Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

171–180 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#171
post #167

This is exactly why BYD is and should continue to be banned in the US. It’s not that they are doing this, but that they have done it and they have the capability

should US products be banned outside the US because NSA has done all those fancy things and have the capability to do it again?

[deleted]

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#173

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

China is not a free market and shouldn’t be allowed to compete as if it were.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#174

All I can say is that shivers go down my spine what could happen if one of those OEM's that have remote updates possible would get their keys compromised. You could brick hundreds of thousands of vehicles. I would be scared shitless to store those things.

Forget bricking them. How about driving their batteries to overheat? An entire fleet across a city enflamed...

If they were designed to do that from the start maybe. But usually low level stuff like battery management wouldn't be accessible to the main updatable OS. A lot of it isn't even software controlled, but physical parts designed to pop before things catch fire.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#175
post #32

Earlier quoted context omitted.

> If these were esims they would be much harder to detect or remove? It's not clear in the article how exactly they discovered it, but by the text that mentions it, I do get the impression they just came across the SIM ports/cards themselves: > internal tests at a secure facility found Romanian SIM cards inside the buses But it could also have been that they put the entire bus in a giant Faraday cage (or similar) and…

A local group of security people have been running a weekend project they call Project Lion Cage where they take Chinese cars into a local mine with spectrum analyzers etc. to watch where they send data and so on. This is how the bus was evaluated as well. Tor Indstøy has quite a few posts on his LinkedIn page talking about the work and what they have found. Press release (Norwegian): https://www.mynewsdesk.com/no/ru…

If you wanted to maliciously get around this you could just listen for background radio signals. When AM radio and GPS vanish, don't transmit.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#176
post #167

This is exactly why BYD is and should continue to be banned in the US. It’s not that they are doing this, but that they have done it and they have the capability

should US products be banned outside the US because NSA has done all those fancy things and have the capability to do it again?

NSA sold cars with remote bricking feature?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#178
post #167

This is exactly why BYD is and should continue to be banned in the US. It’s not that they are doing this, but that they have done it and they have the capability

should US products be banned outside the US because NSA has done all those fancy things and have the capability to do it again?

I think it would be eminently reasonable for e.g. China to ban US products on those grounds.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#180

Earlier quoted context omitted.

Glad you asked 1929 – Sino-Soviet Conflict (Chinese Eastern Railway) — ROC authorities moved to seize the CER in Manchuria; the USSR responded militarily. (Initiation: ROC seizure.) 1954–1955 – First Taiwan Strait Crisis — PRC began large-scale shelling of Kinmen/Matsu and amphibious operations (e.g., Yijiangshan). (Initiation: PRC artillery/offensives.) 1958 – Second Taiwan Strait Crisis — PRC opened intense bombard…

Glad you listed, because that data shows apart from Sino Vietnamese almost half a century ago, PRC launched basically no wars of aggression, i.e. everything including SCS was territorial defense, i.e just. And if it was in chart form, the peace disease lull in last 30 years relative to PRC growth makes modern PRC rise the most unprescedently peaceful in modern history, borderline on absurdly serenity. Truly somehting…

The invasion of Zhenbao island was "territorial defense", really?
Post reply on HN