Archived

Norway: Chinese-made electric buses have major security flaw, can be remotely stopped and disabled by their manufacturer in China, Oslo operator says

The public transport operator in Norway’s capital said Tuesday that some electric buses from China have a serious flaw – software that could allow the manufacturer, or nefarious actors, to take control of the vehicle.

Oslo’s transport operator Ruter said they had tested two electric buses this summer – one built by China’s Yutong and the other by Dutch firm VDL.

The Chinese model featured a SIM card that allowed the manufacturer to remotely install software updates that made it vulnerable, whereas the Dutch model did not.

“We’ve found that everything that is connected poses a risk – and that includes buses,” Ruter director Bernt Reitan Jenssen told public broadcaster NRK.

“There is a risk that for example suppliers could take control, but also that other players could break into this value chain and influence the buses.”

Ruter said it was now developing a digital firewall to guard against the issue.

According to other reports, the Chinese manufacturer has access to each bus’s software updates, diagnostics, and battery control systems. “In theory, the bus could therefore be stopped or rendered unusable by the manufacturer,” the company said.

Ruter has reported its findings to Norway’s Ministry of Transport and Communications.

Arild Tjomsland, a special advisor at the University of South-Eastern Norway who helped conduct the tests, said: “The Chinese bus can be stopped, turned off, or receive updates that can destroy the technology that the bus needs to operate normally.”

[…]

      • mech@feddit.org
        link
        fedilink
        English
        arrow-up
        46
        arrow-down
        6
        ·
        14 days ago

        It does matter, if there is ever a conflict between China and the EU, China can completely disable our infrastructure without firing a shot.
        It would have the same effect as a nuke on all cities.

        • remon@ani.social
          link
          fedilink
          English
          arrow-up
          33
          arrow-down
          1
          ·
          14 days ago

          It would have the same effect as a nuke on all cities.

          Yeah, just like the other day when there was a problem with the overhead line which stopped all the trams and gave me radiation poisoning.

            • Whostosay@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              8
              arrow-down
              3
              ·
              13 days ago

              Let’s be real for a sec, the only thing that can turn a couple square miles of city into glass is a nuke. There is no alternative.

              • CybranM@feddit.nu
                link
                fedilink
                English
                arrow-up
                4
                ·
                13 days ago

                Obviously, but turning off all electronics in a city will have an immense impact.

                • Maeve@kbin.earth
                  link
                  fedilink
                  arrow-up
                  6
                  ·
                  13 days ago

                  I’m more concerned our own governments will do that, if we ever decide complacency isn’t serving us.

                  • CybranM@feddit.nu
                    link
                    fedilink
                    English
                    arrow-up
                    5
                    ·
                    13 days ago

                    These two scenarios are not mutually exclusive. Both are bad and that’s why we shouldn’t have backdoors in software

        • trollercoaster@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          1
          ·
          14 days ago

          Guess where many European manufacturers do have a lot of their components made, because it’s cheaper? If China wants to disable much more than just European infrastructure, they can simply do this by enacting an embargo.

          In a conflict with China, we’re royally fucked in one way or another. Thanks to boundless corporate greed and political complicity.

          The real problem here is over the air updates in a piece of infrastructure, even more so in a machine where a malfunction can endanger lives.

          • Alcoholicorn@mander.xyzBanned from community
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            4
            ·
            13 days ago

            What if you simply didn’t go to war with your biggest trading partner?

              • Socialism_Everyday@reddthat.comBanned from community
                link
                fedilink
                English
                arrow-up
                6
                arrow-down
                2
                ·
                13 days ago

                We did that by trading with China instead of with the bully (USA). The EU fundamentally cannot manufacture most of the stuff it consumes because neoliberal policy doesnt allow for that. If you want to go to self-made stuff, you’d have to become the eastern block politically. Which I advocate for.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          13 days ago

          It would have the same effect as a nuke on all cities.

          that’s how you invalidate all other things you said

        • Socialism_Everyday@reddthat.comBanned from community
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          8
          ·
          13 days ago

          How about our policy were not to become enemies of thr largest manufacturing hub and rising world power with 3 times our population?

