefits associated with increased red clearance intervals.

and goes on to describe how it has negative traffic flow implications.

so I suspect at least some agencies out there still are not using them.

[1]: https://ops.fhwa.dot.gov/publications/fhwahop08024/chapter5....

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#62
post #18

Sounds like the company realised they can't solve the issue in 90 days. Betting a combination of infrastructure scale problems, terrible tech, no-longer-building old solutions, no maintenance fee's built in and contractors who hate them. So they pulled the only lever they had left, which was the lawyers. Same time, RedThreat's email was kinda (maybe rightly) hostile. Read from the other side it's basically "You have…

The 90 day window is an industry standard for zero-days, how the author worded it is neither here nor there. 90 days is ample time for even a half-functioning organization to address the issue in some way. I agree with Red Threat’s decision to not show their hand in the first email. The altruistic take on this is that they do not want the email to fall upon deaf ears (or even a bad actor within a company) and would p…

90 days isn't really an industry standard. It's what Google unilaterally decided upon when they chose to staff up Project Zero and reflects their assumptions being, as they are, a company that grew up on the web. One of those assumptions is that you have fully automated test processes and the ability to remotely update any/all installs of your software within a week or so, which in turn implies that users aren't involved in the decision about whether to upgrade or not. It also assumes you can do this as often as you want. This is a strong set of assumptions that happens to be true for Google but isn't true of SCADA shops.

Even if they make a patched firmware, actually rolling it out would require a lot of work by their customers and of course maybe the same guy finds another security bug after 80 days and the whole thing starts again.

Given the unclear threat model here (how does one get access to the networks that these are attached to? could you just hotwire the lights themselves and bypass the controller?) it's also not really obvious how you'd classify reports. If there's a bypassable HTTP login page that's clearly an exploit but customers may not care if they trust the underlying VPNs/firewalls/air gaps. If there's unauthenticated SNMP access by design then is it even intended to be secure against malicious network access at all?

In many cases these devices will be reachable from the public internet, and in some of those cases it will be intentional. But is the security bug there on the controller or in the network setup that allows that access? It's probably easier to properly firewall off the controllers than continuously patch all the controller firmwares themselves, especially as the latter done wrong could easily enable hackers to perform a worse-than-Crowdstrike level takedown of all controllers simultaneously.

It's really not clear that the model that works well for web browsers will ever work well for infrastructure. We just saw an awesome demo of what can go wrong when rapidly hot-patching security updates into critical infrastructure computers goes wrong.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#63

Earlier quoted context omitted.

> (believe it or not, in some localities a "red clearance" time - all red - is not required and lights will go from yellow in one direction to green in another.) This was definitely true in the past, I feel like the concept of a 'red clearance time' is something that only became common within the last 5-10 years. Do you think it has become (with rare exceptions) ubiquitous at this point?

I'd like to think it's become ubiquitous - it has been a while since I've seen a signal without a red clearance configured. However, the Federal Highway Administration in the US (which sets guidelines, but most states define actual rules at the state level) still says in their Signal Timing Manual [1] > The use of a red clearance interval is optional, and there is no consensus on its application or duration. [...] th…

I feel like my area (where I've lived my whole life) does not have red clearance interval. It's not something Ive paid attention to before.

I'm sure it's proper driving technique but I feel it's ingrained in my head to give a couple seconds when a red turns into a green for all cross traffic to finish / anyone who runs the light. It's a common thing around me and I don't think it would be happening as much if an all-red period was implemented.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#64
post #28
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

Could you help me understand what you are suggesting is done instead? To me, it seems like you're suggesting that vulnerabilities are just left in play until someone malicious comes along and decides to do some real damage. But that seems so silly that I must be missing some alternative that you're thinking about.

> it seems like you're suggesting that vulnerabilities are just left in play until someone malicious comes along and decides to do some real damage

That's how security mostly works in meatspace, yes.

In the specific case of internet connected software the industry has a lot of experience saying that if something is exploitable then someone will come along and exploit, so we don't normally need to see an example of it happening in the real world first. It's sufficient to assume that if you get popular enough, a professional blackhat will find your bugs and exploit them. It's also reasonable to assume that the cost of a fix is low and the cost of change in the field is also low.

Outside that context the threat models are usually unclear and refined through experience. If you notice someone cut through a wire fence to steal some equipment from a cell tower maybe you build a wall around it instead. But if nobody is stealing anything there's no point in pre-emptively trying to guess that it might happen and building lots of walls because that might just be a waste of resources (perhaps there's no market for stolen tower equipment, so protecting it better would be a waste of resources).

