Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

71–80 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#71

Whats sad is Norway sits right next to the country which manufactures Scania and Volvo Busses, but instead buys busses from thousands of km away. I suppose cost is all that maters these days, even for national infrastructure which must remain in control and secure.

I know for a fact that at least one of those companies also installs SIM cards in all their busses.

The only difference is who could potentially use the backdoor, and yes Sweden seems slightly less poised to attack Norway than China. At least these days. Because, let's face it, the Swedes owned Norway back in the day and them wanting their oil-rich lucky cousin back at home is deranged but not as much as the Chinese wanting the fjords....

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#72

Earlier quoted context omitted.

Don't attribute to malice what can adequately be explained by ignorance.

That seems like a cliché happily championed by the malicious.

Vs. conspiracy theorists are happy to imagine an evil genius black op behind every village idiot?

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#73
post #21

Surprisingly Norway choose this brand, never had a good ride in one, feels like sitting in a water boiler.

Maybe not so surprising as Norway summer temp averages get into mid 60s F (18C) at the warmest.

That's averages, but Norway has hot summer days too. Factor in thinner atmosphere (more UV), lower sun angles, over 20h days and you get more warmth with less average temperature.

And those buses stink like inside of a plastic factory. Never been to a plastic factory, but rode these buses. And the smell is strong even a year into use. Makes you wonder if China has same rules for carcinogenic plastic in consumer goods.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#74

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Logistics in war is essential so it’s not a stretch. You can easily extend that line of thought to anything from drones to cars.

Yes easily, like how they use all the public transit buses at the frontlines of ukraine

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#75
post #62

Earlier quoted context omitted.

Also it would probably be 5x as corrupt. The things you see in EU public tenders is just amazing, especially when they's little to no competition.

>The things you see in EU public tenders Can you give examples of what you (obviously, since you're commenting) have seen, and how typical it is?

This is one of those things that is so obvious as to not require a source. Just sharing my perspective on this conversation, I don’t think it’s an unreasonable question to ask if you’re unfamiliar with the space

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#76
post #57

Ah, and they never review iPhones/Android phones after Israeli companies demonstrated they can backdoor any cellphone on this planet, and especially after they demonstrated they can explode consumer devices and maim 3000+ people overnight. They don’t review Windows machines either after the Snowden revelations. How many wars did the Chinese start in the past century?

[dead]

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#77
post #65

Earlier quoted context omitted.

> If these were esims they would be much harder to detect or remove? It's not clear in the article how exactly they discovered it, but by the text that mentions it, I do get the impression they just came across the SIM ports/cards themselves: > internal tests at a secure facility found Romanian SIM cards inside the buses But it could also have been that they put the entire bus in a giant Faraday cage (or similar) and…

"But it could also have been that they put the entire bus in a giant Faraday cage" And that's what they did. If that was necessary for the conclusions is not said in the article. Only that the remote access could - Update software (well, that's pretty common) - Diagnosis (ditto), and - Manage the control system for battery and power supply. The conclusion by the team was that the buses can be remotely stopped or bric…

Bricking a bus via remote software update is easy. What is hard is remotely updating a vehicle and not bricking any of them. I'm under NDA so lets just say it is hard to get something that passes our test group when we are trying to make things work correctly. Trying to brick a vehicle is easy mode. (now if you want to brick it in a specific way that can be hard)

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#78

If your transport is accessible remotely, it can be hacked remotely. This reminds me of that story about Polish Trains. In that case GPS was used to execute a kill code. https://social.hackerspace.pl/@q3k/111528162462505087

When the next petya-class worm hits, IOT is going to be so very painful.

Personally, I'd like to skip over all of the buildup and go straight to hoverboard mafia pizza delivery.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#80

Earlier quoted context omitted.

Don't attribute to malice what can adequately be explained by ignorance.

That seems like a cliché happily championed by the malicious.

As recommended by the CIA: https://youtu.be/Ro7sIqpcspM
Post reply on HN