Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

21–30 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#22
post #4

This is just stupid. All modern vehicles har been fully remote controllable for years.

I fully agree. If these were buses from any other country, this would not be an issue. Every road vehicle sold today has a sim card, most for diagnostics, some for remote control.

Having "a sim card" is less than saying your car "has an on-board computer". In no way does that imply remote control.

Even you admit that most of them aren't for remote control, so what are you agreeing with?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#23
All I can say is that shivers go down my spine what could happen if one of those OEM's that have remote updates possible would get their keys compromised. You could brick hundreds of thousands of vehicles. I would be scared shitless to store those things.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#25
If your transport is accessible remotely, it can be hacked remotely. This reminds me of that story about Polish Trains. In that case GPS was used to execute a kill code. https://social.hackerspace.pl/@q3k/111528162462505087

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#26
So... did the Chinese company put Romanian SIMs in the busses? Or was it an importer that installed those? Are there fleet management features enabled by that connectivity or are they actually secret?

Also, why would they purchase busses that they thought couldn't be remotely monitored or controlled?! That seems like a very valuable feature for public transport.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#27
post #21

Surprisingly Norway choose this brand, never had a good ride in one, feels like sitting in a water boiler.

Maybe not so surprising as Norway summer temp averages get into mid 60s F (18C) at the warmest.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#28
post #26

So... did the Chinese company put Romanian SIMs in the busses? Or was it an importer that installed those? Are there fleet management features enabled by that connectivity or are they actually secret? Also, why would they purchase busses that they thought couldn't be remotely monitored or controlled?! That seems like a very valuable feature for public transport.

Good questions!

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#29
I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail.

It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but she wouldn't budge.

As a result, CRCC continues to win contracts abroad, largely (it is believed) by undercutting competition. IP theft is known to be one objective of their at-loss or low-profit contracts (I've been involved in fighting that, specifically).

It's hardly a stretch to imagine that having control of the rail in countries that might oppose you militarily is strategically huge.

This article is about busways, but the parallels are obvious.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#30

If your transport is accessible remotely, it can be hacked remotely. This reminds me of that story about Polish Trains. In that case GPS was used to execute a kill code. https://social.hackerspace.pl/@q3k/111528162462505087

This 10 year old article may be of interest if you are into stuff like that: https://illmatics.com/Remote%20Car%20Hacking.pdf
Post reply on HN