Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

81–90 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#81
post #67
post #12

Whatever happened with the Polish trains that had all the backdoors that were discovered?

Ah, but you see, domestic enshittification and anti-consumer actions are different from the foreign influence boogeyman. \s

https://www.aftenposten.no/norge/i/Vz7LA6/forsvarets-kinesis...

Here, an article (from June 2025) about Chinese buses full of cameras and other sensors driven regularly inside secret Norwegian army bases. Those buses are to be used during a war or a crisis.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#82
post #7
post #6

Earlier quoted context omitted.

I wasn't aware of that, thanks. But still, if you go buy a car right now, I doubt they are going to make it a sales pitch that you are not the only one who can control your car.

This is why we invented the fine print. Not putting this information in the fine print is fraudulent behaviour

There are limits to what can be put into the fine print as well. We probably need to revisit though rules, but you can't get away with anything just by putting it in the fine print.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#83

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

> Two major non-Chinese train companies attempted to merge Siemens (Germany) and Alstom (France) > It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal Margrethe Vestager, the European Commissioner for Competition at the time (2019). At the time of the decision, she said "No Chinese supplier has ever participated in a signaling tender in Europe or delivered a single…

[deleted]

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#84

I do worry if they are adding this to buses what are they doing to MacBooks and your phone? Do people here think these devices are compromised or should we take Apple’s word for it!?

Do you seriously think Apple wouldn’t notice? They’re probably one of the most hated companies in the world, millions are itching to see them fail.

> They’re probably one of the most hated companies in the world

By tecchies.

That’s like adding “In Mice,” to headlines of biological breakthroughs.

It’s quite clear that a fairly significant majority of customers don’t hate Apple. They aren’t “brand slaves,” like Harley riders (anymore), but people clearly vote with their wallets.

Microsoft always had the “My work requires it” thing going, but only a couple of industries are majority Apple.

Like it or not, people pay personal money for Apple kit, and they are a demographic that marketers drool over.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#85

Earlier quoted context omitted.

Forget bricking them. How about driving their batteries to overheat? An entire fleet across a city enflamed...

Not sure that would be possible on demand, but... Yeah, there are tons of options there. Absolutely terrifying. For context, for a short while I wrote SW for auto BCM's albeit the security stuff not the drive your batteries stuff.

Didn’t North Korea supposedly start a data center fire to cover their tracks? I believe they attached the UPS batteries.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#86
post #8

Earlier quoted context omitted.

It was most likely in the specs from the beginning. You can't have busses roaming around with no way to turn them off remotely.

Yes, those wild buses on the loose have been a major problem

Kinda explains why nothing is being done in Poland about hunters accidently killing lots of people, mistaking them for boars. If you crack down on hunters, you can't have them control the population of wild buses.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#88
post #26

So... did the Chinese company put Romanian SIMs in the busses? Or was it an importer that installed those? Are there fleet management features enabled by that connectivity or are they actually secret? Also, why would they purchase busses that they thought couldn't be remotely monitored or controlled?! That seems like a very valuable feature for public transport.

To me this smells of rather basic economic/political propaganda to scare people. The collective west is clearly getting orders from high above to apply pressure on China and it may just be that this is part of it, spreading an air of concern and fear to dissuade other people who pay attention to this kind of thing in municipalities to avoid Chinese manufacturers. It's rather basic social engineering that has the ham fist of "intelligence" all over it.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#90
post #68

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

About a year ago a Polish rail equipment supplier brought a lawsuit over a locomotive because it was serviced by a third-party, and the service was enabled by jailbreaking software in the locomotive. Surveillance tech in products doesn't necessarily imply grey zone warfare. But that doesn't make it a good thing either.

I'm not sure this comment does justice to the situation.

Poland put out a separate bid for manufacturing and servicing of their locomotives and one company won the manufacturing bid while another won the servicing bid.

The servicing company was unable to get the trains into working order and after hiring hackers accused the manufactoring company of bricking the software on purpose by including geo-fences where the trains would no longer work after arriving at the servicing company's property.

Perhaps the interesting part to me was Dragon Sector's (the hackers) claims that the software needs to be blessed so although they discovered problems they never changed anything because they don't have the authority to bless it and heavily imply that the fact that the manufactoring company is changing the software at will is illegal.

The changes by the manufactoring company had an (undisclosed) activation sequence added to it so you didn't need to modify the software in order to get the train working so the servicing company never actually modified the software.

https://www.youtube.com/watch?v=XrlrbfGZo2k

https://www.ifixit.com/News/112008/polish-train-maker-is-sui...

Post reply on HN