Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

61–70 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#61
post #8
post #7

Earlier quoted context omitted.

This is why we invented the fine print. Not putting this information in the fine print is fraudulent behaviour

It was most likely in the specs from the beginning. You can't have busses roaming around with no way to turn them off remotely.

"You can't have busses roaming around with no way to turn them off remotely."

Hm? Not a single bus on the road in my city can be turned off remotely. There's never been one ever, since bus transport started. So why should, no, must, that be a feature of new buses?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#62
post #41

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

The European champion would still be ten times smaller than the Chinese but would have factual monopoly in Europe. I don’t think blocking the merger was entirely unreasonable.

Also it would probably be 5x as corrupt.

The things you see in EU public tenders is just amazing, especially when they's little to no competition.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#63

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

The west is too lax on some of these officials. People like this should be thoroughly investigated. China is flagrantly breaking the rules of the WTO that the west has set up, having state backed companies, and these people are either purposefully or unintentionally undermining the west's efforts to fight back.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#64

I do worry if they are adding this to buses what are they doing to MacBooks and your phone? Do people here think these devices are compromised or should we take Apple’s word for it!?

And that other place, with the Cloud act.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#65

If these were esims they would be much harder to detect or remove? BYD electric busses have recently rolled out where I live in Sweden.

> If these were esims they would be much harder to detect or remove? It's not clear in the article how exactly they discovered it, but by the text that mentions it, I do get the impression they just came across the SIM ports/cards themselves: > internal tests at a secure facility found Romanian SIM cards inside the buses But it could also have been that they put the entire bus in a giant Faraday cage (or similar) and…

"But it could also have been that they put the entire bus in a giant Faraday cage"

And that's what they did. If that was necessary for the conclusions is not said in the article. Only that the remote access could

  - Update software (well, that's pretty common)  
  - Diagnosis (ditto), and 
  - Manage the control system for battery and power supply. 
The conclusion by the team was that the buses can be remotely stopped or bricked by the manufacturer.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#66
post #57

Ah, and they never review iPhones/Android phones after Israeli companies demonstrated they can backdoor any cellphone on this planet, and especially after they demonstrated they can explode consumer devices and maim 3000+ people overnight. They don’t review Windows machines either after the Snowden revelations. How many wars did the Chinese start in the past century?

Glad you asked

1929 – Sino-Soviet Conflict (Chinese Eastern Railway) — ROC authorities moved to seize the CER in Manchuria; the USSR responded militarily. (Initiation: ROC seizure.) 1954–1955 – First Taiwan Strait Crisis — PRC began large-scale shelling of Kinmen/Matsu and amphibious operations (e.g., Yijiangshan). (Initiation: PRC artillery/offensives.) 1958 – Second Taiwan Strait Crisis — PRC opened intense bombardment of Kinmen/Matsu. (Initiation: PRC artillery.) 1962 – Sino-Indian War — PRC launched major offensives in October after a series of frontier incidents. (Initiation: PRC large-scale attack; India calls it unprovoked, PRC says “counter-attack.”) 1967 – Nathu La & Cho La clashes (India border) — Firefights erupted while India was fencing the pass; Chinese forces are generally assessed to have fired first at Nathu La. (Initiation: PRC fire in initial clash.) 1969 – Sino-Soviet Border Conflict — PLA ambushed Soviet troops on Zhenbao/Damansky Island in March; further clashes followed. (Initiation: PRC ambush.) 1974 – Battle of the Paracel Islands (vs South Vietnam) — PLAN/PLA forces expelled RVN units and took full control of the Paracels. (Initiation: PRC naval attack in contested area.) 1979 – Sino-Vietnamese War — PRC invaded northern Vietnam in February. (Initiation: PRC cross-border invasion.) 1984–1989 – Sino-Vietnamese Border War (post-1979 phase) — PRC mounted periodic offensives and artillery duels (e.g., Laoshan/Johnson Mountain). (Initiation: multiple PRC attacks in a protracted conflict.) 1988 – Johnson South Reef Skirmish (Spratlys, vs Vietnam) — PLAN engaged Vietnamese forces and seized the reef. (Initiation: PRC assault during standoff.)

Internal (civil/unification campaigns) 1926–1928 – Northern Expedition — ROC (KMT) launched a national unification war against warlords. (Initiation: ROC campaign.) 1930–1934 – Encirclement Campaigns against the Chinese Soviet — ROC initiated successive large operations against CCP base areas. (Initiation: ROC offensives.) 1949–1950 – Hainan & Zhoushan/Coastal-Islands Campaigns — PRC amphibious operations against ROC-held islands during the civil war endgame. (Initiation: PRC landings.) 1950–1951 – Tibet (Chamdo campaign → occupation) — PLA entered eastern Tibet and compelled the Seventeen-Point Agreement. (Initiation: PRC invasion; PRC frames as “peaceful liberation.”)

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#68

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

About a year ago a Polish rail equipment supplier brought a lawsuit over a locomotive because it was serviced by a third-party, and the service was enabled by jailbreaking software in the locomotive.

Surveillance tech in products doesn't necessarily imply grey zone warfare. But that doesn't make it a good thing either.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#69

All I can say is that shivers go down my spine what could happen if one of those OEM's that have remote updates possible would get their keys compromised. You could brick hundreds of thousands of vehicles. I would be scared shitless to store those things.

Forget bricking them. How about driving their batteries to overheat? An entire fleet across a city enflamed...

Not sure that would be possible on demand, but... Yeah, there are tons of options there. Absolutely terrifying.

For context, for a short while I wrote SW for auto BCM's albeit the security stuff not the drive your batteries stuff.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#70
post #62
post #41

Earlier quoted context omitted.

The European champion would still be ten times smaller than the Chinese but would have factual monopoly in Europe. I don’t think blocking the merger was entirely unreasonable.

Also it would probably be 5x as corrupt. The things you see in EU public tenders is just amazing, especially when they's little to no competition.

>The things you see in EU public tenders

Can you give examples of what you (obviously, since you're commenting) have seen, and how typical it is?

Post reply on HN