They have not been trained for this
ccc.de
ccc.de
What Newag is doing here is absolutely vile. They want to charge 20.000€ per train to “reactivate” them after they have been serviced at third party workshops. We must not let them win and set a precedent.
I highly encourage everyone to watch the previous presentation: https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_tra...
If companies that did this got jailbroken and blacklisted by the government, pretty much nobody would try this bullshit.
On the flip side, it can often be the only option for businesses that need equipment. The US has a longstanding trend of hacking John Deere tractors to accept third-party servicing since John Deere's first-party offerings are both expensive and often unavailable.
And getting sued by a train manifacturer is typically a asymmetrical battle for a private person. Consider watching the original talk (very entertaining and insightful, probably one of the best hacking related videos I watched in 2024), and if you like them toss them a tenner or so.
When you intentionally design systems with purpose to delay, but overall sabotage, you show malice and you defraud the purchaser (after-the-fact), you also interfere with their business with third-parties, and impose coercive costs that have never been acceptable.
Coercion is generally not accepted by any civilized society that still follow its original founding principles, and coercion and corruption tend to go hand-in-hand.
Apparently its a critical component.
IBAN: DE41 2001 0020 0599 0902 01
BIC: PBNKDEFFXXX
Purpose: Lokomotive
Payee: CCC eV
I spent almost an hour trying to jump through the fiery, spinning hoops being dangled by my bank website only to finally at the end be given an "It looks like this part of our site isn't working. Please try again later."
Thank you, bank /s
For anyone else wanting to try their hand and weather the gauntlet, I found slightly more detail of their published bank acct info at: https://www.ccc.de/en/membership
and an official, physical address over at: https://www.ccc.de/en/imprint
If you're trying to send from America, it's still the normal way to send a payment to Europe so see how your bank sends international payments.
It should be as easy as possible to donate, imo it would be better even setting up a basic kofi or buy me a coffee account, or I see the Ukrainians using paypal all the time.
It should be a 3 click payment not a bank transfer requiring copying and pasting IBAN numbers and bank account numbers etc
To poke fun at the Germans at least they are not requesting we fax a copy of the money in :P
That... is what SEPA is, but built into the european banking system directly.
> I think he's right that if you are relying on IBAN and needing to do an individual bank transfer then it's not ideal.
It's not ideal that you can do a simple transfer by inputting the recipient's IBAN and an amount and be done with literally no third party involved? What?
> imo it would be better even setting up a basic kofi or buy me a coffee account, or I see the Ukrainians using paypal all the time.
You think it's easier to require setting up a third party account, adding your card to it, getting the card authorised, and doing the payment that way, with fees.
Than putting 20 digits in your own bank's application and pressing "send"?
> It should be a 3 click payment not a bank transfer requiring copying and pasting IBAN numbers and bank account numbers etc
It's a SEPA transfer, it's super common and nothing very complicated. There is no bank account number involved: the BIC is the bank's own identifier, and while it was commonly required 10 years ago it's been optional for a long time, my bank's application doesn't even have a field for that anymore.
There's a standard format for qrcode SEPA called EPC (https://en.wikipedia.org/wiki/EPC_QR_code), however the amount is fixed which is not always desirable e.g.
- qrcode for a 133.70€ donation https://epc-qr.eu/?bname=CCC%20eV&iban=DE41%202001%200020%20...
- qrcode for a 13.30€ donation https://epc-qr.eu/?bname=CCC%20eV&iban=DE41%202001%200020%20...
> Than putting 20 digits in your own bank's application and pressing "send"?
Posting from U.S. (and admittedly a very U.S.-centric response), but in the case of Venmo/Paypal/buymeacoffee/Patreon/gofundme, yes.
I spent another half-hour trying to go the route of Wise suggested by a sibling comment but got stuck in the KYC hurdles. I already sent them my I.D. several times, but the selfie-verification flow won't complete for me, and I'm drawing the line at choosing not to install their app. (And well, I bit the bullet and installed app. It refuses to take a clear selfie, no matter how clear the the preview is /shrug)
Yes if you're trying to use SEPA from the US I can see that, no issue there.
