this post was submitted on 13 Dec 2023
1325 points (99.6% liked)

Technology

59219 readers
2836 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

In one of the coolest and more outrageous repair stories in quite some time, three white-hat hackers helped a regional rail company in southwest Poland unbrick a train that had been artificially rendered inoperable by the train’s manufacturer after an independent maintenance company worked on it. The train’s manufacturer is now threatening to sue the hackers who were hired by the independent repair company to fix it.

After breaking trains simply because an independent repair shop had worked on them, NEWAG is now demanding that trains fixed by hackers be removed from service.

top 50 comments
sorted by: hot top controversial new old
[–] ShittyBeatlesFCPres@lemmy.world 274 points 11 months ago (3 children)

This story should be on every newspaper front page right below war correspondents.

[–] Lev_Astov@lemmy.world 31 points 11 months ago

Yeah, especially in the EU where apparently their laws regarding circumventing DRM might make the people who fixed this the bad guys instead of this comically evil manufacturer who put GPS kill switches on public passenger trains.

load more comments (2 replies)
[–] BloodSlut@lemmy.world 268 points 11 months ago (2 children)

"We didn't add a kill switch to our trains to force the use of our maintenance service, but fuck the hackers that removed the kill switch we didn't implement, and the trains that were hacked and don't have the kill switch we didn't add should be removed from service."

[–] Th3D3k0y@lemmy.world 145 points 11 months ago* (last edited 11 months ago) (2 children)

Dear Reader,

Regarding your recent free and non-profitable un-fucking of our problem, please use the honor system and manually refuck yourself.

Love, Technology Companies.

[–] thefartographer@lemm.ee 14 points 11 months ago

Someone's gonna figure out a horror movie for this called The Refucker

[–] ASeriesOfPoorChoices@lemmy.world 7 points 11 months ago (4 children)

Wasn't free - they were paid to hack it.

But yeah.

load more comments (4 replies)
[–] Jessvj93@lemmy.world 53 points 11 months ago

"And how dare those hackers go through all the trouble of finding those (literal) GPS coordinates of train maintenance centers not in our system to circumvent us getting more money."

[–] andrewrgross@slrpnk.net 164 points 11 months ago (2 children)

That's awesome. Man, fuck that company. Bricking a train? Outrageous.

[–] Bizarroland@kbin.social 74 points 11 months ago (5 children)

Poland ought to ban that company from ever working or operating or selling any products inside of its country and any trains made by that company that are not currently owned by Poland should be prevented from traveling on the tracks that cross through Poland.

[–] SpookyUnderwear@eviltoast.org 33 points 11 months ago

This is the kind of government intervention I can get behind. This story is so outrageous, it's hard to believe it's true.

[–] funkless_eck@sh.itjust.works 10 points 11 months ago (1 children)

unfortunately they have a right wing government so it's likely they'll want more of this not less

[–] Maggoty@lemmy.world 31 points 11 months ago (2 children)

They just swore in the new Cabinet today. They still have a far right President and Judiciary to contend with but the legislature is a coalition of centrists and leftists now.

load more comments (2 replies)
[–] BearOfaTime@lemm.ee 8 points 11 months ago

Maybe make it the entire executive and senior management, rather than the company.

load more comments (2 replies)
[–] thefartographer@lemm.ee 42 points 11 months ago (2 children)

Run by fucking criminals. We should brick them like they're The Sticky Bandits

[–] AlwaysNowNeverNotMe@kbin.social 13 points 11 months ago

Better to brick them like The Cask of Amontillado.

[–] pelotron@midwest.social 8 points 11 months ago

Great idea, Marv.

[–] DacoTaco@lemmy.world 159 points 11 months ago* (last edited 11 months ago) (2 children)

The person is doing a talk about it in hamburg, germany (37c3) next week. Its on my to watch list because that sounds hella interresting.

Edit : 37c3 list of talks : https://halfnarp.events.ccc.de/#dec115da17562cebafa9ba7a150a4fc607c25c880c03593dcc8da6087c9441a4

[–] khannie@lemmy.world 37 points 11 months ago (7 children)

That actually does sound hella interesting. I'm saving your comment to try to remember but actually look it up in about two years when I scroll back though my saved posts.

[–] pwalker@discuss.tchncs.de 12 points 11 months ago (2 children)

It's 37c3, but thx for the hint. The talk is called Breaking "DRM" in Polish trains by Redford, q3k, MrTick

I will try to watch it on stage, unfortunately still no final schedule available

load more comments (2 replies)
[–] roguetrick@kbin.social 69 points 11 months ago* (last edited 11 months ago) (2 children)

SPS became desperate and Googled “Polish hackers” and came across a group called Dragon Sector, a reverse-engineering team made up of white hat hackers.

Hilarious. I hope 404 continues with this level of high quality journalism.

Dragon sector, who they hired, is a security capture the flag team.

https://dragonsector.pl/

Edit: Socials of those who worked on it

https://social.hackerspace.pl/@q3k
https://infosec.exchange/@mrtick
https://infosec.exchange/@redford

[–] sukhmel@programming.dev 17 points 11 months ago* (last edited 11 months ago) (1 children)

TIL that [security CTF](https://en.m.wikipedia.org/wiki/Capture_the_flag_(cybersecurity)) is

an exercise in which participants attempt to find text strings, called "flags", which are secretly hidden in purposefully-vulnerable programs or websites

Never heard of this and I may not be alone in that. Thanks for pointing this out.

