Polish Hackers that repaired DRM trains threatened by train company
404media.co
404media.co
That's extremely evil. I'm not emotionally invested in right-to-repair like many others here are, but it's corrupt that DRM is causing/has caused difficulty in operating things necessary for people's survival. Shame on these companies.
Those who want to convince others of right-to-repair should point to cases like this because it's the #1 thing that makes me want to rally behind it too.
If a person who decides to make pop music can DRM their work, why shouldn't a person who goes into life saving tech DRM theirs? "think of the children!" Hey, if you care so much about the children, pay your bills. Covid caused unforseen problems? you know what? they were unforeseen.
The person who created the life saving tech already saved a bunch of lives, those lives are still saved, and it seems a little ungrateful to claim they haven't done enough for you.
and btw, what you said is completely obvious to the point of dreary cliche, "things more important than the bottom line", like Phoebe's realization on Friends that she and her mother had a lot in common because turns out they both love pizza and puppies.
What I said was food for thought and unexpectedly (in an inside out sort of way) explanatory toward the question asked by the comment I was replying to.
maybe you could stop stopping and smelling the flowers on the road less taken for a minute and consider ideas with depth, it might make all the difference.
I think you point to a real conflict of interests though where some may feel less motivated to work on life-saving tech if they aren't compensated for it. Here in the UK, the government launched a scheme called "Eat Out to Help Out" to help support businesses like takeaways which had understandably had low revenue during COVID. I would have been happy to see a subsidy (and pay a tax towards it) for companies manufacturing life-saving tech if it was the only sustainable solution.
We live forward in time, not backward.
Also, people know about IP rights. Either it's the law of the land or a treaty obligation. Clearly documented, as are the available remedies in case of dispute. Available to everybody, in theory.
This "DRM" was unilateral. Surreptitious. Why do this if not to remove agency from the client at some later date? Why bypass the legal system? Silently?
Altruism? Maybe, but that's just as bad, idealists and coercion go hand in hand throughout human history.
Pragmatism? Seems more likely. The trains can be fixed, except they get turned off from the mothership whenever they seem to be in the shop. They don't fix them for free, presumably.
Either way, that is some snake ass shit, since it's undocumented. Poor.
https://jalopnik.com/this-dystopian-biker-airbag-crash-vest-...
It's not quite as bad as it sounds - the hack allowed people to buy second hand ventilators and fix them up which I guess is handy in an emergency but could create safety risks if the thing then fails when a patient is relying on it.
Still, to put such restrictions in code and threaten the people who found them with legal action... I'm not even sure how to describe it.
https://www.traple.pl/legalna-dekompilacja-programu-komputer...
Article in polish, but you can auto-translate easily.
The article seems to say the hackers were hired by the maintenance place that the owner of the trains (Lower Silesian Railway) hired.
Newagg is the manufacturer of the trains which were bought, not the owner of them.
If a company hires me to inspect their systems, and it's not shady (i.e. everything seems legitimate), then I'm not hacking anything. It's really no different to working on a CRUD (well, it's more interesting :)).
There might be some legal provisions (DRM laws, some EULA, etc.) that muddy the water. But that doesn't change the fact, that I can't find any ethical problem with what the Dragon Sector folks did[1]. And for me hacking is something unethical--criminal aspect is secondary.
[1] based solely on the articles I read
The ethical distinction is between white hats and black hats. The people in the article are white hats, that is, they work legally, ethically, and they are open about their activities.
Note: I mean hacking as it is most commonly known now. Not MIT-style hacking.
But of course on technical forums like HN we call it hacking ("we" includes myself).
To address some of your points:
> they did something someone attempted to prevent them to do
Well, Newag claims they didn't add any shady stuff to the firmware, i.e. they didn't prevent anyone from anything. Which means Dragon Sector didn't break any protection mechanism, they were just debugging potential glitches! :)
I've debugged a lot of software in my life and no one has ever called me "hacker" for finding that missing CSS class :)).
> Hacking a train so that it accepts third party repairs and hacking a credit card reader to steal your money make use of the same techniques.
This is a very low level discussion ("low level" as in "assembler", and not intellectually, for the lack of a better word), but in this case there's one significant different--train firmware is supposed to be unchanged (according to Dragon Sector).
And credit card reader's fw has been modified.
So for me, again, they acted as forensic investigators/"debuggers".
> The ethical distinction is between white hats and black hats. The people in the article are white hats, that is, they work legally, ethically, and they are open about their activities.
Yes, I agree. But I would still prefer if the non-tech world called them something like "forensic investigators", as white hats are still a kind of hackers.
However, this was a huge step backward. The company bypassed the legal system via code, to add obligations, and secret functionality to the client. How was this found? By others who would and do circumvent the law for their own reasons.
These reasons might be as noble. Just. Enlightened.
