Email or username:

Password:

Forgot your password?
Jason Koebler

The hero Polish hackers who fixed DRM-bricked trains have explained how they did it. There was DRM that killed power to trains and broke compressors if trains had been to independent repair yard. One train was also programmed to arbitrarily break on December 21, which actually happened two weeks ago:

404media.co/polish-hackers-exp

15 comments
stereo griever

@jasonkoebler not sure where you got this emergency brake part from, the train is supposed to release them when you're trying to run it, that's done correctly. the problem here was that, together with releasing the brakes, it wasn't sending power to the inverters, which power the engines.

Micha艂 "rysiek" Wo藕niak 路 馃嚭馃嚘

@selfisekai @jasonkoebler yup.

Here's the full technical talk that goes into all the details:
media.ccc.de/v/37c3-12142-brea

And fun fact the ED78-010 train that was celebrating the Broken Compressor Day since December 21st, returned to work on January 1st, as expected:
rynek-kolejowy.pl/wiadomosci/n

Jason Koebler

@rysiek @selfisekai I've corrected the piece, this was my mistake. I dumbly assumed that 'emergency stop' signal corresponded to emergency brakes. Thanks for pointing out

Micha艂 "rysiek" Wo藕niak 路 馃嚭馃嚘

@jasonkoebler thank you!

Also, one more little thing: it's "Newag" or "NEWAG"; not sure where the "NewAg" capitalization came from.

Good piece though, please don't take these little nit-picks the wrong way. Really enjoyed how 404media has been covering this.

@selfisekai

Tube馃崅Time

@rysiek @selfisekai @jasonkoebler oh wow this talk is really good, what a fantastic reverse engineering job!

Switch

@jasonkoebler I bet the people who implemented this give of strong Hackers 1995 Bad Guy vibes...
imgur.com/olySa60 (link to a random gif of the character)

Leszek Karlik

@jasonkoebler

The company name is "Newag", not "NewAg" :-)

Anyway, I'm still waiting for criminal prosecutions to drop, we'll see if anything happens.

RojCowles

@Leszek_Karlik @jasonkoebler

Me too, though from my side I'm hoping that Polish law allows discovery by the team being sued and that they get access to Newag's source code repository with full history and internal company communications which might show who, when and why these geospatial locks were added.

At least in my rich inner fantasy universe that's how things play out.

Stanley

@jasonkoebler Trolley Problem: Would you prevent the runaway train from killing people if doing so meant breaking the Terms of Service?

LibertyForward1

@jasonkoebler modern technology is so fun sometimes.. 馃檮

Zorin =^o.o^=

@jasonkoebler Wow. This is insane. This manufacturer needs to be sued and penalized so severely that no one ever thinks of pulling this shit again.

Peter Bindels

@zorinlynx @jasonkoebler This is the first manufacturer caught with their pants down. There are at the very least dozens others doing the same thing - likely thousands.

Patrick

@jasonkoebler amazing work and very important, too! Nevertheless, it doesn't really surprise that vendors went down that road. But in this case really concerning.

Go Up