340

The situation is a heavy machinery example of something that happens across most categories of electronics, from phones, laptops, health devices, and wearables to tractors and, apparently, trains. In this case, NEWAG, the manufacturer of the Impuls family of trains, put code in the train’s control systems that prevented them from running if a GPS tracker detected that it spent a certain number of days in an independent repair company’s maintenance center, and also prevented it from running if certain components had been replaced without a manufacturer-approved serial number.

The problem was so bad that an infrastructure trade publication in Poland called Rynek Kolejowy picked up on the mysterious issues over the summer, and said that the lack of working trains was beginning to impact service: “Four vehicles after level P3-2 repair cannot be started. At this moment, it is not known what caused the failure. The lack of units is a serious problem for the carrier and passengers, because shorter trains are sent on routes.”

Very good article, I'd recommend reading it. I hope the court rules against NEWAG and sets a precedent for right to repair.

all 36 comments
sorted by: hot top controversial new old
[-] FiskFisk33@startrek.website 53 points 11 months ago

Modifying the software of a device YOU OWN, should never be illegal in and of itself.

[-] Engineer@discuss.tchncs.de 9 points 11 months ago

Absolutely. Maybe an exception for video game multiplayer cheating, but that's the only thing I can think of. Any other situation I can think of just enriches the computer to the massive detriment of the user.

[-] Akrenion@programming.dev 22 points 11 months ago

Force modified clients in a seperate lobby. Mods can be fun and extend shelflife of games immensly.

[-] TheHobbyist@lemmy.zip 15 points 11 months ago

And allow selfhosting servers for (at least after) when the publisher/developer stops supporting the game.

[-] JohnBrownNote@hexbear.net 6 points 11 months ago

abandoned software should be public domain, including server code and the tools for maintaining and updating it.

really the workers should own the means of production and all that stuff should be public from hello world, but we're talking about some transitional steps i guess.

[-] TheHobbyist@lemmy.zip 3 points 11 months ago

I agree and I wish, I think the tricky part would be defining the criteria to what constitutes "abandomware". Is it the stop of the sale? The shutdown of the attestation servers, the shutdown of the multiplayer servers (and in that case what about single player games)? I can only imagine the creativity of publishers pretending their game is not abandonware yet it practically being so.

[-] JohnBrownNote@hexbear.net 3 points 11 months ago

yeah it's a little tricky to put that sentiment into law... and to some extent we wouldn't need to if copyright law wasn't just disney's regulatory capture.

[-] Rom@hexbear.net 2 points 11 months ago

"Our 15 year old game has a single password protected server running that an employee connects to a few times a year so technically it's not abandoned and we don't have to make the code public domain, checkmate"

[-] lunarul@lemmy.world 12 points 11 months ago

No, that shouldn't be illegal either. Against the rules of a server and getting you kicked out of that server, sure.

[-] Saeculum@hexbear.net 11 points 11 months ago

Is multiplayer cheating illegal? They have the right to kick you off their servers, but I'd be surprised if it's a criminal offense or anyone has ever had a case brought against them.

[-] JohnBrownNote@hexbear.net 4 points 11 months ago

i'd be ok with videogame cheaters being executed by the state

[-] Rom@hexbear.net 2 points 11 months ago
[-] Engineer@discuss.tchncs.de 3 points 11 months ago

Yeah I don't think it is. I was just trying to think of edge cases.

[-] FiskFisk33@startrek.website 3 points 11 months ago

cheating is a problem but, actually making it illegal? nah man, I think that's too far.

[-] huf@hexbear.net 8 points 11 months ago

which is why they're trying to move to a model where you own nothing

[-] WindowsEnjoyer@sh.itjust.works 1 points 11 months ago

I am not against you, but in case of warranty - how do you draw a line of where is user's fault, and where is manufacturers fault?

[-] FiskFisk33@startrek.website 3 points 11 months ago* (last edited 11 months ago)

well, it doesn't have to be illegal to void warranties. If you for example brick your device through software shenanigans you don't expect the maker to fix it for free for you, but you don't expect them to sue you either!