But from the perspective of a very euro/german centric CCC[0], SEPA is really not complicated, and almost certainly free (I understand that a few banks still charge for those but most don't, possibly to a limit). So that's likely a blind spot of theirs: SEPA is probably the cheapest and most straightforward method for 95% of their donations or more.
Even more so as this is the central organisation, but the CCC is mostly a network of local clubs[1], so revenue to the national CCC is I assume almost entirely from the clubs shunting some of their income up
[0] if you check their front page, 1/2 to 2/3 the posts are in german, so are several of the pages
I don't see why you'd need Wise for a one-off payment. Just go to the international transfer page at your bank and enter the details? Do they not have one?
I believe this is par for the course for US banking and why so many alternate payment systems exist. And in all fairness, it does very much remind me of european banking 15-20 years ago, before the spread of smartphones and banks getting on with the program and making SEPA a (and later EPC) a baseline feature, undoubtedly prodded on by member states.
And I can understand having to translate from SEPA to SWIFT and then needing to deal with that to be less than ideal. When I had to send money to a friend outside the EU I had to go through the bank's website (not available at all from the mobile application) and to register & wait for validation of their account as beneficiary (24h delay IIRC).
At the same bank, SEPA transfers is a button on the home screen of the mobile application, and doesn't require any setup, just input the IBAN or scan the EPC and go (and god would I like more businesses to accept SEPA / use EPC instead of requiring inputting my credit card every time or going through third party payment providers)
- You don't have to setup an account
- You don't have to get the card authorised (I don't know what this means)
- Adding your card numbers in takes me 10 seconds, in the case of Paypal, it's already there so no time
- Fee's are minimal, not even worth wondering about
In terms of donation, entering in the amount to donate and clicking submit is yes, easier than going into my bank's website, bringing up the international transfer, and it's asking me for SMS confirmation that I want to do this, and I can't be bothered going further.
edit: I think maybe we are fighting the wrong battle.
You think IBAN is super easy, and maybe in Europe it is.
I'm not in Europe though and neither is the other chap, so maybe the donations are very easy in Europe but not so much out of it.
I've never done an IBAN payment in my life but I've donated thousands and thousands of dollars to loads of places all over the world without issue for years including Ukraine, this is the first time I've seen a place only accepting an IBAN donation, which feels like a friction that is not there for other places.
This feels like an "American discovering the outside world for the first time and discovering that American systems aren't very good" moment.
What I meant is that in BLIK, phone number gets resolved to a bank account number and a regular (express) transfer gets made, which can be seen in your account history.
It’s not; SWIFT is, and that requires additional information not shown there (although some of it is encoded in the IBAN if you know how to decode it).
Do you see the rest of the world complaining when no-one can send free uncomplicated transfers to fund a U.S. non-profit because the U.S.A. prefers to run a draconian consumer banking system?
The shier American arrogance in this comment thread gives me an aneurism. Fix your banking system, ours works.
i wanted to leave some breadcrumbs for anyone else in a similar situation (that is, trying to donate from U.S., not the bit about wealth) trying to figure out how to make it work, because i sure expended some effort digging it up.
this specific discussion thread is a call to donate and to write here in solidarity in having done so. i may not have successfully donated cold, hard cash, but i'll dare say my pledge of most of my afternoon trying to move mountains in order to send some scratch their way fits in here. it may have barely registered as a drop in the bucket had i been successful, but i believe this is what the thread is about.
Okay, but surely you can appreciate that making it easier for Europeans and non-Europeans to contribute to this cause would achieve the goal of the donation campaign more efficiently?
My personal opinion is that it would be very much worth it to accept payments via PayPal, Stripe, or other global electronic payment methods[^1]. And show how much money has been received to date.
I would rant about being content with “it works for us, people will donate if they really want to” but I’ve already done that too many times this year.
^1: yes there are some fees associated with this. But it’s also more convenient and probably more people would donate. But for some people the convenience argument does not compute.
As a Belgian (EU), I love how I can pay them just by sending them money, without all these weird intermediate companies stealing your personal details and sometimes even your money.
