Live data from Hacker News

They have not been trained for this

ccc.de

41–50 of 160 posts

Re: They have not been trained for this

#41
post #22

Newag is acting like the mafia here: "Wouldn't it be a shame if your trains stopped working..?" Not that I want to tell the Polish how to do things (I don't), but a satisfying outcome would be one where they found out precisely who gave the order to program Newag trains like that and then jail them. Add to their jailtime for each train that is found running the software and force Newag to do free maintenance on those…

NewAg is clearly acting with malice and sabotage in mind (as well as extortion), and when it comes to trains and railways this is not just a business matter, it becomes a strategic national security issue.

"Wouldn't it be a shame if the trains filled with perishable food stuffs stopped working in route..., and the harvests rot"

Do you know of any country where food security doesn't impact the government's ability to keep order?

If any non-service operator, did this, like a third-party, they would reasonably be considered a terrorist organization, and the members of such a cohort should be treated as such.

Even if the claim is made its only for small specific things which you had to agree to, its an inserted vulnerability into the supply chain that is both non-essential for regular function, which has been designed to be essential.

At a bare minimum, they pave the way for such groups even if they don't act on it themselves.

Re: They have not been trained for this

#42

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

In this case, probably? I'm not a fan of excessive regulation, for this particular problem, I don't see how it could be solved without some kind of "right to repair" law, or at least a "right to be thoroughly informed about repairability before buying" law. Even if copyright was scaled back to 20 years and explicit registration, that still would be long enough to screw customers. In fact, even if copyright didn't exist, the problem would still exist for devices that are hard to reverse-engineer.

Re: They have not been trained for this

#43
post #6
post #3

Previous discussion, when it was first discovered - I am surprised there wasn't more: https://news.ycombinator.com/item?id=38893116

There was much, much more discussion here, e.g: https://news.ycombinator.com/item?id=38530885 https://news.ycombinator.com/item?id=38567687 https://news.ycombinator.com/item?id=38628635 https://news.ycombinator.com/item?id=38788360 & more

Ah! My search-fu failed me, I was looking for company name and for train hacking mentions, but didn't find all these! Thank you!

Re: They have not been trained for this

#44

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

> This really has to stop.

"We", the totally homogeneous group of software professionals could make this stop. "We" don't.

Re: They have not been trained for this

#45
post #12
post #4

I just donated 133,7€ and will gladly do it again if further legal costs arise. Please consider also making a generous donation and post about it in this thread. What Newag is doing here is absolutely vile. They want to charge 20.000€ per train to “reactivate” them after they have been serviced at third party workshops. We must not let them win and set a precedent. I highly encourage everyone to watch the previous pr…

At 20k euros, would it not just be cheaper to hire some software people to jailbreak them? If companies that did this got jailbroken and blacklisted by the government, pretty much nobody would try this bullshit.

The firmware would need to be certified. They mentioned that in the q&a couple of minutes ago.

Apparently its a critical component.

Re: They have not been trained for this

#46
This is almost universal. If manufacturers are not already doing this they are planning it.

There is a lot of anxiety around the business model because a lot of the world is advancing and manufacturers are popping up everywhere with cheaper machines on offer. The moats are disappearing and durable goods manufacturers are clamoring for the next wave in the business model: subscription services for maintenance and support.

Ford has a connected fleet service offering that is picking up steam and could prove very lucrative in the commercial vehicle space.

A lot of this is rooted in an eroding labor pool that is lacking in bodies, training and experience.

This train fiasco is definitely bordering on criminal but it isn't far off from the wave of "progress" that is taking place.

Re: They have not been trained for this

#47

Earlier quoted context omitted.

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

If businesses are unable to regulate themselves, it must be done by law. If copyright is the root of the problem, it may be time to remove that protection; or at least revert it so it is more in-line with patent law expiration. No more author's life + 75. Lets try 15-20 once again, and no derivative protection, unless significantly different, receive protection.

Also, different terms for different works. Having the same rules for software, drugs, books, paintings etc. is ridiculous.

Software should require disclosure of details of what is protected (e.g. the source) so it can be public used post expiry - just as patents give you a monopoly only what is disclosed in the patent.

Re: They have not been trained for this

#48
post #15
post #12

Earlier quoted context omitted.

At 20k euros, would it not just be cheaper to hire some software people to jailbreak them? If companies that did this got jailbroken and blacklisted by the government, pretty much nobody would try this bullshit.

This ("software people to jailbreak them") is exactly the identity of the hackers who have been sued

It takes a lot of resources, all rooted in a lot of uncertainty. Not an option for businesses that need equipment.

Re: They have not been trained for this

#49
post #8

Is no one suing the manufacturer for vandalizing the trains?

No, and frankly if the Polish government won't do anything with this overwhelming evidence then they've got the train manufacturer they deserve. You can lead a horse to water...

If that will happen, maybe it is time to start following that money.

Re: They have not been trained for this

#50
post #33
post #6

Earlier quoted context omitted.

There was much, much more discussion here, e.g: https://news.ycombinator.com/item?id=38530885 https://news.ycombinator.com/item?id=38567687 https://news.ycombinator.com/item?id=38628635 https://news.ycombinator.com/item?id=38788360 & more

Thanks! Macroexpanded: Manufacturer's Repair DRM Killed Train's Power, Broke Compressor - https://news.ycombinator.com/item?id=38893116 - Jan 2024 (2 comments) Breaking "DRM" in Polish trains [video] - https://news.ycombinator.com/item?id=38788360 - Dec 2023 (51 comments) Polish DRMed trains stop as predicted due to date-based logic-bomb - https://news.ycombinator.com/item?id=38729035 - Dec 2023 (103 comments) Trains…

> Macroexpanded

Unrelated but is this macro available to others, or just mods? I tried searching the webs for it but found nothing.

Post reply on HN