Live data from Hacker News

They have not been trained for this

ccc.de

71–80 of 160 posts

Re: They have not been trained for this

#71

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

> but is it really what we want?

What we want is results. Whatever mechanism is most efficient at producing those results should be used.

> Copyright is the root of the problem.

If you sell me a device that relies on copyrighted software for operation then you must also grant me a limited non-transferable license tied to that specific device to modify that software however I please. Perhaps DMCAs anti tampering provisions are really the issue here.

Re: They have not been trained for this

#72
post #44

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

> This really has to stop. "We", the totally homogeneous group of software professionals could make this stop. "We" don't.

“We” is an amorphous blob, not a guild. The company will just shop the job around until they find someone to do it.

Re: They have not been trained for this

#73
post #44

Earlier quoted context omitted.

> This really has to stop. "We", the totally homogeneous group of software professionals could make this stop. "We" don't.

Yea, every time I read one of these articles, I can’t help but think: “A software engineer sat down and wrote this remote kill switch." We, as a profession are responsible for this shit, or at the very least, complicit. Regulation is one thing, but also, software engineering as a profession is in dire need of ethical standards. Just because we can code something doesn’t mean we should.

One of the great and terrible things about the software industry is that there's no certifying body, no professional ethics code to sign and adhere to, no government regulation around how you can sell your services.

This is one of the best parts: many software people have gotten in through circuitous routes, have no formal training, and have done great things despite that.

On the other hand, because of that, we don't have any consensus and ability to shun or disposess companies that act unethically.

Quite frankly, I don't think any board of ethics would step in here. I don't see anything in the IEEE code of ethics that would be clear here. I don't think that professional licensing or better professional organizations are the way to stop this behavior.

Re: They have not been trained for this

#74

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

The device/train could be bricked with or without copyright.

Re: They have not been trained for this

#75

Earlier quoted context omitted.

Yea, every time I read one of these articles, I can’t help but think: “A software engineer sat down and wrote this remote kill switch." We, as a profession are responsible for this shit, or at the very least, complicit. Regulation is one thing, but also, software engineering as a profession is in dire need of ethical standards. Just because we can code something doesn’t mean we should.

One of the great and terrible things about the software industry is that there's no certifying body, no professional ethics code to sign and adhere to, no government regulation around how you can sell your services. This is one of the best parts: many software people have gotten in through circuitous routes, have no formal training, and have done great things despite that. On the other hand, because of that, we don't…

I think disabling the firmware in circumstances that are clearly defined but not disclosed to the customer is very much outside existing IEEE ethical rules.

And making a Professional Engineer sign on to the software release before the release would be a good way to prevent shit like this.

Re: They have not been trained for this

#76

> If more than the € 30,000 required to date is donated, if the legal costs are lower or if court costs are repaid, all payments received in excess will be used for the statutory purposes of the Chaos Computer Club e.V.. Please note that the CCC e.V. is not formally recognised as a non-profit organisation. That is one sure way to make people not donate to the cause. I want to support the people, but I don't want my m…

The "Please note that the CCC e.V. is not formally recognised as a non-profit organisation" part is a bad translation - this one is related to the German tax code. To put it short: there are two different kinds of NPOs, first "regular" e.V. and then those e.V. that fulfill exclusively "aims for the common good" ("gemeinnützige Zwecke", the full list is in §52 AO [1]) - they carry a special benefit: donations can be d…

I kind of envy Germany's large array of possible corporate charters for non-profits, for-profits and kinda-sorta-nonprofits. I wish America had the same menu to pick fro.

Re: They have not been trained for this

#77
post #32

Earlier quoted context omitted.

The payment information is a bit obfuscated, being only a parenthesized sequence of letters and numbers in the OP. IBAN: DE41 2001 0020 0599 0902 01 BIC: PBNKDEFFXXX Purpose: Lokomotive Payee: CCC eV

I don't suppose they have any other published, easier methods? I spent almost an hour trying to jump through the fiery, spinning hoops being dangled by my bank website only to finally at the end be given an "It looks like this part of our site isn't working. Please try again later." Thank you, bank /s For anyone else wanting to try their hand and weather the gauntlet, I found slightly more detail of their published b…

I guess you can use something like https://wise.com to make the IBAN transfer locally, and pay them using a more convenient payment method for you, like ACH, PayPal, Credit Card, etc

Re: They have not been trained for this

#78
Sadly, I suspect discoveries like this will only cause other companies to learn from it --- by making it even more difficult to discover their "plausible-deniability" tricks, and hiding them under the guise of "security". Big Tech has been playing that game for a while:

https://news.ycombinator.com/item?id=36926276

https://news.ycombinator.com/item?id=24955071

Re: They have not been trained for this

#79

Earlier quoted context omitted.

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

Yes? Unless we want to let manufacturers sell us a vehicle but license the code that makes it run.

Talking about licensing is going their way, what we need is ownership, not licensing.

Re: They have not been trained for this

#80
post #55
post #45

Earlier quoted context omitted.

The firmware would need to be certified. They mentioned that in the q&a couple of minutes ago. Apparently its a critical component.

I remember they said in the last talk last year that there is a "cheat code" that resets the software locks, but almost every train also had slightly different software to obfuscate that they are sabotaging their competition.

Yes, although i recall it was more lack of build automation meaning not every train had every patch
Post reply on HN