>it is hard to find an institution in Poland that has done anything beyond kindly expressing interest in the matter. We are not aware of any action taken either by the Office of Consumer and Competition Protection or by the Railway Transport Office, That the worst part of all that.
Dieselgate, but for trains – some heavyweight hardware hacking
141–150 of 309 posts
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#142Earlier quoted context omitted.
If an individual did this, they'd go to prison.
Companies are made up of individuals. I'm all for holding everybody who contributed to this malware accountable.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#143Nevermind malware, not using seL4 should already be a crime in this context.
We have rovers on Mars and satellites and probably nuclear warheads using RTOS of all kinds and in cases even Linux, but sure seL4 is the only OS conceivable for those cases, obviously ! This is a case of fraud, industrial malfeasance and just plain dishonesty. The software component of the story and its security measures are not even at play. Sure they are probably shit (given the date parsing ...) but even FreeRTOS…
Absolutely, and thus there's obvious room for improvement.
>This is a case of fraud, industrial malfeasance and just plain dishonesty.
In practice, this amounts to critical infrastructure sabotage, which fits into terrorism.
If the train network experiences issues, the whole country is impacted.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#144Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…
If an individual did this, they'd go to prison.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#145Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".
Hell, even if governments are squeamish about requiring code to be fully open and public, they can still require the manufacturers to privately submit to the government all code that powers public infrastructure (like trains), to be made available to any relevant party upon request.
I wonder if companies purchasing trains could put code disclosure in the purchase contract? I wonder if, in aggregate, train purchasers or car purchasers could fund an independent code storage vault and pay a small premium to fund that code vault organization?
In other words, if purchasers wanted this and valued this, they would demand it in purchase contracts and fund it.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#146Earlier quoted context omitted.
If the manufacturer did it, doesn't it still fit the definition? It's something like "deliberately causing something to fail", regardless of who does it.
While I believe intentions were malicious, it's very easy to argue that 1. it's not failing, it's disabling 2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it" 3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#147Nevermind malware, not using seL4 should already be a crime in this context.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#148Seems like deliberate sabotage via software to force the costumer to buy the manufacturer’s services instead of 3rd party (cheaper) ones. Curious to see the court’s decision.
There’s no question that it’s sabotage. The only thing left to prove is the culprit, which is with 99% the manufacturer (motive, means, opportunity) but obviously need to be established in a court who is responsible and criminally culpable. The fact that lawmakers, courts and the public are lost in the tech is a problem, but surely this crime can be fitted into existing criminal code against sabotage… although the me…
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#149Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…
I honestly hope that company will be fined to the oblivion, and for criminal charges for that, but i doubt it will happen.
Re: Dieselgate, but for trains – some heavyweight hardware hacking
#150Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…
If an individual did this, they'd go to prison.