          • Quittenbrot@feddit.org
            link
            fedilink
            English
            arrow-up
            10
            arrow-down
            1
            ·
            13 days ago

            If a policy to remain independent means becoming the enemy of someone, it’s not the policy that’s the problem.

            • Socialism_Everyday@reddthat.comBanned from community
              link
              fedilink
              English
              arrow-up
              7
              arrow-down
              3
              ·
              13 days ago

              How are we China’s enemy? We’re the ones suddenly trying to nationalize companies like Nexperia. When did China do something like this? Obeying leader Trump in 5% military expenditure isn’t exactly being independent either.

              • Hotznplotzn@lemmy.sdf.orgBanned from communityOP
                link
                fedilink
                English
                arrow-up
                5
                arrow-down
                2
                ·
                13 days ago

                @[email protected]

                When did China do something like this?

                What an absurdly flawed argument. China never did something like that simply because a foreign company is legally banned from owning its own Chinese subsidiary in the first place. You always need a Chinese partner that would then own the majority of “your” company.

                • Socialism_Everyday@reddthat.comBanned from community
                  link
                  fedilink
                  English
                  arrow-up
                  6
                  arrow-down
                  1
                  ·
                  13 days ago

                  I’m answering to the comment about “becoming their enemy by being independent”. I’m asking for evidence of China choosing Europe as its enemy, as I genuinely haven’t seen such hostile acts unless in retaliation from Europe choosing to suddenly become China’s enemy.

                  • Alcoholicorn@mander.xyzBanned from community
                    link
                    fedilink
                    English
                    arrow-up
                    6
                    arrow-down
                    2
                    ·
                    13 days ago

                    Well no, America chose to became China’s enemy, and Europe is following them as they have since WWII.

              • Quittenbrot@feddit.org
                link
                fedilink
                English
                arrow-up
                3
                arrow-down
                2
                ·
                13 days ago

                We’re the ones suddenly trying to nationalize companies like Nexperia. When did China do something like this?

                You do realise that China defined ‘restricted’ industrial sectors where foreigners at most can form a joint venture with a Chinese company which must own more than the foreign one? We granted far more liberties to the Chinese than the other way round.

                • Socialism_Everyday@reddthat.comBanned from community
                  link
                  fedilink
                  English
                  arrow-up
                  6
                  arrow-down
                  4
                  ·
                  13 days ago

                  That still doesn’t respond to my initial question of when China has designated Europe as its enemy, which is why I brought up the particular event of escalation of economic warfare that Europe decided to engage in this very week.

                  • Quittenbrot@feddit.org
                    link
                    fedilink
                    English
                    arrow-up
                    3
                    arrow-down
                    2
                    ·
                    13 days ago

                    You can call it “enemy”, you can call it “rival”, or whatever you like: China views itself as in competition with us and hence will naturally try to shift things in their favour. Which is completely fine by me, that’s just how it goes if you want to be a major power. But we shouldn’t pretend that our interests, i.a. a strong Europe, is China’s interest. Because it isn’t.

              • troed@fedia.io
                link
                fedilink
                arrow-up
                3
                arrow-down
                2
                ·
                13 days ago

                Hi! Person with knowledge of doing business in China as a “western company”. You start up your company and hire Chinese engineers. After a while many of them will quit and instead work for a newly created company across the street that do the exact same thing as you do (soon to be “did”).

                • Socialism_Everyday@reddthat.comBanned from community
                  link
                  fedilink
                  English
                  arrow-up
                  7
                  arrow-down
                  2
                  ·
                  13 days ago

                  Huh, I thought we loved free market competition in Europe. If you can’t keep your workers or compete against another firm, by market logic your business isn’t efficient and shouldn’t exist.

