Live data from Hacker News

They have not been trained for this

ccc.de

81–90 of 160 posts

Re: They have not been trained for this

#81
post #2

I remember this story of “hackers” discovering that the train company disabled trains being serviced by competitors. It’s a shame they are being sued. Hopefully, they raise enough to do painful and invasive discovery.

It's a shame that the company wasn't charged with sabotage and possibly treason.

Attacking trains, even the ones you manufactured is an attack on nationally crucial infrastructure.

Re: They have not been trained for this

#82
Can someone please summarize (for those of us who don't know the full story) why the government(s) that bought these trojaned trains isn't ripping the train vendor a new orifice, and pinning medals on the hackers who exposed this?

Re: They have not been trained for this

#83
post #18

Earlier quoted context omitted.

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

I have no problem with some wide ranging law about right to repair. If that's regulation, yes please.

> If that's regulation, yes please

It is, and as much as we all want to pretend this is always about rent seeking.

There can be other reasons.

Some systems are bought in manners that include service contracts and outs liability on manufacturers. In such scenarios one man's kill switch could be a safety feature.

You don't want unauthorized personel messing about a medical x-ray device. Because (a) you want it to work, (b) there might be 10k+ volts sitting in giant capacitors.

I'm guessing it's similar with airplanes.

---

In complex enterprise systems, right to repair might not always be simple.

But if it comes to your home appliances, a tractor, car, etc. I'd be a lot less worried.

Re: They have not been trained for this

#84
post #63

Earlier quoted context omitted.

Yea, every time I read one of these articles, I can’t help but think: “A software engineer sat down and wrote this remote kill switch." We, as a profession are responsible for this shit, or at the very least, complicit. Regulation is one thing, but also, software engineering as a profession is in dire need of ethical standards. Just because we can code something doesn’t mean we should.

I remember one of Asimov's stories involved a human defeating the Laws of Robotics by distributing work among multiple robots with imperfect information. I wonder if something analogous doesn't happen with software engineers nowadays. When it comes to something like a "remote kill switch" for software, it's hard to imagine any alternate beneficial use. But generally I assign the blame to the users of software who put…

>When it comes to something like a "remote kill switch" for software, it's hard to imagine any alternate beneficial use.

The obvious alternate beneficial use is the ability to immediately disable the hardware in case a serious safety issue (the kind that triggers product recall) is discovered.

Re: They have not been trained for this

#85
post #44

Looks like train manufacturers are taking a page out of the playbooks of many other companies today. The practice of manufacturers remotely disabling products after the time of purchase (for whatever reason) is becoming a scourge in many other product areas. The device's manufacturer should have no say about how a product is used once money is handed over in exchange for it. This really has to stop. Regulatory agenci…

> This really has to stop. "We", the totally homogeneous group of software professionals could make this stop. "We" don't.

If you want to have a say in how software works, then you have to control how companies run.

If Technical folk are not on the Boards or have controlling share in an org, or don't know how to get into such positions then they have very little to no say in how anything works.

There are countless examples were technical people object and get replaced, sidelined or fired, cuz they are totally unprepared in how to win such age old political and financial fights. If Oppenheimer, Engelbart and the Google brainiacs who protested recently got pushed aside, then its beyond obvious how the story will end for anyone else.

The lesson from history for anyone serious about this stuff is - develop business+finance acumen, or develop alliances with business+finance power.

Re: They have not been trained for this

#86

Earlier quoted context omitted.

Copyright is the root of the problem. More regulation could be a solution, sure, but is it really what we want?

You say this as if regulation for companies is a bad thing. Your entire existence is governed by regulations. Why should theirs not be?

It's not wholly a good or bad thing. It's a complex thing, with large secondary effects that people habitually overlook.

One typical effect of increasing any kind of regulation is that large incumbents tend to benefit disproportionately compared to small operators and newcomers, for several reasons: (1) larger operations can amortise compliance costs more easily; (2) larger operations legitimately contain people with useful expertise in helping government decide the shape of the regulations (and will propose kinds of regulation that correspond as far as possible to their own existing practices, and to practices that competitors would find costly to implement); (3) larger operations have the wherewithal to lobby for regulations that are to their benefit and to competitors' detriment, irrespective of how good those regulations are for other stakeholders. (2) and (3) together lead towards regulatory capture, at which point the regulations are almost purely a drain on all other participants with no upside.

Re: They have not been trained for this

#88
post #64

Earlier quoted context omitted.

I don't suppose they have any other published, easier methods? I spent almost an hour trying to jump through the fiery, spinning hoops being dangled by my bank website only to finally at the end be given an "It looks like this part of our site isn't working. Please try again later." Thank you, bank /s For anyone else wanting to try their hand and weather the gauntlet, I found slightly more detail of their published b…

For Europeans, this is an extremely easy method and the normal way to send money electronically. The information provided is all that's needed. If you're trying to send from America, it's still the normal way to send a payment to Europe so see how your bank sends international payments.

“Extremely” is a bit extreme for something that takes 100,000 times longer than a Venmo payment. Or, intercontinentally, a stablecoin transfer

Re: They have not been trained for this

#89
post #15

Earlier quoted context omitted.

This ("software people to jailbreak them") is exactly the identity of the hackers who have been sued

It takes a lot of resources, all rooted in a lot of uncertainty. Not an option for businesses that need equipment.

> Not an option for businesses that need equipment.

On the flip side, it can often be the only option for businesses that need equipment. The US has a longstanding trend of hacking John Deere tractors to accept third-party servicing since John Deere's first-party offerings are both expensive and often unavailable.

Re: They have not been trained for this

#90
post #29

Earlier quoted context omitted.

> I highly encourage everyone to watch the previous presentation: https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_tra... According to the schedule [1], there's a presentation from that team titled "We've not been trained for this: life after the Newag DRM disclosure" that will start at 23:00 local time (in about 30 minutes at the time of this writing) on this livestream [2]. Edit: presentation's over and it…

Here's the live recording link for those who missed it and are too impatient to wait for the cleaned-up one: https://streaming.media.ccc.de/38c3/relive/233cb1d4-4833-538...

Thank you! I have to say that my favorite in their latest update is the 60 day counter can be reset after closing the cabin door and hitting the SOS in the toilet. Now I want interview with the engineers sharing these product requirements...
Post reply on HN