Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

121–130 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#121
post #62

Earlier quoted context omitted.

Also it would probably be 5x as corrupt. The things you see in EU public tenders is just amazing, especially when they's little to no competition.

>The things you see in EU public tenders Can you give examples of what you (obviously, since you're commenting) have seen, and how typical it is?

So the major, common and probably most destructive, theme is the ecosystem of specialised tender companies. I mostly know this from the software side, but if you start working on such projects, you'll quicky find out that there's a persistent ecosystem of companies which specialize for these tender signups.

People employed there optimize for winning them (at any cost - quid-pro-quo agreements aren't rare in my experience). It's common for several such companies to collude in a way that they get awarded the tenders in a circle ("I get this one, next one is for you.")

Afterwards, they outsource the work to the cheapest lowest bidder (usually IT studends in the cases I've seen for software development, but essentially they'll be bottom of the barrel juniors). The quality of such products is about the same as the quality of any outsourced product which is built only to satisfy a checklist at the end. The US equivalent of that would be a corporation getting a defense contract and then basically have everything built by the cheapest outsourcer in India or similar location. Funny enough, university labs (or spinoffs) tend to be major part of this ecosystem, using grad students as workforce - their credentials tend to give them legitimacy over smaller companies.

The results are as disastrous as you can expect - companies a HNer could expect to win usually don't (due to lack of specialized knowledge on how to game the tender process, lack of connections and cost) and those that do are really there to do the bare minimum, shed the work as much as possible and deliver something they can't get sued over.

It's also not uncommon to see whole chains of such companies - the winner sometimes shares some outsourcing work with "losers" they outsource work further, skimming the funds on top and essentially outsourcing everything to the cheapest engineer they can find.

Dealing with any public EU project has been nothing but misery for me personally (as you can imagine from this post :) and this environment bred some of the most toxic workplaces I've worked with. The products were universally terrible and rarely actually useful for the purpose.

As much as I want independent EU software ecosystem, I don't think using public funding can breed anything but more corruption.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#122
post #112

Whats sad is Norway sits right next to the country which manufactures Scania and Volvo Busses, but instead buys busses from thousands of km away. I suppose cost is all that maters these days, even for national infrastructure which must remain in control and secure.

Surprised to learn that Volvo manufactures buses in Sweden considering they're 78% owned by a Chinese conglomerate..

I think that's Volvo Cars that the main Volvo sold off to Ford and ended up with Geeky.

Trucks and busses remain with the parent Volvo AB.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#123

Earlier quoted context omitted.

Did anyone investigate this person to see if she’s being bought by any “Foreign” Gov’t?

Don't attribute to malice what can adequately be explained by ignorance.

If the past decade of my life has taught me anything, it's "attribute all malicious actions to malice." It's usually just a matter of direct vs. indirect malice. Meaning, are they directly benefiting from their malicious actions or are they just assholes who "do it for the lulz".

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#124

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Did anyone investigate this person to see if she’s being bought by any “Foreign” Gov’t?

Or maybe she just doesn't believe it's worth discarding anti-trust law over the bogeyman of the day.

The two train companies that couldn't merge can still make trains, and still sell them to whomever they want. European purchasers can still buy them. And after reading articles like this one, these two companies have a big competitive advantage: they don't include Chinese backdoors. Maybe they're small now, but if the Chinese train/bus/etc. manufacturing companies end up being blacklisted in the EU, these two companies will grow. And, better yet, there will still be some healthy competition in the space.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#125

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

The problem with "oh, but wait, this merger actually improves competition" is that mergers are a contagion. A large competitor's mere existence creates an economic imperative for more mergers. This happens both horizontally (across multiple firms) and vertically (up and down the supply chain). When you get big, you can start stripping your vendors' and customers' of their profit margin, which means they need to get b…

Re: the Newag situation, can their customers not sue them, win, and hurt Newag's bottom line enough that they stop pulling shit like this?

