Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

31–40 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#31

All I can say is that shivers go down my spine what could happen if one of those OEM's that have remote updates possible would get their keys compromised. You could brick hundreds of thousands of vehicles. I would be scared shitless to store those things.

Forget bricking them. How about driving their batteries to overheat? An entire fleet across a city enflamed...

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#32

If these were esims they would be much harder to detect or remove? BYD electric busses have recently rolled out where I live in Sweden.

> If these were esims they would be much harder to detect or remove? It's not clear in the article how exactly they discovered it, but by the text that mentions it, I do get the impression they just came across the SIM ports/cards themselves: > internal tests at a secure facility found Romanian SIM cards inside the buses But it could also have been that they put the entire bus in a giant Faraday cage (or similar) and…

A local group of security people have been running a weekend project they call Project Lion Cage where they take Chinese cars into a local mine with spectrum analyzers etc. to watch where they send data and so on. This is how the bus was evaluated as well. Tor Indstøy has quite a few posts on his LinkedIn page talking about the work and what they have found.

Press release (Norwegian): https://www.mynewsdesk.com/no/ruter/pressreleases/ruter-tar-...

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#33

I do worry if they are adding this to buses what are they doing to MacBooks and your phone? Do people here think these devices are compromised or should we take Apple’s word for it!?

Do you seriously think Apple wouldn’t notice? They’re probably one of the most hated companies in the world, millions are itching to see them fail.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#34
post #8
post #7

Earlier quoted context omitted.

This is why we invented the fine print. Not putting this information in the fine print is fraudulent behaviour

It was most likely in the specs from the beginning. You can't have busses roaming around with no way to turn them off remotely.

What? That's the way it's always been.

Do you imagine some benevolent authority sits in your town with a finger on the kill switch for every vehicle in motion?

If it were in the specs from the beginning, there would be no issue. This isn't a "click here to accept" thing; multiple people scan the technical data in these projects.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#35
post #15

I do worry if they are adding this to buses what are they doing to MacBooks and your phone? Do people here think these devices are compromised or should we take Apple’s word for it!?

Of course they're compromised, by Apple, to comply with UK law.

Well only in the UK, if you have the -banned in the UK- ADP on as far as people know it’s not compromised

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#36
post #4

This is just stupid. All modern vehicles har been fully remote controllable for years.

100% false. For obvious reasons, non-CBTC trains are not remotely controllable (CBTC essentially means "remotely driven"). It's all or nothing; either a safety system that inherently accepts the risk, or no way to remotely control the speed, short of fully stopping the train. If modern cars have been fully remotely controllable for years, why can't police stop often-deadly car chases? Ditto on air traffic control and…

[flagged]

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#37

Earlier quoted context omitted.

100% false. For obvious reasons, non-CBTC trains are not remotely controllable (CBTC essentially means "remotely driven"). It's all or nothing; either a safety system that inherently accepts the risk, or no way to remotely control the speed, short of fully stopping the train. If modern cars have been fully remotely controllable for years, why can't police stop often-deadly car chases? Ditto on air traffic control and…

[flagged]

What on Earth are you rambling about now?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#38
>The transport operator stressed there is no evidence of misuse but said the discovery moves concerns “from suspicion to concrete knowledge”. (...) The case comes as Chinese electric buses are increasingly adopted across global markets,

If a state wants to hide strategic "war/espionage" control, they don't use eSims and open mobile communications, trivially discoverable and traceable. Sounds like some bs "IoT" / telemetry shit manufactures are shoving down our throats for over a decade.

The other side is feigning shock at common industry practices (don't all Tesla's require a net connection for example), to paint it as some unique issue, and kill their sales. In other words , just another episode in the trade war.

Not unlike the DJI drones, which added all kinds of shit because the regulators demanded it, and then they act surprised that it has that shit...

https://uavcoach.com/dji-ban/#7

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#39
post #4

This is just stupid. All modern vehicles har been fully remote controllable for years.

100% false. For obvious reasons, non-CBTC trains are not remotely controllable (CBTC essentially means "remotely driven"). It's all or nothing; either a safety system that inherently accepts the risk, or no way to remotely control the speed, short of fully stopping the train. If modern cars have been fully remotely controllable for years, why can't police stop often-deadly car chases? Ditto on air traffic control and…

>If modern cars have been fully remotely controllable for years, why can't police stop often-deadly car chases?

They want to retain the power of discretionary action. If the powers that be employed their 1984 stuff all the time over trivial things people wouldn't support them. Part of this means they don't give the beat cops those toys.

Also, there's a difference between "can be" and "are". Like there's god knows how many numbers of compatibility layers and intermediary systems I bet even if the capability exists it's broken more often than it's not. Diverse software systems take a ton of constant work to maintain.

During the "last years of XP" era you probably could have theoretically taken down half the world's industry on paper but if you tried to do so at scale without literal years of prep and testing you'd have been foiled by the 50% of machines where you payload just didn't work for some obscure reason.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#40

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Logistics in war is essential so it’s not a stretch. You can easily extend that line of thought to anything from drones to cars.
Post reply on HN