• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Claims that new signalling "could be hacked...."

Status
Not open for further replies.

route:oxford

Established Member
Joined
1 Nov 2008
Messages
4,949
There's always talk of this sort of thing whether it is planes or trains, next will be the auto drive automobiles :)

Or pacemakers...

(Reuters) - Barnaby Jack, a celebrated computer hacker who forced bank ATMs to spit out cash and sparked safety improvements in medical devices, died in San Francisco, a week before he was due to make a high-profile presentation at a hacking conference.

The New Zealand-born Jack, 35, was found dead on Thursday evening by "a loved one" at an apartment in San Francisco's Nob Hill neighborhood, according to a police spokesman. He would not say what caused Jack's death but said police had ruled out foul play.

The San Francisco Medical Examiner's Office said it was conducting an autopsy, although it could be a month before the cause of death is determined.

Jack was one of the world's most prominent "white hat" hackers - those who use their technical skills to find security holes before criminals can exploit them.

His genius was finding bugs in the tiny computers embedded in equipment, such as medical devices and cash machines. He often received standing ovations at conferences for his creativity and showmanship while his research forced equipment makers to fix bugs in their software.

Jack had planned to demonstrate his techniques to hack into pacemakers and implanted defibrillators at the Black Hat hackers convention in Las Vegas next Thursday. He told Reuters last week that he could kill a man from 30 feet away by attacking an implanted heart device.

http://www.reuters.com/article/2013/07/26/us-hacker-death-idUSBRE96P0K120130726
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

RichardN

Member
Joined
29 Nov 2013
Messages
430
No they aren't!!
Unless you can explain how a lower quadrant semaphore signal can do that.

I think we're talking at slightly cross purposes. I didn't say it was connected unsafely to the signalling equipment.

http://nrodwiki.rockshore.net/index.php/S_Class_Messages

Describes a message queue that receives information about signal state changes. It cannot do that unless it is connected to said equipment, though that connection can (and should) be read only.
 

Yabbadabba

Member
Joined
23 May 2014
Messages
385
Signalling systems are already connected to the web, how else would the maps at opentraintimes work?

I'd take a guess that it somebody armed with nothing more than cable and crocodile clips could cause a lot of disruption in track circuit areas anyway...

Train describes are not connected to the interlocking and the fact that we can and do run trains with the train describer compleatly failed is proof of that. The information they give out is beacuse they run from imputs from our indication circuits and that's not safety critical either, as we can still run trains with all indications failed by other means. All this means is that TRUST, CCF, PIS, opentraintimes and all other such like information systems just lose there information feeds but the trains still run.
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,489
Location
Powys
I think we're talking at slightly cross purposes. I didn't say it was connected unsafely to the signalling equipment.

http://nrodwiki.rockshore.net/index.php/S_Class_Messages

Describes a message queue that receives information about signal state changes. It cannot do that unless it is connected to said equipment, though that connection can (and should) be read only.

You said:
Signalling systems are already connected to the web, how else would the maps at opentraintimes work?

Well sorry but they all are not, in any way.
There is no connection between the lower quadrant signals or their mechanical interlocking at my signal box and anything that is connected to the internet.
The ONLY internet access in my signal box is the TRUST computer we use to submit times. Nothing else!

And as someone who has had dealings with ERTMS and the staff at Machy I can assure you that there is no internet access through with their equipment either. I wish people on here would do some proper research and not jump to conclusions.
ERTMS is a lot more complex than many think they understand and even an "inside" job would require a vast amount of reprogramming at lots of different levels. ERTMS is not a pyramidical programme structure but cross referenced, multi-level, interwoven complex structure.
 

Class 170101

On Moderation
Joined
1 Mar 2014
Messages
8,662
Most criminals are after money so attacking there railway wouldn't appeal to them. It would most likely be state sponsored.
I can think of one type of group who wouldn't be state sponsored but 'hacking' the railway might appeal to cause a train crash.

ISIS and such similar groups - lots of media coverage without having to find bomb making equipment.
 