[-] eskimofry@lemmy.world 2 points 11 months ago

You gotta attach some base flat fee to send out the engineers that would deter fraudulent claims?

[-] lemann@lemmy.one 23 points 11 months ago

I hope this NEWAG gets raked over the coals for this.

It's outrageous to hold public infrastructure at ransom because the equipment spent X days in an independent repair shop - and pretty invasive to have DRM monitoring the train's GPS location, and in some cases live reporting these back to the manufacturer to facilitate a remote lockdown.

Not to mention pushing an update to flag up a copyright warning on a screen in the drivers' cab while the train is running 🤦‍♂️

I commend the engineer at the independent repair facility that had the idea to have hackers pick apart the train's control unit, and the rest of the team for agreeing to it.

[-] activistPnk@slrpnk.net 21 points 11 months ago* (last edited 10 months ago)

~~The mere fact that the manufacturer had a remote kill switch is the safety issue that should have a big spotlight.~~(edit: this is not the case - see the reply below) What if a malicious hacker decides to trigger that kill switch while the train is loaded with people and at a sensitive moment (e.g. on bridge/cliff with a huge drop).

If the kill switch were in place for dealing with hi-jackers, perhaps fair enough. But having it for the purpose of business protectionism is an entirely reckless safety risk.

There’s an overlooked failure here: why doesn’t the Polish transport authority have a clause in their procurement contracts that bans trains with remote-control kill switches that are not under user control? And why wasn’t the code reviewed to catch that in advance? The hackers say they did not alter the code, which somewhat implies that the source code might have been available for inspection.

[-] kilgore_trout@feddit.it 5 points 10 months ago* (last edited 10 months ago)

In the talk they gave yesterday night, Dragon Sector hackers clarified that they are not aware of any remote control available to the manufacturer.

The locks were implemented inside the code both when the trains were first serviced to railway operators by the manufacturer, and any time the manufacturer was given direct on-hand access.

See here to watch their speech: https://feddit.it/post/4391905

[-] activistPnk@slrpnk.net 5 points 10 months ago* (last edited 10 months ago)

Thanks for the link. Indeed you are correct. The lock only triggers when it’s stopped and it’s hard-coded and not remote. Apparently the only comms involved was the train signalling to the manufacturer that the lock was triggered.

[-] baggins@lemmy.ca 20 points 11 months ago

The GPS coordinates are especially damning. Also funny that the manufacturer is claiming they made the trains unsafe, since obviously once they uncovered the unlock code they can just use it on unmodified trains.

[-] fallingcats@discuss.tchncs.de 2 points 11 months ago

They did say the manufacturer removed the override key combination

[-] Nationalgoatism@hexbear.net 17 points 11 months ago

It's ridiculous, not only the manufacturers egregious behavior, but also the fact that there is software required to operate a vehicle without a mechanical override. If and when I am forced to own a car with such technology my first move will be to disconnect the entire module and install a proper starting and control system.

[-] grey@discuss.tchncs.de 8 points 11 months ago

Man, just go back to normal trains and now computers with attached trains. Can't hack or remotely kill what doesn't have a computer in it.

[-] RubberElectrons@lemmy.world 8 points 11 months ago

Erm... There's a lot going on inside an electrically powered train. Even a diesel engine has a computer managing fuel flow and diagnostics.

More importantly, you need networked computers to handle automatic train safety systems, a requirement in the EU from what I understand, after several notable rail crashes up to the 70's.

this post was submitted on 14 Dec 2023
340 points (99.7% liked)

Right to Repair

1493 readers
63 users here now

Whether it be electronics, automobiles or medical equipment, the manufacturers should not be able to horde “oem” parts, render your stuff useless if you repair it with aftermarket parts, or hide schematics of their products.

I Fix It Repair Manifesto

Summary article from I Fix It

Summary video by Marques Brownlee

Great channel covering and advocating right to repair, Lewis Rossman

founded 1 year ago
MODERATORS