                  • troed@fedia.io
                    link
                    fedilink
                    arrow-up
                    2
                    arrow-down
                    2
                    ·
                    13 days ago

                    You’ve never held a job, correct? It would be difficult to explain not understanding “company secrets” otherwise.

                • Maeve@kbin.earth
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  13 days ago

                  Bill Gates and Apple. Both are shit business models, but this isn’t a “Chinese specific” thing.

                • Hotznplotzn@lemmy.sdf.orgBanned from communityOP
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  2
                  ·
                  13 days ago

                  Hi! Person with knowledge of doing business in China as a “western company”. You start up your company and hire Chinese engineers. After a while many of them will quit and instead work for a newly created company across the street that do the exact same thing as you do (soon to be “did”).

                  As someone who has also experience of doing business in China as a “Western company”: Yes, that’s exactly the way it is.

      • troed@fedia.io
        link
        fedilink
        arrow-up
        20
        arrow-down
        1
        ·
        13 days ago

        From the OP post:

        The Chinese model featured a SIM card that allowed the manufacturer to remotely install software updates that made it vulnerable, whereas the Dutch model did not.

      • Alcoholicorn@mander.xyzBanned from community
        link
        fedilink
        English
        arrow-up
        4
        ·
        14 days ago

        At least most motorcycles are safe, as long as you stay away from like BMW and Harley

    • FiskFisk33@startrek.website
      link
      fedilink
      English
      arrow-up
      32
      arrow-down
      1
      ·
      13 days ago

      Dont forget those polish trains, this is not simply a china vs west situation, this ridiculously wide spread. Lawmakers should have been all over this years ago!

    • hayvan@feddit.nl
      link
      fedilink
      English
      arrow-up
      24
      arrow-down
      1
      ·
      13 days ago

      It’s less about that. Buy things you actually own, independent of the supplier. Sure, I’d rather have a European supplier to control my stuff than Chinese one, it’s not even a competition, but come on.

      • arin@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        7
        ·
        13 days ago

        All modern cars can be taken control over by manufacturer or law enforcement. Same as most phones and computers.

          • Alcoholicorn@mander.xyzBanned from community
            link
            fedilink
            English
            arrow-up
            10
            arrow-down
            2
            ·
            13 days ago

            I looked up 4 european bus manufacters at random and whether they use OTA updates. They all did. It seems like the VDL bus is unusual, if it does infact not use OTA updates as the article says.

            • Mark with a Z@suppo.fi
              link
              fedilink
              English
              arrow-up
              6
              ·
              13 days ago

              Yeah, that isn’t surprising, but I’m really glad it’s making headlings because IoT vehicles are a liability.

              Also, really nice that you made the effort to check it yourself.

              • Alcoholicorn@mander.xyzBanned from community
                link
                fedilink
                English
                arrow-up
                8
                arrow-down
                1
                ·
                13 days ago

                I’m really glad it’s making headlines

                Bad news, that’s not what’s making headlines. This isn’t an article about smart devices introducing unnecessary attack surfaces, this is an article about the perfidious Chinese sneakily putting spyware into your buses. Hence why there’s a million articles about this one Chinese bus and none about the other 98% of buses in Europe and they call for boycotts of Chinese buses instead of banning OTA updates on buses.

                • Mark with a Z@suppo.fi
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  1
                  ·
                  13 days ago

                  I do still think it’s better than nothing for awareness. It’s not a massive leap to go from “chinese remotely brickable bus bad” to “any remotely brickable bus bad”.

                  • Maeve@kbin.earth
                    link
                    fedilink
                    arrow-up
                    4
                    ·
                    13 days ago

                    I would have thought so. From OP post history and plenty of comments, apparently it’s not.

    • Evotech@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      13 days ago

      They’re not allowed. These kinds of things must be placed to the open market and the best offer must be accepted