14-Year-Old Turns Tram System Into Personal Train Set
F-3582 writes "By modifying a TV remote a 14-year-old boy from Lodz, Poland, managed to gain control over the junctions of the tracks. According to The Register the boy had 'trespassed in tram depots to gather information needed to build the device. [...] Transport command and control systems are commonly designed by engineers with little exposure or knowledge about security using commodity electronics and a little native wit.' Four trams derailed in the process injuring a number of passengers. The boy is now looking at 'charges at a special juvenile court of endangering public safety.'"
I know some kids who are extremely bright, curious, and for lack of a better description, "like to experiment". Any one of these I think could have done the same thing, and with completely innocent (though mischievous) intent. For playing with such big toys in such a fashion there should be repercussions. But the kids I know who also could have done something like this would be much more on track with thinking about how they're moving switches than about what moving those switches implies.
However, I'm led to a different train of thought. What other systems are out there created in the same context, i.e., with little thought to external interference? I'm betting there are a "few". I wonder that in the process of designing something like this if we must pay more attention to the possibility of outsiders tinkering. I hope France's TGV has a bit more built in checks and balances than this. I hope the new Boeing 787 has more security built in than this.
I actually think (and hope) this kid's imagination and curiosity somehow gets channeled rather than squashed. He actually sounds like he could be a contributor. Of course, he's at least grounded for the next month.
It should be the enginners and their bosses that should be the ones facing criminal charges.
Does it really take special security training for engineers to realize that controlling train junctions with TV remote controls (or close enough) might be a bad idea? Where's the whatcouldpossiblygowrong tag when you need it?
In some law systems, he'd probably be labeled a terrorist, charged with attempted murder (if he even gets a criminal trial) and spend 10 years in jail. Let's hope Poland is more civilized, I'd guess humiliation from the trial plus quite a lot of hours of community service will frighten him enough to never cross the line again. Then again, his parents will probably be ruined as they'll have to pay the damages.
Fleur de Sel
Sounds like this kid was not adequately challenged by his school. At least that's what the story leads me to believe. If I was the judge I would let him off on the condition that he goes to a school where his curiosity will be encouraged but given enough direction so he doesn't get into more trouble.
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
Why is it that facility operators, be it trains, power plants, oil refineries, or anything have pathetic security, and when something does happen, they blame it totally on the perp who likely never had to confront even a single lock, much less a guard?
Makes me wonder if countries should have a special regulatory team whose job it is to attempt break ins on a regular basis to various areas, and levy fines to organizations failing compliance. Only problem is areas where people shoot to kill... telling a tiger team from a genuine trespasser/burglar/criminal before pulling the trigger.
Well, yes and no. Just give a bit of serious thought to the issue... I'm at work, have to AC.
It sounds as though the system worked of infrared pulse encoding, and that is why he could use a modified television remote. Imagine you are the one designing this (probably in the 1970's or 1980's...) It is generally desirable to keep things simple to ensure they actually *work* -- that is, having a rolling code that may be out of sync while having a signalling train hurtle toward the junction at 80 mph is not desirable -- you want a simple system that the train can activate if needed.
Anybody who has worked with security (my job) knows that the more layers you add, the harder (network) testing is, and the more ways something can go VERY wrong for a legitimate user.
If the train couldn't switch the junction box because it didn't have the right "password," you would also criticize the engineers.
I defend the train design -- this should be treated as sabotage, and is more along the continuum of putting a penny on the tracks or mechanically interfering with a junction box, things that are also dangerous, illegal, and difficult to defend entirely against.
I'm surprised nobody has asked the obvious question. Switches normally switch between two tracks. How does switching a train to a different track cause it to derail? Collide, sure, but derail? Sounds like a design problem to me... or a whole lot of design problems if it is possible for it to switch when a train is in the middle of the switch, as I suspect occurred. There should be safety interlocks to prevent switching from even being possible as long as a weight sensor at the switch is depressed.
It strikes me that this kid not only found a security flaw in the system, but also found at least one very serious safety flaw that could have occurred due to electronics glitches even if he hadn't done this. It could have ben a lot worse, particularly if those same switching systems are used for any high-speed trains....
Check out my sci-fi/humor trilogy at PatriotsBooks.
...heinously vulnerable systems are the ones who should get locked up in jail.
Speculation: An alternative explanation would be that the two curves were of different diameter, and the driver intended to take the larger-diameter one, traveling at a speed too high for the sharper curve the tram ended up taking. Tram lines sometimes take pretty sharp turns.
Those people that panic and don't move promptly should have their licenses revoked.
This whole thread is pissing me off. "He was young and didn't know what he was doing..." BS. If the kid is smart enough to hack into a system, he's easily smart enough to know how much a train weighs and what damage a train derailment will cause. Send this kid to jail!
Secondly, I hate when people excuse bad driving as normal. It's not acceptable. If you don't clear the intersection when emergency vehicles are coming, you shouldn't be driving, period. If you consistently drive 5mph under the speed limit, your license should be revoked. If you can't PARK YOUR CAR without extreme effort, license REVOKED! If you took licenses away from all the people that shouldn't have them for safety reasons, there would be 50% fewer people on the road, AT LEAST.
I hate people.
evil adrian
Is this not the rationale for penetration testing? It's better to have your lack of security demonstrated to you by a relatively benign agent before a truly malevolent one.
Which sort is this 14 year old who derailed 4 trains and injured people again?
I'm not saying his punishment should be harsh but he *did* do wrong here and knew or should have known that he was doing wrong.
New punctuation update "~" (no quotes) at the end of a line to indicate sarcasm. ~
Now, I'm all for people driving the speed limit, maybe a little more. But legally, the speed limit is an upper limit, not a lower limit. And people who drive like the speed limit is just a guideline tend, in my experience, to be more prone to road rage than those who actually obey it.
Maybe you should consider a class in anger management. Or take a deep breath and put on some jazz music when you get in heavy traffic.
!#@%*)anks for hanging up the phone, dear.
That would explain the case of a train entering the base of the Y and exiting the top. The far more likely case is that the train entered the top of the Y and the switching rail was on the other leg. The inner rail would be pointed at the other leg. Trains don't run well on a giant gap in the rail.