> EU agencies and member states do not have the power to disqualify Newag from future tenders for failing to adhere to prior ones

That seems like a problem that can be fixed, given the political will to do so.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#126
post #112

Whats sad is Norway sits right next to the country which manufactures Scania and Volvo Busses, but instead buys busses from thousands of km away. I suppose cost is all that maters these days, even for national infrastructure which must remain in control and secure.

Surprised to learn that Volvo manufactures buses in Sweden considering they're 78% owned by a Chinese conglomerate..

Volvo cars was sold to Geely but Volvo Buses (+ trucks) is still a Swedish company.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#127
post #57

Ah, and they never review iPhones/Android phones after Israeli companies demonstrated they can backdoor any cellphone on this planet, and especially after they demonstrated they can explode consumer devices and maim 3000+ people overnight. They don’t review Windows machines either after the Snowden revelations. How many wars did the Chinese start in the past century?

Glad you asked 1929 – Sino-Soviet Conflict (Chinese Eastern Railway) — ROC authorities moved to seize the CER in Manchuria; the USSR responded militarily. (Initiation: ROC seizure.) 1954–1955 – First Taiwan Strait Crisis — PRC began large-scale shelling of Kinmen/Matsu and amphibious operations (e.g., Yijiangshan). (Initiation: PRC artillery/offensives.) 1958 – Second Taiwan Strait Crisis — PRC opened intense bombard…

Glad you listed, because that data shows apart from Sino Vietnamese almost half a century ago, PRC launched basically no wars of aggression, i.e. everything including SCS was territorial defense, i.e just. And if it was in chart form, the peace disease lull in last 30 years relative to PRC growth makes modern PRC rise the most unprescedently peaceful in modern history, borderline on absurdly serenity. Truly somehting to emulate. Can you believe those Eurocusk gave a Peace prize to Obama?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#128

Earlier quoted context omitted.

Thank you for the details. > ...acknowledging mistakes made in the past " That's falling somewhat short of admitting she alone fucked that situation up. The US and Canada had already given permission for the merge to bypass antitrust laws.

Antitrust is important, so why not pass a law that prioritizes national or European companies for critical infrastructure, even if they're more expensive? Creating a monopoly to combat another monopoly is unlikely to end well in the future.

Agreed. I'd think a better solution would be to ban Chinese companies from these sorts of contracts, and invest in the non-Chinese companies to help them grow. You don't need to allow monopolies to form to be successful here.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#129
post #57

Ah, and they never review iPhones/Android phones after Israeli companies demonstrated they can backdoor any cellphone on this planet, and especially after they demonstrated they can explode consumer devices and maim 3000+ people overnight. They don’t review Windows machines either after the Snowden revelations. How many wars did the Chinese start in the past century?

Glad you asked 1929 – Sino-Soviet Conflict (Chinese Eastern Railway) — ROC authorities moved to seize the CER in Manchuria; the USSR responded militarily. (Initiation: ROC seizure.) 1954–1955 – First Taiwan Strait Crisis — PRC began large-scale shelling of Kinmen/Matsu and amphibious operations (e.g., Yijiangshan). (Initiation: PRC artillery/offensives.) 1958 – Second Taiwan Strait Crisis — PRC opened intense bombard…

This doesn't include their current border conflicts with India, which could potentially go hot.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#130
post #117

Earlier quoted context omitted.

Antitrust is important, so why not pass a law that prioritizes national or European companies for critical infrastructure, even if they're more expensive? Creating a monopoly to combat another monopoly is unlikely to end well in the future.

This seems like the most obvious solution, provided local offers aren't massively more expensive. I don't see why we wouldn't award contracts to EU companies that create jobs here, pay taxes here, and follow local regulations. We don't need a super company with a local monopoly, just to stop prioritising “as cheap as possible”.

The reason why is because if they did China would retaliate and cut off cheap access to Chinese imports. That is the double edged sword of globalization the US and Europe are reckoning with today, in different ways
Post reply on HN