Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

101–110 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#101
post #67
post #32

Earlier quoted context omitted.

Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.

An organisation that is prepared to write "sabotage" software would have no problem deploying software that is different to the software they submit.

Doesn't mean it's not a step in the right direction. Any transparency is better than zero.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#102
post #32

Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".

Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.

That would work only on paper. The financial interests involved are huge.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#103
post #77

Earlier quoted context omitted.

If the manufacturer did it, doesn't it still fit the definition? It's something like "deliberately causing something to fail", regardless of who does it.

While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used

Newag was required by contract to provide accurate service manuals so that competitors could safely maintain the trains. This was not a "just take your car to dave, he knows some stuff". For SPS and other competitors this was like "you need to show every certification that exists and certify all your tools to prove that indeed you can service those cars, or you will be foreclosed due to fines". Plus, they were provided ALL service manuals, like 20k pages to follow to the letter.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#104
post #53

Nevermind malware, not using seL4 should already be a crime in this context.

We have rovers on Mars and satellites and probably nuclear warheads using RTOS of all kinds and in cases even Linux, but sure seL4 is the only OS conceivable for those cases, obviously !

This is a case of fraud, industrial malfeasance and just plain dishonesty. The software component of the story and its security measures are not even at play. Sure they are probably shit (given the date parsing ...) but even FreeRTOS would make an amazing OS *IF USED PROPERLY *.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#105
post #32

Earlier quoted context omitted.

Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.

That would work only on paper. The financial interests involved are huge.

All the more reason for governments to insist.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#106
post #77

Earlier quoted context omitted.

While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used

Newag was required by contract to provide accurate service manuals so that competitors could safely maintain the trains. This was not a "just take your car to dave, he knows some stuff". For SPS and other competitors this was like "you need to show every certification that exists and certify all your tools to prove that indeed you can service those cars, or you will be foreclosed due to fines". Plus, they were provid…

i wouldnt be surprised if this info was somewhere in those 20k pages, and perhaps if the procedures were actually followed, stuff like GPS based lockouts wouldn't happen

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#107
post #80

Newag issued a statement since, denying all allegations and saying that it was their competition which "hired hackers to slander them". I've met q3k because we used to work at the same company and briefly on a project together. Not the kind of person I would suspect of participating in a conspiracy of this sort and Newag's statement generally reads like "we didn't think we would get caught".

^I think this is being downvoted because of poor reading comprehension skills. Please note that the parent comment is in favor of the hacking group.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#108
post #60

Earlier quoted context omitted.

What is the cause then?

Bad culture that views software as a necessary evil or afterthought rather than an important part of the product.

Same as industrial design then. You get the occasional Braun, Herman Miller or Apple, and a vast number of nondescript silver/beige/black boxes.

It's probably true of lots of aspects of product design - if it's not driven from the top, it's mediocre.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#109
post #75

Earlier quoted context omitted.

I don't think it's assholeish for someone who's not getting compensated in any way to not help out. It's a business. They have an active incentive to NOT help.

It's not about "not wanting to help". It's about placing logic bombs of "if vehicle is at this gps coordinates of a competitor, engage self-destruct". Hackers actually did extract such coordinates from train firmware.

unless we have the entirety of the context for this code and the 20,000 pages of service manuals, i do not accept at face value that it's this simple

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#110
post #65

Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".

I'm all for free and open source software, but what would you suggest here? That train operators will download code from the internet and install it on their trains?

The same way technical diagrams for roads, bridges and other public infrastructure are public.

In most OECD countries food needs to be labelled with a full list of ingredients.

Your GP can read scientific papers about the efficacy and risks of a new treatment.

(Yes, many papers are paywalled but that's irrelevant compared to secrecy)

Post reply on HN