Polish railway system hacked, trains forced to stop by attackers
twitter.com
twitter.com
It's about as much of a "hack" as calling to your school and saying there's a bomb.
I also left a comment addressing the potential for varied interpretations of hacked.
Most trains have a emergency brake lever inside which is also very easy to abuse, but is there for safety. It is better to enforce harsh penalties for abuse.
Here I don't think that this signal system is designed to be used by the public. I'm guessing that there are transmitters installed and operated by the railways and perhaps police/emergency services but no-one else.
I am sure that the system will now be upgraded to include cryptographic authentication or something to that effect.
Ever walked around in a factory? Those big red mushroom buttons everywhere actually work. Absolutely nothing is going to stop you from hitting one of them. It's not unlike the social contract: the assumption is that you too are kept safe by others.
Abusing such systems is the lowest of the low, and will get you in serious trouble. As would be sabotaging fire fighting equipment, arson, bomb threats, throwing stuff onto the highway and so on. The fact that you can't see any reason means that you are probably not in charge of safety anywhere. The battle is so asymmetrical that you can't win unless people stick to the assumption that their lives are valuable too. If that is no longer the case you are technically at war.
This is why suicide bombers have an easy time of it: they have broken out of that social contract and are willing to give up their own lives to take the lives of others. You simply can not effectively defend against this unless you are willing to throw out the social contract and become a police state yourself (or suffer eventual loss of life).
The minimum level of competence to run an important system (to put a train in motion, for instance) is definitely there. But to stop an important system should need no competence, it should just require presence and action. Any other requirements are not going to be secure (because too many people need to have access to such systems, including all of the public) but will cause the critical part to fail just when it is needed.
Here we're discussing a radio transmission (from what I understand) in the wild that can come from absolutely anyone and anywhere and stop a whole train. There is no reason for this not to be secured.
I didn't claim that there should be a special competence to remotely stop a train, and indeed we may want something as simple as a big red button. But not anyone should be able to push that button and there should obviously be competence to run the system behind the scene as per my previous comment.
Factory workers are not vetted beyond being able to perform some function on behalf of the factory owners / operators. That can be as much as having finished grade school. On your first day you have the run of the place.
> Here we're discussing a radio transmission (from what I understand) in the wild that can come from absolutely anyone and anywhere and stop a whole train.
Oh no! Such radio transmissions have been the norm for decades and plenty of such older systems are still in use all over the world. Abusing such systems is easy. Upgrading them properly is costly and carries risk so the default is to leave things as they are.
> There is no reason for this not to be secured.
Well, why don't you propose a system that is 'secured'? And then I'll show you fifty ways in which your so called secured system can be 'hacked'. For instance, pre-emptively by stealing some of the gear.
There are fall-backs for all of those and the final fall back is flares and hand signals which every railway man hopes to never see in their lives. Fucking with infra is easy. Creating systems that are still just as safe but that are secure isn't easy at all: it is impossible. As every hacked website proves. And even if you could: the next thing that would happen is that these jerks would derail the trains instead of stopping them because that too is stupidly easy.
At some point we all rely on each other not to do bad stuff.
At least here there was no catastrophe but still enough noise at a sensitive enough time that, again, I am sure that those systems will be upgraded.
Also, we're discussing securing infrastructure against threats up to state actors. They don't care about harsh penalties unless these are painful counter-attacks.
What will most likely happen is that we will see more such acts of sabotage, against these and other systems.
Some suspects (Polish nationals) have been arrested:
https://www.i24news.tv/en/news/international/europe/16931682...
Defilibrators, strategically positioned at places where a lot of people congregate. Such as train stations or city centers.
Herearound those are not locked. There's nothing stopping you of taking it out and toss it into the river.
The social contract is such that you just don't fucking do it and frankly, I never heard of such a thing happening. And yes, we have our shares of assholes.
Contrast that to the UK, where they are under lock and code. You call an operator explaining the emergency and she may unlock it.
