Live data from Hacker News

Norway reviews cybersecurity after remote-access feature found in Chinese buses

scandasia.com

91–100 of 235 posts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#91

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

The problem with "oh, but wait, this merger actually improves competition" is that mergers are a contagion. A large competitor's mere existence creates an economic imperative for more mergers. This happens both horizontally (across multiple firms) and vertically (up and down the supply chain). When you get big, you can start stripping your vendors' and customers' of their profit margin, which means they need to get big to compensate. Even if a merger might have positive competitive effects, it still spreads the contagion. Which is a problem, because anyone who doesn't or can't get big will get fucked. That includes individual consumers and workers.

If the problem is that Chinese companies are shipping train firmware with backdoors, then you need to ban those companies. Problem is, given the Newag situation[0], I don't think they can actually do this at the level of individual procurements. So they need specific EU directives banning this behavior and explicitly adding a process by which procurement can ban suppliers for prior noncompliance. What facilitating an illegal merger will do is reduce the EU's bargaining power with industry, ensuring that we get more backdoored trains and more risk.

[0] Short version: they got caught shipping firmware that bricks the train if you take it to a third-party repair shop, even though the contract specifically mandated Newag provide repair manuals. EU agencies and member states do not have the power to disqualify Newag from future tenders for failing to adhere to prior ones, so they keep winning contracts

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#92

Earlier quoted context omitted.

>The things you see in EU public tenders Can you give examples of what you (obviously, since you're commenting) have seen, and how typical it is?

This is one of those things that is so obvious as to not require a source. Just sharing my perspective on this conversation, I don’t think it’s an unreasonable question to ask if you’re unfamiliar with the space

> What can be asserted without evidence can also be dismissed without evidence.

Hitchen's Razor.

"Everyone knows" is always a dangerous place to stand in any argument.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#93

Earlier quoted context omitted.

Do you seriously think Apple wouldn’t notice? They’re probably one of the most hated companies in the world, millions are itching to see them fail.

So where will they get Mac’s or iPhones made if they found out there was some shenanigans going on?

The make a lot of stuff in India and Vietnam now due to the tariffs and general attempts at diversifying

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#94
lets see, a modern bus has, woooooo, conectivity, woooooo, on basicly everything, woooooo, so some manager can obsess over oil filters or the voltage on the lighting circuit, and the sixteen antenas advertised in the broshure were,in fact installed realy, wtf?, it's not like anybody is unaware that something like 10 billion things are conected to the net, and dozens, ? hundreds, of actors are doing there best to slurp up every last scrap of data, ha!, that they can the worst part is that it would be no surprise to find out that the bus comes with a monitering contract that is in effect.

next it will be cranes all sensored up to detect cable stretch or who know what

and didn't china just go ahead and hack the pentagon, but wooooo, Norwiegen bus hacking wooooo

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#95
post #41

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

The European champion would still be ten times smaller than the Chinese but would have factual monopoly in Europe. I don’t think blocking the merger was entirely unreasonable.

The parent comment is describing a scenario where the Chinese company may get a factual monopoly in Europe because it can outcompete the two European companies due to economies of scale.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#97

I work in rail safety. Two major non-Chinese train companies attempted to merge a few years ago, explicitly to build a company that could compete with China's national company, and provide safer alternatives to state-sponsored cyberhacking of Western rail. It fell down to an anti-monopoly decision by a single person in the EU ministry, who killed the proposal. Several attempts were made to streamline the merger, but…

Honestly I couldn't care less considering how scummy our train making companies are, I'm fine with Chinese selling trains on a loss for pieces of paper. It's their problem if they want to build them and ship them for pennies, their loss.

Our companies meanwhile are all turning in John Deere, and I'm glad the merger was blocked.

The security part, obviously I do care but this article says very little about it.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#98

If your transport is accessible remotely, it can be hacked remotely. This reminds me of that story about Polish Trains. In that case GPS was used to execute a kill code. https://social.hackerspace.pl/@q3k/111528162462505087

When the next petya-class worm hits, IOT is going to be so very painful. Personally, I'd like to skip over all of the buildup and go straight to hoverboard mafia pizza delivery.

Go full Snowcrash - I can think of several current world leaders who need "Poor Impulse Control" tattooing on their foreheads.

I need to re-read that book, one of my all time favourites.

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#99
post #62

Earlier quoted context omitted.

Also it would probably be 5x as corrupt. The things you see in EU public tenders is just amazing, especially when they's little to no competition.

>The things you see in EU public tenders Can you give examples of what you (obviously, since you're commenting) have seen, and how typical it is?

Here's a short 30 pages on corruption and collusion risks in Hungary and Poland from the Yearbook of European Law, Volume 41, 2022

https://academic.oup.com/yel/article/doi/10.1093/yel/yeac009...

Re: Norway reviews cybersecurity after remote-access feature found in Chinese buses

#100
post #8
post #7

Earlier quoted context omitted.

This is why we invented the fine print. Not putting this information in the fine print is fraudulent behaviour

It was most likely in the specs from the beginning. You can't have busses roaming around with no way to turn them off remotely.

Better than a bus that are blown up if it goes under 50 mph.
Post reply on HN