RichardN

Member
Joined
29 Nov 2013
Messages
430
You said:
Signalling systems are already connected to the web, how else would the maps at opentraintimes work?

Well sorry but they all are not, in any way.
There is no connection between the lower quadrant signals or their mechanical interlocking at my signal box and anything that is connected to the internet.
The ONLY internet access in my signal box is the TRUST computer we use to submit times. Nothing else!

And as someone who has had dealings with ERTMS and the staff at Machy I can assure you that there is no internet access through with their equipment either. I wish people on here would do some proper research and not jump to conclusions.
ERTMS is a lot more complex than many think they understand and even an "inside" job would require a vast amount of reprogramming at lots of different levels. ERTMS is not a pyramidical programme structure but cross referenced, multi-level, interwoven complex structure.

I didn't say your lower quadrant signal was connected to the internet. I said signalling systems were. The train describer is connected to signalling, and state changes in the train describer are sent via message queues into software that displays maps and sometimes signal aspect on the internet. I never said it was possible to amend any state from the internet, merely that there is a connection.
 

Jamesb1974

Member
Joined
20 Mar 2006
Messages
596
Aren't we all overlooking a very important component here? Ie, the driver?

Regardless of whether a theoretical 'hack' could take place, you still have someone at the front controlling the speed of the train. Drivers sign the routes they travel over, so they know what signal aspects to expect at certain locations. If you are expecting to a single yellow, followed by a red and a number four route indicator that is pulled off as you approach but instead get a (hacked) green, you are hardly likely to just whack open the power handle and career along the wrong route thinking, "It'll be ok".

And there are speed limits and interlocking to contend with, not to mention AWS and TPWS. Realistically speaking, any terrorist worth his fiendish salt would want to maximise the casualties and look to engineer an accident at a major station or high speed junction. It would take a lot less effort to just derail a train with an obstacle and hope for the worst than it would to hack systems, defeat mechanical and electrical interlocking and time it all so that the two trains you wanted hit each other.

Even if there was some attempt to hack into a system like ERTMS and engineer a head on crash between two trains, the actual effort to do such a thing would be outweighed by the chance that someone (ie the drivers) have the ability to undo all your dastardly supervillain work and make the trains stop.

Until we have fully automated trains (about the same time that Hoverboards and Johnny Cabs become the primary mode of transport in cities), we'll have the person at the front who can make the train stop.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,716
Location
Scotland
Aren't we all overlooking a very important component here? Ie, the driver?
While I agree with the sentiment of your post, in the higher levels of ERTMS there are no lineside signals so it might be easier to 'arrange' an accident.
 

Jamesb1974

Member
Joined
20 Mar 2006
Messages
596
While I agree with the sentiment of your post, in the higher levels of ERTMS there are no lineside signals so it might be easier to 'arrange' an accident.

Yes, levels 2 and 3. But my point remains that you'd achieve the same result (as a terrorist/attacker) by parking a car on a level crossing or throwing a lump of scrap rail across the four foot.

To 'arrange' an accident you are talking about hacking into the system in its entirety, not just one component part. Lots of very clever people get paid vast amounts of money to ensure that systems like ERTMS don't turn turtle when one part fails (or is hacked). Just hacking one part isn't going to do much good when the rest of the system has been designed to communicate in a designated way and to have safety backups and fail safes. The UK railway system is one of the safest in the world. I can't imagine that we are going to throw that away by implementing a signalling system that is open to hacking.
 
Last edited:

Yabbadabba

Member
Joined
23 May 2014
Messages
385
I didn't say your lower quadrant signal was connected to the internet. I said signalling systems were. The train describer is connected to signalling, and state changes in the train describer are sent via message queues into software that displays maps and sometimes signal aspect on the internet. I never said it was possible to amend any state from the internet, merely that there is a connection.

The train describer is not connected to the signalling it just works off the indications. It doesn't talk to the interlocking, it's not connected to the interlocking. It's a stand alone computer that basically in a simplistic way just reads our diagrams and move decriptions around.
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,489
Location
Powys
I didn't say your lower quadrant signal was connected to the internet. I said signalling systems were. The train describer is connected to signalling, and state changes in the train describer are sent via message queues into software that displays maps and sometimes signal aspect on the internet. I never said it was possible to amend any state from the internet, merely that there is a connection.