Having spent some time online, I of course, am skeptical.
original news story discussion just over a week ago: https://news.ycombinator.com/item?id=38530885
And the followup from the company
Polish train maker denies claims its software bricked competitor rolling stock https://news.ycombinator.com/item?id=38570654
More late quality from 404
Polish train maker denies claims its software bricked competitor rolling stock - https://news.ycombinator.com/item?id=38570654 - Dec 2023 (2 comments)
Dieselgate, but for trains – some heavyweight hardware hacking - https://news.ycombinator.com/item?id=38567687 - Dec 2023 (289 comments)
Polish trains lock up when serviced in third-party workshops - https://news.ycombinator.com/item?id=38530885 - Dec 2023 (357 comments)
I think there may have been others?
https://twitter.com/jciesz/status/1732411016221524070?s=20
translation: > The president of Newag contacted me. He claims that Newag fell victim to cybercriminals and it was not an intentional action by the company. The analysis I saw indicated something else, but for the sake of clarity, I will write about everything.
Contrarily, if they _knew_ about it, and didn't tell anyone, then it's even worse.
The moment I heard about this event, I knew that it was only a matter of time before the offending company executives would be blaming the developers. Interesting that their particular path forward is blaming malicious third party developers because the next thing that happens is someone interviews their devs and finds out that they in fact are the people who put this in. At the behest of middle management who behested at the behest of upper management.
My prediction is that we'll soon be hearing about how upper management would never have told a developer or middle manager to program this in and it's the lower level guys who have gone rogue which is why they blamed cybercriminals.
A lot of philosophy and poetics go into software engineering ethics that I find uncompelling at best. However, the pair of "why would you want to injure someone you don't even know" and "you will be the one blamed" feels to me to cover 95% of what software ethics claims to.
It doesn't make any sense either: "falling victim to cybercriminals" who entered GPS coordinates of all competitors in the code, to make competitors-repaired only trains down - sounds legit! That's exactly what cybercriminals do!
Aint it at least the proof of something shady?
I hate living in (techno)feudalism, I thought we moved past that...
This time around corrupting the national politicians won't cut it to get the contracts — the European regulator is keeping a close eye on this and it's not known for being complacent with attempts to bypass its oversight.
We have barely even started.
wrote an article about why company's line of defence that malicious code could be injected is flawed
https://gynvael.coldwind.pl/?id=777
It is mostly about reverse engineering, compilation process, how thing are laid out in the final binary -.text, .data sections, offsets and stuff like
It'd be nice to imagine that, for large industrial equipment, buyers could squeeze DRM-happy suppliers out of existence. Vs. in reality...
But both national law states it's OK, and there is a ruling by Court of Justice of the European Union stating that Reverse Engineering done by owner even of a program license (EULA style) to make it work or fix errors is legal.
In this meaning, copyright is not the same as authorship rights, which is a basis of intellectual property protection in Europe.
Similarly for software patents, they do not work in EU.
copyright having exceptions does not mean that copyright does not exist
unless you claim that copyright does not exist in USA because they have fair use?
That's why we have the relevant legal act discuss separate aspects of "moral" and "financial" "Author's rights" to a creation, instead of just singular "copyright", and why American-style "public domain" does not exist in Polish legal system, or that of many other EU countries (US' style public-domain involves effectively losing all rights to the creation, including moral ones, whereas those are non-dismissible, non-transferable and permament in Polish law).
The exact way things differ would probably require a philosopher and a lawyer to discuss differences of.
(a) copyright (b) moral rights
which are separate. Maybe it was badly described or I misremember what I learned decade ago.
The first test of an open source license in court was https://en.wikipedia.org/wiki/Jacobsen_v._Katzer. It was initially lost on a somewhat similar argument. Namely that it was a contract, not a copyright license, and then was an unenforceable contract and therefore invalid. This decision was reversed on appeal.
I have no particular reason to believe that the first French judge to rule on an open source license did a better job than the first US judge to do the same. Both ruled against the license.
We also have this right:
The person having a right to use a copy of a computer program shall be entitled, without the authorisation of the rightholder, to observe, study or test the functioning of the program in order to determine the ideas and principles which underlie any element of the program if he does so while performing any of the acts of loading, displaying, running, transmitting or storing the program which he is entitled to do.
Article 5(3) and 6.
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32...
I don't know what other provisions of EU law might apply here. But it is literally the job of the lawyers issuing the threats to find potential gotchas like that. I would assume that they are competent.
you cant call breaking someone elses property a business practice
If the law is huge and complex, and a large company wants to make your life hell...
Reverse Engineering (Decompiling) software that you own to fix errors and allow interoperability is explicitly allowed.
I fear that (allowing for the "someone with enough money and lawyers can make your life hell" effect) you are not.
It is either that or DRM means the OEM gets to remotely shut down entire train network whenever they like? Imagine the money one could make with such a service.