To answer some contras:
In my experience, the process takes about 10 seconds before the payment confirmation appears in the destination bank. Outside business hours and for some bank combinations, the actual money might be in a reservation/underway/unspendable state until the next business day starts. You can not cancel the transfer once it's gone, so most businesses don't care about that delay.
Typing the IBAN is a tiny bit annoying. I see QR codes appearing, containing bic+iban+amount+message to autofill. You pay by scanning the QR code and pressing OK.
AFAIK bic+iban+amount+message is all you need to pay from anywhere in the world. The BIC can be derived from the IBAN if you have the right and up to date database, but outside the EU it is smart to know it, just to be sure.
Sometimes, reading HN, I wonder if I should write a loooong blog post about how Belgium does its money transfers(iban) and buys bread (Bancontact). I suspect most of the EU will answer: duh, boring! Meanwhile, the average USAian brain goes poof.
According to the schedule [1], there's a presentation from that team titled "We've not been trained for this: life after the Newag DRM disclosure" that will start at 23:00 local time (in about 30 minutes at the time of this writing) on this livestream [2].
Edit: presentation's over and it was outstanding.
[1] https://events.ccc.de/congress/2024/hub/en/event/we-ve-not-b...
The "...Derail" portion of the slogan references Newag's handout shown a few seconds earlier in the presentation.
Lessons learned?
Lawsuits are temporary, glory is forever.
Go public.You do NOT fuck with the safety system.
Sure, it's not the mission critical safety system and you're only reading it, so what's the harm? Well, one of these days someone doing that is going to typo == into a =, or whatever the PLC version of one-character oopsie is.
To be clear, the law changes over time, so newer laws have less precedence, and I expect courts to respect new laws even though no courts have made ruling based on such a law before.
When electric scooters were reclassified as «small electric vehicles» they suddenly came under the same drunk drive laws as motorbikes and cars. So the lower courts ruled a bunch of drunk driving of electric scooters as severely as they would drunk driving of a 2000 kg car that can go 200 km/h. Essentially they just followed the precedence of previous rulings on drunk driving without taking into consideration the intent of the law. People got huge fines and lost their car licenses for several months on the assumption that if they were careless enough to drink and drive an electric scooter they would be just as likely to drink and drive their car.
Eventually a case went all the way to the Supreme Court where they actually thought it through and and decided that there wasn’t any reason to assume that a person would drink and drive a car just because they did so with an electric scooter.
If that's regulation, yes please.
It is, and as much as we all want to pretend this is always about rent seeking.
There can be other reasons.
Some systems are bought in manners that include service contracts and outs liability on manufacturers. In such scenarios one man's kill switch could be a safety feature.
You don't want unauthorized personel messing about a medical x-ray device. Because (a) you want it to work, (b) there might be 10k+ volts sitting in giant capacitors.
I'm guessing it's similar with airplanes.
---
In complex enterprise systems, right to repair might not always be simple.
But if it comes to your home appliances, a tractor, car, etc. I'd be a lot less worried.
John Deere is proof that the manufacturer alone can't be trusted because they can't provide timely service in a time-critical industry.
If copyright is the root of the problem, it may be time to remove that protection; or at least revert it so it is more in-line with patent law expiration.
No more author's life + 75. Lets try 15-20 once again, and no derivative protection, unless significantly different, receive protection.
Software should require disclosure of details of what is protected (e.g. the source) so it can be public used post expiry - just as patents give you a monopoly only what is disclosed in the patent.
I'd add that functionally dependent software that is used for the items primary purpose, or its features, should also receive little to no protection, and be disclosed up-front.
You own the things that you buy.
Most things have the same (too long for anything) life + 70.
There is a bad edit in my comment. One item was supposed to go in a second para about the same regarding patents...
