Live data from Hacker News

Dieselgate, but for trains – some heavyweight hardware hacking

badcyber.com

71–80 of 309 posts

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#71
post #65

Great advert for free and open source software. As with dieselgate, this suggests you basically cannot trust anything containing software. Can't trust it to follow regulations. Can't trust it to do its job. Can't trust the software. Can't trust the institutions that write the software. All very "late stage capitalist software development".

I'm all for free and open source software, but what would you suggest here? That train operators will download code from the internet and install it on their trains?

Clearly not. A reasonable expectation might be though that if you want to sell your multi million pound products to a captive public sector, you have to publish all the source code and the means to build the binaries.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#72

Seems like deliberate sabotage via software to force the costumer to buy the manufacturer’s services instead of 3rd party (cheaper) ones. Curious to see the court’s decision.

There’s no question that it’s sabotage. The only thing left to prove is the culprit, which is with 99% the manufacturer (motive, means, opportunity) but obviously need to be established in a court who is responsible and criminally culpable.

The fact that lawmakers, courts and the public are lost in the tech is a problem, but surely this crime can be fitted into existing criminal code against sabotage… although the methods are “new” the crime itself is classic.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#73
post #14

Earlier quoted context omitted.

>The train manufacturer, Newag, also competed in the tender to carry out the maintenance, but the manufacturer’s bid was about 750k USD higher and the tender was eventually won by SPS, which offered to carry out the maintenance of 11 trains for around 5.5 mln USD.

Just thinking outloud. But if you made it so your competitor couldn't fulfill their servicing contract, then the entity taking out the contract might just very well come to you to solve the problem. You might not win the contract on price, but win it by default because you made it impossible for anyone else to complete it. That is until your scheme is uncovered because you left the GPS coordinates of your competitors…

More sanely (not to be confused with likely!) the courts will decide that since this is something only the OEM can do, it must done at no charge as part of normal warranty work.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#74

In a properly functioning country the responsible persons should already be imprisoned. Some governmental agencies were aware of that for at least half a year, but failed to act. The fact that source code was not immediately dumped and analyzed is the evidence of malevolence, corruption and intentionally putting people's lives at risk. Welcome to the dark side of Poland - where citizens don't matter.

Corruption is not just the dark side of Poland, but the entire west IMHO

Yes, the west is corrupt. The rest is worse though, and less ashamed of it.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#75
post #17

Earlier quoted context omitted.

There wasn't just one manufactured failure, but multiple different ones. Refusing to help would also point towards intentional malice. Why would you sell a product, then refuse to assist, unless you've intentionally designed the product to fail so only you would know how to make it work again?

The manufacturer lost the bidding process, so quite reasonably (if you look at it in a limited fashion) said "Fine, let SLS do the work, you're on your own". Arsehole-ish, but not illegal. All the hidden lockouts on the other hand....

I don't think it's assholeish for someone who's not getting compensated in any way to not help out. It's a business. They have an active incentive to NOT help.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#76
post #62

Its insane how brazen this is. Code that 'bricks' the train locomotive if its gps coordinates remain with bounds of a competing repair facility for more than ten days! This is way beyond putting information barriers to repair, like undocumented interfaces or even crypto-signed firmware. This is actively malicious destruction of property. I don't know anything about the legal system in Poland, but I can't imagine how…

If an individual did this, they'd go to prison.

And if it is a big or even state company we need to save and ensure workplaces, or "hello dear lobbyist with that big suitcase!" :D

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#77
post #4

But was this sabotage by an insider at the manufacturer, or something deliberate by the manufacturer?

If the manufacturer did it, doesn't it still fit the definition? It's something like "deliberately causing something to fail", regardless of who does it.

While I believe intentions were malicious, it's very easy to argue that

1. it's not failing, it's disabling

2. it's a safety feature - "SPS can't safely maintain these trains, so we have a safety lock out if they attempt it"

3. there is a ton of stuff that works this way - even Harley Davidson motorcycles require authorized maintenance and the bike's computer won't accept repairs unless a proprietary tool is used

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#78

[flagged]

It is clear you haven't even clicked on the article. Shame on you. This deserves a ban from HN. Just reading the headlines and contributing to a discussion about that article as if you actually read it is deceptive and wrong. It's killing our ability to meaningfully discuss content when people just read the headlines. If you don't want to read articles and instead post about what you think the articles must be based…

he accepted he made a mistake, chill out. downvote and move on

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#79
post #28

My impression is that the quality of train firmware is generally not very good, and I hope that this scandal will lead to greater scrutiny. 3 years ago, Deutsche Bahn publicly complained of "grotesque" software problems with newly delivered Bombardier trains. For example, when train drivers changed the direction of travel, the train software would crash. It then took 1 hour to boot the train up again [0]. Switzerland…

Because this software is not made by software engineers, it's made by plc programmers, electric circuit designers and whoever did drift into the field. Except for beckhoff to tc3 they haven't made it to object orientation yet, so the field is stuck as a whole in the blue screen mines of yore. Managing complexity with thin standard docs, no version control while the machines grow ever more complex sensor and actuator…

> ... they haven't made it to object orientation yet, ...

Not always a blessing and I've actually recently been thinking (e.g. in context of Lua) if object orientation is in most situations not better to avoid.

Re: Dieselgate, but for trains – some heavyweight hardware hacking

#80
Newag issued a statement since, denying all allegations and saying that it was their competition which "hired hackers to slander them".

I've met q3k because we used to work at the same company and briefly on a project together. Not the kind of person I would suspect of participating in a conspiracy of this sort and Newag's statement generally reads like "we didn't think we would get caught".

Post reply on HN