That's bonkers. And criminal.
Neither cares about breaking DRM or IP, but third party (including vendor) manipulation.
For example article 6, part 2 (a) does not allow the information retrieved to be used for any purpose other than establishing interoperability. The hackers stepped over that line when they released some of what they discovered for the purpose of publicly criticizing the manufacturer.
This isn't DRM (though that's bad too). It's far worse. It's ransomware, they hijacked trains. Everyone involved should be locked in a dungeon for the better part of a century.
Newag's revenue is about $300 million. This isn't Siemens.
https://www.traple.pl/legalna-dekompilacja-programu-komputer...
The article is in polish, but auto-translate should do it's job easily.
This is not some david vs goliath thing.
Since then, MRO is purchased through separate tender process - and NEWAG didn't win several times.
> Contracting Parties shall provide adequate legal protection and effective legal remedies against the circumvention of effective technological measures that are used by authors in connection with the exercise of their rights under this Treaty or the Berne Convention and that restrict acts, in respect of their works, which are not authorized by the authors concerned or permitted by law.
(DRM's a silly name, anyway; it should be called "technological measures" or "technological protection measures" or something.)
They might win in the short term but I can't imagine that would serve the train company well in the long term - lawmakers (who are typically octogenarians) often don't understand how software restrictions limit use of equipment traditionally enjoyed under property rights until they're interfered with. Like a train being geofenced.
The manufacturer should be put out of business.
NEWAG executives & those responsible should face criminal charges for conspiracy to defraud in addition to libel.
It's clear that NEWAG knowingly lied about alleged malfeasance from the third party repair shops, and took advantage of their sabotage to incentivize if not require their customer to pay for service at NEWAG's own repair shops.
Seems like a slam dunk public outcry.
https://www.rynek-kolejowy.pl/wiadomosci/hakerzy-odpowiadaja...
Fasten your seatbeats, it seems there's a lot more details this time. For instance, the say they have a before/after Newag service diff of the firmware, and there are interesting changes there.
If that's true, then the "rogue hackers" must be sprinkled inside Newag :).
It was parts of software included by producer to make 3rd party shops look incapable of servicing. Placed there in a sneaky way.
DRM makes it look like official documented tampering prevention - article itself is good. Use of DRM in title and in article is just wrong.
its a bit funny in.this case the company first claims.it doesnt brick stuff, and subsequently threatens these guys.. did they lie first? that seems bordering criminal for a company to do... just admit it :/. 'yes we drm our crap and brick stuff with anti tamper detections'. how hard is it...
hope dragon sector doesnt get into trouble, they do amazing work!
Why buying DRM things in first place?
well, they didn't. No single word in manual about that. Also the locks are illegal vs. EU wide regulation about train maintenance.
Companies bought trains with „full technical documentation and service instructions” - I put it in quotes because all the locks and „DRM” stuff was undocumented and producer is claiming they never put anything like that in the first place.
In what universe this is not sabotage?
[1]: https://en.wikipedia.org/wiki/Spoofing_attack#GNSS_spoofing
[2]: https://www.ainonline.com/aviation-news/air-transport/2023-0...
[3]: https://en.wikipedia.org/wiki/Iran%E2%80%93U.S._RQ-170_incid...
The target doesn't need to be airborne for such an attack to work.
>A "proof-of-concept" attack was successfully performed in June 2013, when the luxury yacht White Rose of Drachs was misdirected with spoofed GPS signals by a group of aerospace engineering students from the Cockrell School of Engineering at the University of Texas in Austin.
I mean, the spoofing signal needs to usually come from sky. You want to hinder the original signal and makes yours stronger. Of course, signal can be reflected and there are other means to reach this.
The GPS system doesn't use the direction to the GPS satellite for localization but rather only the distance i.e. timing, so spoofing GPS is based on accurate control of the time of the transmitted (or replayed!) signals.
GPS uses Signal-to-Noise ratio for determinating the signal quality and integrity. Horizontal signal will suffer pretty fast. Especially if your receiver is sophisticated and could actually detect the signal strength (power) outliers. If you want to spoof GPS signal very well, it should be also weak. But weak signal will quickly disappear with ground-based transmitters.
I used ”strength” incorrectly on the previous comment.
And regarding "If you want to spoof GPS signal very well, it should be also weak" the scenarios I've seen (e.g. targeting drones in current conflicts) often explicitly target non-sophisticated commercial off-shelf GPS modules that don't attempt to detect spoofing and will gladly accept a signal that's 100 times louder than the actual satellites, so I think the spoofers often have no desire to do it "well" according to your criteria.
https://safran-navigation-timing.com/product/skydel-simulati...
Ignoring the lack of disclosure of what should be a selling point and that there hasn't been a case of trains being stolen for later illicit reuse in recent memory.