One typical effect of increasing any kind of regulation is that large incumbents tend to benefit disproportionately compared to small operators and newcomers, for several reasons: (1) larger operations can amortise compliance costs more easily; (2) larger operations legitimately contain people with useful expertise in helping government decide the shape of the regulations (and will propose kinds of regulation that correspond as far as possible to their own existing practices, and to practices that competitors would find costly to implement); (3) larger operations have the wherewithal to lobby for regulations that are to their benefit and to competitors' detriment, irrespective of how good those regulations are for other stakeholders. (2) and (3) together lead towards regulatory capture, at which point the regulations are almost purely a drain on all other participants with no upside.
What we want is results. Whatever mechanism is most efficient at producing those results should be used.
> Copyright is the root of the problem.
If you sell me a device that relies on copyrighted software for operation then you must also grant me a limited non-transferable license tied to that specific device to modify that software however I please. Perhaps DMCAs anti tampering provisions are really the issue here.
I think so, yeah. But IMO even copyright as a whole brings more problems than it solves nowadays.
"We", the totally homogeneous group of software professionals could make this stop. "We" don't.
When it comes to something like a "remote kill switch" for software, it's hard to imagine any alternate beneficial use. But generally I assign the blame to the users of software who put it to a malicious use, not to authors.
The obvious alternate beneficial use is the ability to immediately disable the hardware in case a serious safety issue (the kind that triggers product recall) is discovered.
They didn't tell her the planes were elongated spherical and filled with powerful explosives and the runways weren't flat - at least not before the plane landed on them.
This is one of the best parts: many software people have gotten in through circuitous routes, have no formal training, and have done great things despite that.
On the other hand, because of that, we don't have any consensus and ability to shun or disposess companies that act unethically.
Quite frankly, I don't think any board of ethics would step in here. I don't see anything in the IEEE code of ethics that would be clear here. I don't think that professional licensing or better professional organizations are the way to stop this behavior.
And making a Professional Engineer sign on to the software release before the release would be a good way to prevent shit like this.
It wasn't just a faceless and nameless software engineer it was a real human being with a name.
Until it is mandated that public infrastructure is developed in the open so we know precisely who attempts to add features to render a product defective by design we will not be able to fix this.
If Technical folk are not on the Boards or have controlling share in an org, or don't know how to get into such positions then they have very little to no say in how anything works.
There are countless examples were technical people object and get replaced, sidelined or fired, cuz they are totally unprepared in how to win such age old political and financial fights. If Oppenheimer, Engelbart and the Google brainiacs who protested recently got pushed aside, then its beyond obvious how the story will end for anyone else.
The lesson from history for anyone serious about this stuff is - develop business+finance acumen, or develop alliances with business+finance power.
https://transinfo-pl.translate.goog/inforail/jest-wniosek-o-...
It’s a shame they are being sued.
Hopefully, they raise enough to do painful and invasive discovery.
Attacking trains, even the ones you manufactured is an attack on nationally crucial infrastructure.
Because what Newag is doing very clearly violates it.
https://news.ycombinator.com/item?id=38530885
https://news.ycombinator.com/item?id=38567687
https://news.ycombinator.com/item?id=38628635
https://news.ycombinator.com/item?id=38788360
& more
Manufacturer's Repair DRM Killed Train's Power, Broke Compressor - https://news.ycombinator.com/item?id=38893116 - Jan 2024 (2 comments)
Breaking "DRM" in Polish trains [video] - https://news.ycombinator.com/item?id=38788360 - Dec 2023 (51 comments)
Polish DRMed trains stop as predicted due to date-based logic-bomb - https://news.ycombinator.com/item?id=38729035 - Dec 2023 (103 comments)
Trains were designed to break down after third-party repairs, hackers find - https://news.ycombinator.com/item?id=38638865 - Dec 2023 (233 comments)
Polish Hackers that repaired DRM trains threatened by train company - https://news.ycombinator.com/item?id=38628635 - Dec 2023 (142 comments)
Polish train maker denies claims its software bricked competitor rolling stock - https://news.ycombinator.com/item?id=38570654 - Dec 2023 (2 comments)
Dieselgate, but for trains – some heavyweight hardware hacking - https://news.ycombinator.com/item?id=38567687 - Dec 2023 (293 comments)
Polish trains lock up when serviced in third-party workshops - https://news.ycombinator.com/item?id=38530885 - Dec 2023 (360 comments)
Unrelated but is this macro available to others, or just mods? I tried searching the webs for it but found nothing.
here's more of an explanation if curious: https://news.ycombinator.com/item?id=40564558
There is a lot of anxiety around the business model because a lot of the world is advancing and manufacturers are popping up everywhere with cheaper machines on offer. The moats are disappearing and durable goods manufacturers are clamoring for the next wave in the business model: subscription services for maintenance and support.
