Archived

Norway: Chinese-made electric buses have major security flaw, can be remotely stopped and disabled by their manufacturer in China, Oslo operator says

The public transport operator in Norway’s capital said Tuesday that some electric buses from China have a serious flaw – software that could allow the manufacturer, or nefarious actors, to take control of the vehicle.

Oslo’s transport operator Ruter said they had tested two electric buses this summer – one built by China’s Yutong and the other by Dutch firm VDL.

The Chinese model featured a SIM card that allowed the manufacturer to remotely install software updates that made it vulnerable, whereas the Dutch model did not.

“We’ve found that everything that is connected poses a risk – and that includes buses,” Ruter director Bernt Reitan Jenssen told public broadcaster NRK.

“There is a risk that for example suppliers could take control, but also that other players could break into this value chain and influence the buses.”

Ruter said it was now developing a digital firewall to guard against the issue.

According to other reports, the Chinese manufacturer has access to each bus’s software updates, diagnostics, and battery control systems. “In theory, the bus could therefore be stopped or rendered unusable by the manufacturer,” the company said.

Ruter has reported its findings to Norway’s Ministry of Transport and Communications.

Arild Tjomsland, a special advisor at the University of South-Eastern Norway who helped conduct the tests, said: “The Chinese bus can be stopped, turned off, or receive updates that can destroy the technology that the bus needs to operate normally.”

[…]

  • Ek-Hou-Van-Braai@piefed.social
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    You can revert it to a older version though.

    With most cars you flash the ECU with software using a diagnostic tool, if you don’t like the new version you can just flash a older version on there.

    Or in many cases modify it and flash your custom version.

    You don’t have that control if it’s all Internet dependant, and there’s no kill switch.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      You can revert it to a older version though.

      if the maker allows it. try that with your smartphone and it will irreversibly turn into an expensive brick. look up android rollback protection

    • trollercoaster@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Unless you can (and actually do) audit the entire software, you can’t know whether there isn’t any kill switch in it. Even if it’s just a simple timer that will break shit once the warranty has expired. Or something that reacts to a seemingly innocuous external trigger.

      • Ek-Hou-Van-Braai@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 days ago

        And we can never make cars 100% safe. That doesn’t mean we shouldn’t care about seat-belts, airbags, ABS and crumple zones.

        Just because we can’t make the danger zero, doesn’t mean we shouldn’t do the bare minimum to mitigate the danger.

        • Maeve@kbin.earth
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          The Internet connection aspect can be made zero. Cars don’t really need computers.

        • trollercoaster@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 days ago

          Yes, and bare minimum is a good keyword, because sometimes, less is more. Especially when it comes to the amounts of software and connectivity. Complexity causes problems.

          I am old enough to have ridden on buses that did run exactly zero software. And you know what? Those things would just keep on working for decades, despite rolling all day long every day every week all year round.