OFGS!!
Read what you said again.

I do not have a train describer!!
Not all signal boxes have train describers!!
The signalling system on the line I work does NOT connect with the internet!!

I do wish people on here, with no connection with the railway other than being fanatics, would do some proper research.
 
Last edited:

RichardN

Member
Joined
29 Nov 2013
Messages
430
I said signalling systems are already connected to the web. Not ALL signalling systems. I assume that you don't disagree that a signal aspect shown on the opentraintimes map is originally taken from a connection to signalling equipment.
--- old post above --- --- new post below ---
The train describer is not connected to the signalling it just works off the indications. It doesn't talk to the interlocking, it's not connected to the interlocking. It's a stand alone computer that basically in a simplistic way just reads our diagrams and move decriptions around.

Your indications are connected to signalling equipment. The only other way is to have double pole electrical switches and completely parallel system, which would be possible, but arguably still connected mechanically...
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,489
Location
Powys
I said signalling systems are already connected to the web. Not ALL signalling systems. I assume that you don't disagree that a signal aspect shown on the opentraintimes map is originally taken from a connection to signalling equipment.
--- old post above --- --- new post below ---


Your indications are connected to signalling equipment. The only other way is to have double pole electrical switches and completely parallel system, which would be possible, but arguably still connected mechanically...

God!! How many more times do I need to say this?

There is NO connection between the signals at my signal box and anything connected to the internet or even the telephone system!!

No signal aspects at my signal box are shown on some spurious external web site, or even on an official NR web site, as they have no connections to the 'net or the telephone system!!

None of the signals at my signal box have "indicators"!!

None of my signals have electronic interlocking!! It is all mechanical other than an internal, un-linked, unconnected system, to 2 short track circuits for the level crossing.

The only internet access in my box is the TRUST computer that has NO connection to any of the mechanical signalling system!!

Sorry but you obviously do not understand how our signalling works, and most definitely how ERTMS works!!
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,587
Location
Torbay
I said signalling systems are already connected to the web. Not ALL signalling systems. I assume that you don't disagree that a signal aspect shown on the opentraintimes map is originally taken from a connection to signalling equipment.

In a modern interlocking system, the indicated states of track circuits, signals and points are exported in real time via a one-way port from the interlocking computers into the separate control centre equipment. At the control centre, a train describer subsystem interprets those inputs to generate and display the train describer tracking information on the signallers' screens.

TD data from control centres and signal boxes networkwide is aggregated in national information systems and then published via various interfaces to all kinds of downstream systems such as station CIS and the open data service used by realtime trains and other online services. There is no way that the TD interface or any of it's downstream derivative data feeds could be used 'backwards' to even send a route setting request to the interlocking, let alone cause the interlocking to actually cause an unsafe command to be sent to the trackside equipment. The nature of the system design simply does not allow it.
 

RichardN

Member
Joined
29 Nov 2013
Messages
430
God!! How many more times do I need to say this?

There is NO connection between the signals at my signal box and anything connected to the internet or even the telephone system!!

No signal aspects at my signal box are shown on some spurious external web site, or even on an official NR web site, as they have no connections to the 'net or the telephone system!!

None of the signals at my signal box have "indicators"!!

None of my signals have electronic interlocking!! It is all mechanical other than an internal, un-linked, unconnected system, to 2 short track circuits for the level crossing.

The only internet access in my box is the TRUST computer that has NO connection to any of the mechanical signalling system!!

Sorry but you obviously do not understand how our signalling works, and most definitely how ERTMS works!!

The your, was not intended for you, but the forum joined two posts. What started this was somebody saying some idiot decides to connect a system to to the internet. I was pointing out that (some of them) already are. I know that the link is read only by hardware design and is perfectly safe. There is no reason why a similarly safe set of interfaces couldn't be provided to any other system (signalling or otherwise) that exports read only data.
 

tranzitjim

Member
Joined
4 Jun 2013
Messages
211
Location
Australia
In the old way, you had to be on the site, and be physical at the location. And by doing so, you could only impact one section of the network.

