A polish hacker found out why trains did stop working. The manufacterer implemented a hidden electronic switch, which automatically activated after trains were serviced by a different company.

  • BombOmOm
    link
    fedilink
    English
    1987 months ago

    the PLC code actually contained logic that would lock up the train with bogus error codes after some date

    I hope they sue the manufacturer.

    • @[email protected]
      link
      fedilink
      English
      1467 months ago

      I hope messing with critical public infrastructure carries criminal not civil penalties, with people going to jail.

      • @[email protected]
        link
        fedilink
        English
        247 months ago

        Idk about Poland but in america a corporation is a person yet it cant be put in jail so only civil penalties are possible and the employees are mostly immune

        • @[email protected]
          link
          fedilink
          English
          137 months ago

          Corporations are people in the legal sense everywhere (i.e. they are subjects of the law with rights and duties). The novelty in the US is that the archaic constitution allowed the US Supreme Court to be creative in assigning rights that every other country assigns only to natural persons to legal persons. In the case of Poland, for example, the constitution explicitly mentions legal persons when rights are supposed to apply to corporations too.

        • @[email protected]
          link
          fedilink
          English
          67 months ago

          You can’t put a company in jail but definitely the asshole that gave the order to do that…

    • @[email protected]
      cake
      link
      fedilink
      English
      227 months ago

      Manufacture should be charged with public engagement or similar.

      An unexpected dead train on a track, emitting bogus codes that possibly confuse rail systems (thus resulting in other trains not being properly warned) could result in a lot of harm. Managers and executives found to be responsible for the team that implemented it should be hit hardest

  • @[email protected]
    link
    fedilink
    English
    837 months ago

    Can we now finally say that drm sucks and any/all attempts to override it are reasonable because it’s broken by design?

  • @[email protected]
    link
    fedilink
    English
    557 months ago

    Yeah manufacturers are getting out of hand with this kind of shit.

    Machines are being made now to be unserviceable except with the manufacturer attending.

      • @[email protected]
        link
        fedilink
        English
        47 months ago

        Yeah and pay their techs pretty average too. At least who i work for does.

        But get to be at the forfront of technology

  • Queen HawlSera
    link
    fedilink
    English
    507 months ago

    Sounds so legal that I’m sure its a plotpoint in a The Boys episode

  • @[email protected]
    link
    fedilink
    English
    35
    edit-2
    7 months ago

    The trains also had a GSM telemetry unit that was broadcasting lock conditions, and in some cases appeared to be able to lock the train remotely.

    So, it sounds like this remote lock is speculation, so I’m not gonna say that this is actually the case here, and I don’t know how trustworthy the source here is.

    But, speaking in general: an additional problem with sticking back doors in products is that someone else may discover them and exploit them, and the uses to which they may put them may be considerably less-pleasant than whatever the purpose that the manufacturer had in sticking them in.

    Just earlier this year, we had articles about this incident with Polish trains. That wasn’t a back door in that it wasn’t particularly hidden, but it was a way to do remote radio control of Polish trains, and sure enough, when someone who wanted to create trouble with it discovered it, it got used to cause problems for Polish train operators.

    https://www.wired.com/story/poland-train-radio-stop-attack/

    The Cheap Radio Hack That Disrupted Poland’s Railway System

    The sabotage of more than 20 trains in Poland by apparent supporters of Russia was carried out with a simple “radio-stop” command anyone could broadcast with $30 in equipment.

    • @[email protected]
      link
      fedilink
      English
      42
      edit-2
      7 months ago

      It wasn’t a back door, it was a safety feature working as designed. IIRC it didn’t have any modern security implemented, because it’s very old.

      Also, the link from the OP doesn’t mention that, but the trains in this story had locations of competitors’ repair centers coded in, and were apparently set to auto-lock if they detected sitting in one for more than 10 days…

      • chaogomu
        link
        fedilink
        167 months ago

        So, locking out repairs for anything they would have to order parts for.

        I’m guessing that they’re using some sort of custom size for their bolts and tolerances in the train. The competitors likely have the standard sizing for parts on hand, and any custom part would need to be ordered in. Likely from the same supplier.

        Since they know their supplier’s order return timing, they can set up the kill switch when they know that the train will be sitting in a yard awaiting parts.

        Scummy as fuck.

        • @[email protected]
          link
          fedilink
          English
          23
          edit-2
          7 months ago

          it worked like this: public tenders for trains and its servicing are separate. at first, newag claimed that service documentation is their super secret IP and they can’t disclose it. european railway authority however basically said that no, fuck you, you as a manufacturer have to disclose it. so they did, it’s a 20k page thick book, and now other workshops (with all certs and so on) can compete in tender. while monopoly lasted, they could call whatever price they wanted and operators would pay anyway. smaller workshops just outcompeted them because they don’t have dozen c-suite to pay

          newag of course didn’t like it and there comes the fuckery. what they did, among others, is they put logic that would prevent DC-AC converters from turning on if train spends 10d+ in one of hardcoded areas, these places being competing workshops. another mysterious thing was gsm modem that could (possibly) brick train remotely in the same way. later corporate would just claim that no one else can fix these trains, call competition unqualified, and grab severely overpriced servicing contracts. that is, until somebody actually looked inside. mechanically and electrically train was fully working, but it was just locked by software

          i guess this will make some national and european regulators and agencies verry interested. here you have more technical details (article in polish) https://zaufanatrzeciastrona.pl/post/o-trzech-takich-co-zhakowali-prawdziwy-pociag-a-nawet-30-pociagow/ it will be also topic of a talk at 37C3

  • @[email protected]
    link
    fedilink
    English
    17
    edit-2
    7 months ago

    Well I guess in the next tender they will add a paragraph for “No Killswitches allowed”

      • Quokka
        link
        fedilink
        English
        117 months ago

        And the owners/ceo/board/everyone involved to be arrested.

        • lad
          link
          English
          57 months ago

          And then we all wake up and it’s 2007 again

  • BarqsHasBite
    link
    fedilink
    English
    127 months ago

    Newag S.A. [pronounced: nevag] is a Polish company, based in Nowy Sącz, specialising in the production, maintenance, and modernisation of railway rolling stock. The company’s products include the 14WE, 19WE, 35WE types electric multiple units; it has also developed the Nevelo tram.[2]

    • federalreverse-old
      link
      fedilink
      English
      29
      edit-2
      7 months ago

      Somehow this is the worst bit – a Polish company fucks the Polish state railway operator because of greed. If they’d done this in another country, there might have been some international repercussions etc. but they opted to burn their name in their own home country. This being found by random hackers is actually the best way for Newag for this affair to become public. This could have been so much worse.

      • BarqsHasBite
        link
        fedilink
        English
        67 months ago

        Yup instead of the “I guess that third party repair really fucked up huh”

  • sadreality
    link
    fedilink
    10
    edit-2
    7 months ago

    These guys are getting super [brazen]. Is this contract with the Polish state? or private?

      • sadreality
        link
        fedilink
        37 months ago

        Sounds like they need use that big dick energy to set these clowns straight.

        I get they think they can punk peasants… but punking the government now?

        • @[email protected]
          link
          fedilink
          English
          8
          edit-2
          7 months ago

          It’s even smarter to piss your only big customer, namely the polish government off. Something about biting the hand that feeds you

    • @[email protected]
      link
      fedilink
      English
      37 months ago

      every province has their own railway operator, ultimately it’s all paid from state budget