Ford has a connected fleet service offering that is picking up steam and could prove very lucrative in the commercial vehicle space.
A lot of this is rooted in an eroding labor pool that is lacking in bodies, training and experience.
This train fiasco is definitely bordering on criminal but it isn't far off from the wave of "progress" that is taking place.
Not that I want to tell the Polish how to do things (I don't), but a satisfying outcome would be one where they found out precisely who gave the order to program Newag trains like that and then jail them. Add to their jailtime for each train that is found running the software and force Newag to do free maintenance on those trains.
If Poland wants to show a hard stance on how to deal with people trying to fuck over the public to earn money that's as good as its gonna get. If Poland wants to tell everybody that fucking the polish public pays off even if there is overwhelming evidence that you did it — ok.
"Wouldn't it be a shame if the trains filled with perishable food stuffs stopped working in route..., and the harvests rot"
Do you know of any country where food security doesn't impact the government's ability to keep order?
If any non-service operator, did this, like a third-party, they would reasonably be considered a terrorist organization, and the members of such a cohort should be treated as such.
Even if the claim is made its only for small specific things which you had to agree to, its an inserted vulnerability into the supply chain that is both non-essential for regular function, which has been designed to be essential.
At a bare minimum, they pave the way for such groups even if they don't act on it themselves.
> The Sejm's [Sejm is "the lower house of the bicameral parliament of Poland"] Parliamentary Committee for Combating Transport Exclusion subsequently convened three hearings regarding the abovementioned allegations on 17 January, 27 February and 26 March 2024, whose participants included representatives of the Dragon Sector team, Newag, railway operators and members of the Sejm.[19]
https://en.wikipedia.org/wiki/Newag#2023_revelation_of_softw...
I could not find any later updates in polish media.
https://kolejowyportal.pl/dragon-sector-newag-wprowadza-opin...
You can lead a horse to water...
Genuine question.
its time we repealed it all. no one gets to own an idea of the universe. especially not a faceless org created for tax purposes.
Seems like they are taking a stance against crypto? Why else not use this perfect new decentralized medium for financial support?
That is one sure way to make people not donate to the cause. I want to support the people, but I don't want my money to go elsewhere, and there is no way of knowing how much has been raised to date or guarantees to get the funds back when the legal costs eventually get covered by Newag. The only guarantee stated is that they will definitely use money for something else. Not OK.
I’m not familiar with German governance for quasi not for profits, but I suspect the idea that funds are conditional for one specific purpose probably breaches governance, and returning funds to donors if certain conditions are/are not met could be problematic from a tax point of view. I know this would be the case in other European jurisdictions with which I am more familiar.
And here (from another HN link I just browsed) is other work CCC is doing, his time exposing a major security flaw in VW Audi Group security policies: https://cyberinsider.com/vw-suffers-major-breach-exposing-lo...
To put it short: there are two different kinds of NPOs, first "regular" e.V. and then those e.V. that fulfill exclusively "aims for the common good" ("gemeinnützige Zwecke", the full list is in §52 AO [1]) - they carry a special benefit: donations can be deducted from your income for tax purposes.
The CCC is a non-profit organization, but since it (among other things) engages in taking political stances while at the same time not being a political party, it is not seen as a "gemeinnützig" organization - a fate that hit quite a few organizations in the last years [2] or is looming over their head [3].
[1] https://www.gesetze-im-internet.de/ao_1977/__52.html
[2] https://www.campact.de/ueber-campact/der-verein/
[3] https://www.mdr.de/nachrichten/deutschland/politik/brandbrie...