There are two problems that I can see (and probably more). The communication device adds another layer of potential failure. And those two minutes it takes to unlock the device may be the difference between life and death.
I, for one, know in which kind of society I prefer to live. Even given the very occasional asshole who breaks that contract and abuses the accessibility of that life saving device.
Some people will die, but if that happens again there's not much choice.
>Because it isn't possible to make a system both easy to access and secure at the same time
Not right now, but since 2009 we're implementing GSM-R, and we still don't have it. It's not a bad solution, but nobody really cared until the recent abuse happened.
Source: I was sitting opposite a family whose small child activated the emergency stop. The train didn't stop.
On the tube, where (aside from a handful of long distance expresses e.g. to/from Amersham) your train is going to stop at a station anyway in the next couple of minutes they have notices explaining to people that the best way to get e.g. medical assistance is going to be to get off the train at a station, where they can help you, not stay on it and push the emergency button hoping somehow assistance magically teleports to a moving train.
And tbh, I just can’t see which sort of emergency can happen inside the train that would require an immediate full stop. Even if something life threatening is happening inside, the best option is to call and meet the emergency services in the next station.
Trains are multiple vehicles that are somewhat loosely connected. A train segment could be detached from the rest of the train.
https://abcnews.go.com/US/amtrak-cars-separate-boston-bound-...
And other mechanical issues with the train besides (for instance: the train being on fire).
The fact that you can't think of something doesn't mean that you have done an exhaustive search.
Trains are fail-safe. They only run because the brakes are held open by a pressured air system running along the whole train. In case of a detachment, the hose connecting the wagons would break, releasing the air pressure and thus slamming the brakes down.
The Eschede crash in Germany: https://en.m.wikipedia.org/wiki/Eschede_train_disaster -- part of the wheel came through the floor into the passenger compartment. The passenger couldn't find an emergency stop, and by the time they'd found a conductor and got their attention (which took minutes) the train crashed.
Trap-and-drag accidents where somebody on the platform gets clothes trapped in the train door and is pulled along with the train as it starts to pull off. If you don't emergency-stop the train within seconds that person is likely to suffer serious injuries or die. Likely the conductor/guard isn't near that door and only passengers will have seen the problem.
/s
Whatever happened to personal responsibility? Hackers without ethics (no matter whether acting on their own or for some larger entity) are less than useless.
Please don't spread this "white hat hacker" extortion mindset to my neighbourhoods.
I don't even lock my door.
Thank you.
Personally I've had it with the so called 'hackers'. They're just criminals. Oh and I think you meant to write 'lock' not 'look'.
Such people have no place in society and setting them loose on neighboring countries is inviting a tit-for-tat that we can all do without. Personally I think these attacks are very close to - or already over the threshold for - acts of war.
That’s false, at least on modern trains, in France, for what I know.
Any modern train will not stop when you pull the alarm lever.
The first thing that will happen is that you will be in communication with the conductor, then the train will be stopped in only two scenarios : either you are communicating a real emergency or you don’t respond at all to the conductor asking you what happens after a given delay (which IIRC is 10 seconds).
And fwiw, a friend of mine who is conductor explained to me that if you activate the alarm lever by inadvertence, the worst thing you can do is to not answer by fear of having problems. If you say it’s an error, the conductor will just ignore it and continue its day while if you say nothing, the conductor is forced to emergency brake the train and all the trains on the line.
This is to ensure that if the driver / conductor is incapacitated the train will still come to a halt. And that in turn is because runaway trains have happened.
For logner tunnels etc there is an override, where emergency break doesn't break immediately as stopping a train mid-tunnel is most of the time the worst choice. Smoke in tunnel is dangerous. Emergency help can't reach it. Evacuation has confined space. etc. There emergency break rings an alarm with the engineer. If they ignore it, it will stop after a while, but usually they will use intercomm to understand the reason.
A way however you can stop trains on a German train line is by putting a 2kHz electromagnet on the tracks. That will tell the train that it just crossed a red signal and will stop.
