In one of the coolest and more outrageous repair stories in quite some time, three white-hat hackers helped a regional rail company in southwest Poland unbrick a train that had been artificially rendered inoperable by the train’s manufacturer after an independent maintenance company worked on it. The train’s manufacturer is now threatening to sue the hackers who were hired by the independent repair company to fix it.

After breaking trains simply because an independent repair shop had worked on them, NEWAG is now demanding that trains fixed by hackers be removed from service.

  • duncesplayed@lemmy.one
    link
    fedilink
    English
    arrow-up
    9
    ·
    7 months ago

    Holy shit. If I understand correctly, the trains were programmed to use their GPS sensors to detect if they were ever physically moved to an independent repair shop. If they detected that they were at an independent repair shop, they were programmed to lock themselves and give strange and nonsensical error codes. Typing in an unlock code at the engineer’s console would allow the trains to start working normally again.

    If there were a corporation-sized mirror, I don’t know how NEWAG could look at itself in it.

    • Malgas@beehaw.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 months ago

      “Train pirate” has got to be one of the steampunkiest job titles I’ve ever heard.

  • onlinepersona@programming.dev
    link
    fedilink
    English
    arrow-up
    6
    ·
    7 months ago

    The government better sue the train manufacturer and protect these hackers. The hackers saved the state millions - possibly hundreds of millions.

  • Moonrise2473@feddit.it
    link
    fedilink
    arrow-up
    5
    ·
    7 months ago

    “The president of Newag contacted me,” Cieszyński wrote. "He claims that Newag fell victim to cybercriminals and it was not an intentional action by the company

    Yes, those cybercriminals that once infiltrated in a business network, instead of stealing data or holding ransoms, hide multiple iterations in the code of a snippet that only benefits the corp. Sure, they exist

  • Blizzard@lemmy.zip
    cake
    link
    fedilink
    English
    arrow-up
    3
    ·
    7 months ago

    I wonder if they’ll be able to overclock those trains or install some mods.

  • kingthrillgore@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    7 months ago

    It would be interesting to see if Alstom, Hyundai Rotem, and Stadler Rail are doing the same. They are sitting on billions in public sector contracts.

  • WashedOver@lemmy.ca
    link
    fedilink
    arrow-up
    1
    ·
    7 months ago

    I wonder if they were taking notes from John Deere and the automotive industry or will it be the reverse here soon?

    Just imagine all these vehicles that could be bricked for not going back to the stealerships for outrageous prices on parts and incompetent service.

    Also the vehicles that could be disabled for not paying for device protection plan that allows your vehicle to operate safely. It would be a shame if your vehicle stopped working on your way to work or the hospital.

    I suspect Tesla, BMW, and John Deere are the closest to this reality.

    I sure hope the government doesn’t help with another great cash for clunkers national program to get rid of more cars too old for these measures. Sure is a great way to drive new car sales though…

  • davel@lemmy.ml
    cake
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    3
    ·
    7 months ago

    The European Union is an antidemocratic corporate cartel.

    • Quacksalber@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      7 months ago

      The EU is in a constant struggle for its direction. Discounting it as a lost cause only allows malicious actors free reign. On the one hand, EU regulators take on tech monopolies, like forcing Microsoft to un-bundle Windows and Edge/Bing. And european courts have repeatedly struck down legislation that would allow for indiscriminate data retention.
      On the other hand, the EU politicians are currently trying to sneak through a law that would force browsers to accept state-issued root certificates, allowing them to spy on and alter any and all internet communication, basically upending the trust-based system that keeps the internet secure currently. This law is part of the eIDAS initiative.
      And I’m sure that with the new, EU-driven right to repair initiative, the train manufacturer will be forced to back down soon too.