Breaking "DRM" in Polish trains [video]
streaming.media.ccc.de
streaming.media.ccc.de
Polish Hackers that repaired DRM trains threatened by train company - https://news.ycombinator.com/item?id=38628635 - Dec 2023 (142 comments)
Polish train maker denies claims its software bricked competitor rolling stock - https://news.ycombinator.com/item?id=38570654 - Dec 2023 (2 comments)
Dieselgate, but for trains – some heavyweight hardware hacking - https://news.ycombinator.com/item?id=38567687 - Dec 2023 (293 comments)
Polish trains lock up when serviced in third-party workshops - https://news.ycombinator.com/item?id=38530885 - Dec 2023 (360 comments)
For example, if HP programs printers to start failing after N pages printed, would that ever be uncovered?
Is there some kind of whistleblower law that would allow someone with knowledge to come forward?
With most other right-to-repair cases there's way less recourse. With trains in Europe you have legal rules that disallow hiding critical maintenance data behind trade secrets, for example.
My suspicion is that a lot of this happens only 99% of cases never see light of day due to NDA-s and settlements
> Is there some kind of whistleblower law that would allow someone with knowledge to come forward?
Depends on where you live, unfortunately anywhere with 'stong' IP laws you aren't allowed to patch anything. Usually reverse engineering analysis is still fine, although if there is a contract saying you're not allowed to you could be screwed anyway.
In the train case the locks were specifically for anti-competitive purposes, and so they can whistle-blow for that; and I think in the general case you can sue for misleading dealings/false advertising/etc but not for anything specific to the software locks/traps.
I am not aware of any IP laws that prohibit patching, except for circumventing copy protection (DMCA). There are plenty of laws prohibiting distributing patches, but making and using them are not commonly prohibited AFAIK.
However in the EU you aren't allowed to use information obtained through "decompilation" for the purpose development/production of a substantially similar program. Which means you cannot patch any program (exception exists for the purpose of interoperability), without risking some legal liability.
2009/24/EC Article 6 for anyone interested.
It feels that implementation of that system was quite complicated. Complicated enough that quite few people must have been involved in it.
Its quite sad that developers would implement this and all keep their mouth shut.
I think the incentive is money. 1 train is worth much money, a single printer is not. Most people won't have any issue with the printer and if so, loss is low. If just 1 train has this issue, loss might be huge.
The cartridge region is printed per cartridge while printing "print quality" reports which prints full-nozzle lines to see whether there are any persistently clogged nozzles on your printhead.
Also, some poor soul at The Verge went through hell and back to document the fun experience of trying to use an HP printer on a different region: https://www.theverge.com/23648726/hp-officejet-printer-regio...
I can't find it right now, but wasn't there a story some months ago about some printers doing exactly that to make you buy new ink cartridges?
I'm on my 4th HP Inkjet, and none of them did anything remotely similar. One worn down (which was a bottom of the barrel model), the two of them was donated, and AFAIK one is still pretty operational.
I'm regularly using my Deskjet Ink Advantage 4515, which is ~10 years old at this point.
Maybe. The problem with consumer devices is that they're much better protected from their end users, so it's harder to dump the firmware to reverse engineer it. Firmware update files, while you can easily get your hands on them, are usually encrypted. Sometimes it's so bad that the best course of action is to find an RCE vulnerability and exploit it.
Though, with inkjet printers being as popular in some parts of the world as they are for some reason, and being as annoying as they are, I'm surprised no one has done that yet.
Great job guys! We all need a lot more like you.
I worked with PLCs for some time and the whole "a dozen different versions" rings a USBell for me. if I Google newag plc programmer at linkedin, I promise you the number will be the same as the number of versions found in the trains, all branching away from one initial version by one initial programmer.
Ocassionally a fb gets exchanged on a USB stick, but the whole version controller magic never reaches the team.
Does anyone know if there are similar end-of-year roundups that non-cryptologist s can follow to keep up to date?
Two wrongs don't make a right there.
it gets crazier and crazier, holy shit!
A case like this involving a train that wont move is something that's easy to comprehend for the general public and is clearly utter bullshit.
I'm a repair guy and I'm always trying to protect my customers against walled gardens, and what not. Talking about this article makes explaining right repair so much easier.
My concern is the changes they're making to bios in Consumer grade OEM Desktop and Laptops. With adding UEFI certificates to anti-theft software that is enabled by default people just don't understand what's really going on. This article explains it beautifully. Thank you Newtag!
The funny thing is that prime minister of the former idiotic government was aware of that and did nothing. Law and justice mafia party is all about pacts, corruption and theft.