Crusade against Wikipedia that the information is stupendously risky if you think that's a good use of your time.
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L...
(p. L 342/109-110, or ^F RADIOSTOP)
This is Official Journal, available in all EU languages (at the time).
Also the risk is .... not existent. To damage railway infrastructure there are way more efficient and simple ways (getting a rail to derail, destroy some signaling cables, ...)
The "attack" here would require quite some investment in equipment (power etc.) and only bring a single train to a realtively quick stop, well in safe margins, where the driver after a quick check with the dispatcher can override and continue the ride, while investigators would collect the equipment.
It's impractical for a stunt (way simpler and more effective: just walk close to the tracks and they will do emergency stops for all trains close by) and ineffective for an attack.
That it's easy to hack makes no difference.
> The saboteurs reportedly interspersed the commands they used to stop the trains with the Russian national anthem and parts of a speech by Russian president Vladimir Putin.
> The only real limitation of the train-paralyzing radio attack, Olejnik says, would be that the saboteurs would have to be relatively close to the target trains—somewhere from hundreds of feet to miles, depending on the power of the radio equipment used in their disruption operation. [...] Given that the disruptions appear to have occurred in three different Polish administrative regions across the country, getting that equipment close enough to all the target trains would likely have been the biggest challenge for the saboteurs.
So it was a coordinated attack. This could really turn into a DoS vector against the railway system - if I extrapolate from Germany there should be enough Z-Zombies in Poland that it's a real danger. If it isn't even done by FSB or GRU but considering that all you need an antenna, a USB-SDR? and a notebook this could get really ugly.
But sadly the hack was merely an emergency stop signal. It sounds like it's about as much a hack as pulling the emergency brake.
Knowing German "digitalisation", the train system probably runs on pen, paper, letters, phone calls and faxes, making it resilient to cyber attacks. Your move hackers!
Even if they could hack into the system, I don't think they can do miracles.
In this case: the data is the same for large swaths of the former USSR so it isn't strange at all that an enemy actor has access to that information. Poland could do the exact same thing to Russia. But I hope they have better ethics.
So it's not just calling a school saying there's a bomb, but using the info about the right frequency and signal pattern triggering remotely all alarms in neighborhood.
[0]: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... (via niebezpiecznik.pl)
BTW, it's good that attention is being called to it. There is a bit of tension in the region, as you may know, and opponents are not going to play nice. That also makes me suspect this was not a malicious attack.
Poland is apparently in the process of purchasing and installing GSM-R, which is basically like old mobile phone (cellular radio) technology but specifically for Railways. Although GSM's security is hardly state of the art it would definitely be reasonable to call that "verification" if they had it. The "easy" way for lay people to send such a message under GSM-R would be to obtain a real transmitter, maybe steal one.
Presumably since they're buying GSM-R they currently have either an ad hoc secure system or they don't have a secure system at all and so in the latter case yes there would be no verification.
Now it is much more of a blanket term for near-anything
But that doesn't mean that you are smart, it just means that as an attacker you have it easy. Electrical infrastructure, water, gas, telecommunications, railways and so on are all wide open to abuse and sabotage. Doing so however is in my opinion about as close as an act of war as you can get if you do it from another country and should net you a decade or more in jail if not. It's also supremely cowardly, not unlike calling in a bomb threat on an airport. Assholes will be assholes.
By the time you've done that the accident has already happened.
Exactly, see what I said above
>not necessarily a security breach
So in short, a security breach CAN be hacking (sometimes it’s not like mitm etc.), but every hacking is not a security breach. Say I used a company server to propagate another attack, that might be hacking by definition, but hacking a toaster with some rubber band to do X is definitely not a security breach.
Problem is its a simple signal consisting of three standard https://en.wikipedia.org/wiki/Selcall tones. Its same as https://www.dallasnews.com/news/politics/2017/04/12/dallas-s...
Solution is adoption of https://en.wikipedia.org/wiki/GSM-R