Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

191–200 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#191
post #166

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Is there a strategy where China could remain a supplier of "lobotomized" hardware? Example: China supplies the trains, but all the silicon must be added after import.

At a guess, you'd find that the prices have mysteriously gone up.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#192
post #143

Earlier quoted context omitted.

The problem with "oh, but wait, this merger actually improves competition" is that mergers are a contagion. A large competitor's mere existence creates an economic imperative for more mergers. This happens both horizontally (across multiple firms) and vertically (up and down the supply chain). When you get big, you can start stripping your vendors' and customers' of their profit margin, which means they need to get b…

How do you confirm that a train controller or any other piece of hardware does not contain a backdoor using industry standard software tools? You can write whatever you want into a contract, but if you have no way to validate it, it's meaningless. Also, the state-owned (and subsidized) Chinese company that doesn't have to play by the West's antitrust rules doesn't need to worry about your "contagion" concerns.

You rip it out and replace it with one that you can trust. And of course you hope you find all of them.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#193
post #168
post #164

Earlier quoted context omitted.

> You can write whatever you want into a contract, but if you have no way to validate it, it's meaningless. 3rd party audit like everything else?

Okay, if you want to pass responsibility off to someone else, how does the third party auditor do it? I'm not talking about checking a compliance box, I'm talking about actually confirming no backdoor exists.

That's proving a negative. You are always going to end up with something like 'to the best of our ability'.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#194

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Why do we even have 'private' train companies again?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#195

This is likely laziness more than malice, but... why are busses connected to the internet?

Real time position tracking, CCTV streaming/archiving, automatic diagnostics logging, there's many reasons for a modern bus to have wireless data connections and I'd be shocked if most modern buses in the US and Europe don't already have such systems (i know here in Chicago the CCTV feeds can be viewed remotely by staff and most buses have their real time position available via public REST API, though i don't know what tech the buses themselves use to transmit that data)

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#196

Earlier quoted context omitted.

ask how serene fishermen in the area are while their country sovereignty on internationally recognized territorial water is infringed upon regularly

Except you know, NOT internationally recognized except to manufactured misconception by headline scanning useful idiots. Reminder PH PCA ruling is not actual international law, as in recognized by UN/UNCLOS, ITLOS, ICJ. TBH its demonstrably stupid to even hold the position UNCLOS can rule on sovereignty claims - they fucking can't. To suggest PRC is infringing on others maritime entitlement in SCS is so stupid it's n…

It's amazing how some upset fisherman look the same as a million murdered civilians in a lot of people's eyes

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#197
post #159

Earlier quoted context omitted.

No, that's not what I'm talking about, and you probably should get your information on foreign affairs from somewhere other than China Daily.

I get information from everywhere but reality has a china daily bias. This isn't complicated, you ask about PRC relation with neighbours I point out blind spot to of those with poor foriegn policy literacy, i.e. those who don't read enough china daily, that PRC has a lot of neighbours and most of them are in fact settled with PRC majority concessions and now at peace. If we're going to go even more China daily, essen…

Keep deflecting and spinning.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#198
post #168

Earlier quoted context omitted.

Okay, if you want to pass responsibility off to someone else, how does the third party auditor do it? I'm not talking about checking a compliance box, I'm talking about actually confirming no backdoor exists.

That's proving a negative. You are always going to end up with something like 'to the best of our ability'.

You figured it out. It's trivial to include a backdoor in a large system of systems, and one placed by a remotely competent adversary will not be found.

So what's the point of a regulation that can't be enforced?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#199

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

> Two major non-Chinese train companies attempted to merge Siemens (Germany) and Alstom (France) > It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal Margrethe Vestager, the European Commissioner for Competition at the time (2019). At the time of the decision, she said "No Chinese supplier has ever participated in a signaling tender in Europe or delivered a single…

> […] There is no prospect of Chinese entry in the European market in the foreseeable future.

The remark stands as yet another regrettable instance of history echoing itself – a lamentable parallel to that uttered by Sir Claude Maxwell MacDonald, whose acquisition of a 99-year lease over the New Territories of Hong Kong on behalf of the British Crown from the Qing dynasty was justified with the breathtakingly short-sighted assertion that it was «as good as forever».

One observes, with increasing weariness, that politicians – regardless of generation or supposed pedigree – remain obstinately immune to the most elementary of truths: history is neither linear nor predictable. It twists, recoils, and devours the complacent. Political decision-making, therefore, ought never be entrusted to those governed by the ephemeral whims of populism – it demands the discipline, foresight, and cold precision of a strategist trained not merely to react, but to foresee. Alas – such minds are in tragically short supply.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#200
Related:

Why Israel Just Banned 700 Chinese Cars from Its Military—And What It Means for Security - https://securityboulevard.com/2025/11/why-israel-just-banned...

IDF recalls 700 Chinese EVs used by senior officers over security concerns - https://www.thejc.com/news/israel/idf-recalls-chinese-evs-se...

Post reply on HN