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#65

This is a great introduction to the mess that is traffic signal controllers! The reality is perhaps even worse than the article suggests. The majority of signal controllers support the NTCIP "standard" MIBs in addition to the "proprietary" MIBs that are provided through FreeTheMIBs. These "standard" MIBs are defined in standards like NTCIP 1202[1], which are freely available online through the NTCIP group. These stan…

I'd be pretty interested in working on this kind of critical infrastructure. Any tips or pointers for an experienced SE/SWE on getting into your world?

I sort of accidentally stumbled into it when I joined an (at the time) startup as they were just getting into the market. So I don't know that I have anything specific to offer :)

I don't want to name names for companies in the industry, but you can find them in industry publications like Traffic Technology Today, or often as contributors to the standards documents like NTCIP 1202, ITE ATC 5301, etc.

I will say that there are a number of long-standing (40+ years) companies in the industry that seem to still operate the "legacy" way - slow iterations, very small software team, seemingly not much desire for large change. Basically, a hardware company that also happens to sell software.

There are also newer entrants to the market in the past ~decade or so that operate a lot closer to a modern software company - lots of new features coming out, fast-moving software teams, etc.

(again, all opinions are my own here.)

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#66

Earlier quoted context omitted.

I am aware of a municipality local to me that, as part of a franchise agreement for a new ISP entering the community, had the ISP run fiber to every traffic cabinet. They're connected back to the city network in a VLAN that's "behind the firewall". >sigh<

Interesting, but I think the VLAN in your explanation is equivalent to the "network" I'm asking about. The V is mostly immaterial, I think.

The VLAN part is important.

"LAN" doesn't imply the same use of VLAN trunking or flat network architecture.

Traffic infra being on a VLAN behind the firewall implies a lot of trust in the traffic infra physical plant. You can harden against layer 2 vulnerabilities, but they're a whole 'nother can of worms and possible failure point.

It also implies the possibility of VLAN trunking being used inappropriately.

All the CCIEs I've learned from and trusted were very suspicious about extending the size and scope of LANs offsite through VLANs.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#67
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

> Out in meatspace, I don't wander around picking random people's locks Sure, because the chances of getting punched out, shot, or reported to the cops is significantly higher. Given how trivial it is to quietly attack across the network, I think the analogy with meatspace makes little sense.

Also breaking into a single persons house... maybe they don't want to lock their doors. It affects nobody but them.

These systems affect lots of people, it's a public safety issue, and there is a company being paid money by the public to ensure that their systems are safe and secure. They should be tested by everybody and anybody who wants to test them. Especially if they are running on a publicly accessible IP address.

Also if you want to test the locks on someone's house, you don't go to their house. You buy the locks that they are using, and test them quietly in your own location.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#68
post #22

This has been bothering me for a while. Security people act like it's their duty to expose every vulnerability, and that companies are negligent if they don't harden themselves against all attack vectors, while they are responsible for a good part of the danger. Out in meatspace, I don't wander around picking random people's locks, making smug posts about how vulnerable their houses are (along with their address). No…

Your analogy is flawed. This isn't testing someone's house. This is buying the locks that are on people's houses and testing them in your own location. Which people should absolutely be doing.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#69
post #67

Earlier quoted context omitted.

> Out in meatspace, I don't wander around picking random people's locks Sure, because the chances of getting punched out, shot, or reported to the cops is significantly higher. Given how trivial it is to quietly attack across the network, I think the analogy with meatspace makes little sense.

Also breaking into a single persons house... maybe they don't want to lock their doors. It affects nobody but them. These systems affect lots of people, it's a public safety issue, and there is a company being paid money by the public to ensure that their systems are safe and secure. They should be tested by everybody and anybody who wants to test them. Especially if they are running on a publicly accessible IP addre…

> Also if you want to test the locks on someone's house, you don't go to their house. You buy the locks that they are using, and test them quietly in your own location.

This is a pretty great point, because it's exactly what the guy in the article did to find the vulnerability in the traffic controllers.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#70
The legal threat letter from the vendor is among the most insane examples I've read. They only consider something a valid vulnerability if the reporter can demonstrate they obtained the equipment through a legitimate recorded sale? What on earth does that have to do with the existence of a vulnerability?
Post reply on HN