The Train Bricks Itself If You Take It to a Rival Garage

Client
Rail operators / passengers
Role
Self-bricking / repair lockout
Stack
Newag Impuls, GPS anti-repair, Dragon Sector, anti-circumvention

The train bricks itself if you take it to a rival garage

Newag, the Polish train manufacturer, doesn’t just build locomotives. It sabotages them. Its locomotives are booby-trapped so that if they sense they’ve been taken to a rival service yard, the train bricks itself — locks its own software, refuses to run, and sits dead on the track.

Then the scam closes. The train operator calls Newag about the mysterious problem. Newag helpfully remotes into the locomotive’s computers to “perform diagnostics” — which is really just sending an unbricking command to the vehicle — for which they charge €20,000. It’s a self-inflicted ransom, paid every time a train needs to be serviced by anyone other than Newag.

The trap, exposed

The hack wasn’t subtle. When Polish repair shop SPS was called in to figure out why trains wouldn’t start, it found software that disabled the trains if they were anywhere near a repair facility that wasn’t run by Newag. Early versions counted days out of use — lock the train after ten idle days. Later versions added a GPS component that checked whether a train was near a known workshop location. One batch of trains even switched off automatically when passing through the Mińsk Mazowiecki station, stranding cars full of passengers.

It’s not just about the unlock fee. The reward for monopolizing the Impuls train service market was estimated at around $40 million a year. When a train’s manufacturer controls the only key, they control the entire aftermarket for servicing their own products.

The whistleblowers are now the defendants

Last year, Polish hackers from the security-research firm Dragon Sector presented their research on this racket at the Chaos Communication Congress — the very conference Cory Doctorow was speaking at when he told the story. And now Newag is suing them under anti-circumvention law for making true disclosures about Newag’s deliberately defective products.

Read that again. The company that installed software to break its own trains is suing the people who found and explained the sabotage — not because the hackers did anything wrong, but because anti-circumvention law makes studying and revealing that software itself a legal offense. The manufacturer gets to both commit the crime and pick who’s allowed to talk about it.

This is what anti-circumvention is for

This is the exact same legal weapon that let Volkswagen hide Dieselgate and that lets Medtronic hold ventilators hostage. Anti-circumvention law was sold as a shield for copyright, but its real customers are companies that want to weaponize the inability to inspect their own products. The moment you make it illegal to open the software in a thing you own, you make it legal for the manufacturer to do anything inside that software — and criminal for anyone to catch them.

“It’s DRM gone wild,” the hackers told Gizmodo. They didn’t sabotage the trains; they fixed them. And Newag is suing them for it.

The fix is the same across every one of these cases: legalize reverse engineering, and treat deliberately breaking your own product to extort service fees as the fraud it is. A train manufacturer that bricks its own trains to bill you €20,000 for the unbricking isn’t an accident. It’s the product.

Watch: Cory Doctorow, The Post-American Internet, 39C3