[–] khannie@lemmy.world 10 points 11 months ago* (last edited 11 months ago) (2 children)

I did one before. They are SO MUCH FUN. Now I have too many children.

sob

edit: There are other ways of capturing the flag like having your team name on the home page of a local web server or whatever.

load more comments (2 replies)
[–] verity_kindle@sh.itjust.works 10 points 11 months ago (1 children)

Finally, hackers with a cool name, like Bellingcat or Oryx. It's all I'm asking for, but the Russian and North Korean hackers are so disappointing in so many ways.

load more comments (1 replies)
[–] sanqueue@lemmy.world 61 points 11 months ago (1 children)

This is good. Someone did that for printers too

[–] Lemminary@lemmy.world 38 points 11 months ago (2 children)

And American Weight (?) digital scales. The ones that brick themselves after 2,000 uses because how dare you only pay once.

[–] jucelc@lemmy.wtf 27 points 11 months ago

Lol. Always suspected there was a scam there, but every time I bring it up in a conversation - people just call me a conspiracy theorist.

This goes for pretty much everything though. Planned obsolescence is real, but people think it's just the natural way of things.

[–] DeafeningDistance@feddit.ch 11 points 11 months ago (1 children)

is there an article about this? Would love to read about it

[–] Lemminary@lemmy.world 10 points 11 months ago

There is no article that I could find, so I guess you take my word for it. But I'll fill you in on why I said it from what I remember. You can make up your mind on this:

I was looking for a digital scale during the pandemic and naturally went on Amazon. I found some within my budget (I live outside the US) but most of them had multiple reviews complaining about a weird error that they couldn't fix. I did some digging around, yet nobody seemed to know what the error really was that was showing up after some time of prolonged use without signs of wear. Eventually, I got to a thread on some technical forum that said it was a software error that strongly hinted at planned obsolescence after so many uses.

The weird thing is that I can't find any of the models that had this on Amazon anymore but it doesn't surprise me after some of the shit I've seen on there with people manipulating reviews on other products I've bought. So I guess it could go either way for someone review-bombing the product or it being a real issue, but that doesn't explain the error showing up on other sites. I wish I could remember what the error code was.

If anybody knows anything more about this, I'd love to hear it. It certainly was a strange surprise that ended up costing me a bit more than I was planning to spend. But I guess bullet dodged?

[–] yamanii@lemmy.world 60 points 11 months ago (4 children)

The anti-circumvention clause is being abused for some years now, it's disgusting.

load more comments (4 replies)
[–] Ruscal@sh.itjust.works 59 points 11 months ago (2 children)
[–] SCB@lemmy.world 10 points 11 months ago* (last edited 11 months ago) (1 children)

Thank you! Came here to ask if anyone had one source with the whole story. This keeps trickling out as it evolves.

Edit: this story is considerably weirder than I expected, and I was already expecting some weird shit.

Begs the question: How is any of this legal?

load more comments (1 replies)
[–] Dio9sys@lemmy.blahaj.zone 38 points 11 months ago

I like how, instead of recognizing that they got caught, now the train manufacturer is claiming this is some kind of dark PR strategy.

If it is, then please show the public that it's a dark PR strategy by explaining the hidden unlock codes and the DRM code!

[–] EdibleFriend@lemmy.world 33 points 11 months ago (1 children)

I hate this fucking planet.

[–] DuckOverload@lemmy.world 24 points 11 months ago (1 children)

I think this is pretty cool. Sure, capitalists are gonna capitalist, but here we have subversive moves in a positive direction.

[–] EdibleFriend@lemmy.world 13 points 11 months ago

Oh yeah what the people did to get around this is fucking awesome I do love that side of this story don't get me wrong.

[–] RememberTheApollo_@lemmy.world 24 points 11 months ago

If they required the trains to be serviced by manufacturer they should have written it into a mandatory service contract at time of sales.

[–] alphacyberranger@lemmy.world 19 points 11 months ago (2 children)
[–] YoorWeb@lemmy.world 8 points 11 months ago

Ah, Louis Rossmann, a real-life superhero. He did some great work in his career.

load more comments (1 replies)
[–] btr_fan87@lemmy.world 14 points 11 months ago (2 children)

Artificially bricked?! Who the hell keeps giving Viagra to trains? Evil bastards.

load more comments (2 replies)
[–] KeenFlame@feddit.nu 13 points 11 months ago

Spewing bs about how they can't guarantee the safety and other outrageous shit pouring out their mouths as they provide clearly practiced lawyerspeak to squeeze money from public service into their owners pockets which will then be invested probably in war and killing children for profit.

But let's discuss ethics and shit! Fuck faces need to be brought to moral justice for the evil they commit every day of their brainwashed miserable hateful lives where they pretend to not harm people because they don't do it themselves but via money grabbing schemes. One day all of this shit will seem to be as stupid as hitting kids are these days

[–] simin@lemmy.world 12 points 11 months ago (2 children)

the world's not one's to fix, learn to protect yourself.

load more comments (2 replies)
load more comments
view more: next ›