Modern CCTV and other security can detect such breaches as they happen.


A computer system on the other hand, can be hacked by anyone from anywhere in the world, from the comfort of their home. And, they can impact on the whole system all at once.

For that, I would prefer the old system over the new.
 

NSEFAN

Established Member
Joined
17 Jun 2007
Messages
3,518
Location
Southampton
tranzitjim, did you read the earlier posts? It's not like signals would be controlled via a staff portal at networkrail.com . The chap raising concerns himself states that a bigger problem is a rogue member of staff rather than a randomer on his sofa at home.
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,489
Location
Powys
tranzitjim, did you read the earlier posts? It's not like signals would be controlled via a staff portal at networkrail.com . The chap raising concerns himself states that a bigger problem is a rogue member of staff rather than a randomer on his sofa at home.

And those of us who know how ERTMS works say that will be impossible!
 

jopsuk

Veteran Member
Joined
13 May 2008
Messages
12,774
far easier to just put something solid into the path of a train travelling at speed...
 

martynbristow

Member
Joined
15 Jun 2005
Messages
426
Location
Birkenhead
You said:
Signalling systems are already connected to the web, how else would the maps at opentraintimes work?

Well sorry but they all are not, in any way.
There is no connection between the lower quadrant signals or their mechanical interlocking at my signal box and anything that is connected to the internet.
The ONLY internet access in my signal box is the TRUST computer we use to submit times. Nothing else!

And as someone who has had dealings with ERTMS and the staff at Machy I can assure you that there is no internet access through with their equipment either. I wish people on here would do some proper research and not jump to conclusions.
ERTMS is a lot more complex than many think they understand and even an "inside" job would require a vast amount of reprogramming at lots of different levels. ERTMS is not a pyramidical programme structure but cross referenced, multi-level, interwoven complex structure.

I can think of one type of group who wouldn't be state sponsored but 'hacking' the railway might appeal to cause a train crash.

ISIS and such similar groups - lots of media coverage without having to find bomb making equipment.
Read the above quote. ISIS may or may not be state sponsored but that's an aside.
The system would be very expensive to hack and most people won't have the resources. It also depends on what interfaces are open.
No door is more secure than a locked door!
 

dggar

Member
Joined
16 Apr 2011
Messages
472
Read the above quote. ISIS may or may not be state sponsored but that's an aside.
The system would be very expensive to hack and most people won't have the resources. It also depends on what interfaces are open.
No door is more secure than a locked door!

surely as far as security goes a door can only be Locked or Unlocked.

When viewing the images from Hatton Garden you can always just go through the wall if the door is locked.
 

carriageline

Established Member
Joined
11 Jan 2012
Messages
1,897
surely as far as security goes a door can only be Locked or Unlocked.



When viewing the images from Hatton Garden you can always just go through the wall if the door is locked.


Which is the entire point of this. Instead of spending the time and money hacking this, they could just have someone in the ROC, break in to a sig center or a train, or chuck something on the track.
 

Jamesb1974

Member
Joined
20 Mar 2006
Messages
596
ISIS and such similar groups - lots of media coverage without having to find bomb making equipment.

Given the nature of all the previous Islamist terror attacks (nearly all bomb or gun attacks http://en.wikipedia.org/wiki/List_of_Islamist_terrorist_attacks), the chances of an attack by hacking into ERTMS is extremely unlikely.

A lot of what these terror groups or individuals seek in their attacks is to cause as many deaths as possible, cause mass panic in the civilian population while simultaneously gaining wide media coverage. Think of the Woolwich attack on Lee Rigby. Totally crude in the way it was conducted, but done in order to cause panic, revulsion and gain as much press coverage as possible.

Why would a terror group go to the extreme lengths of obtaining the equipment and expertise to hack ERTMS (at every level, including the trains) just to cause a collision, when setting off a well placed bomb could cause far more devestation? And, given the structural strength of modern rolling stock, you'd probably cause far less deaths in a staged crash than by attacking a soft target.

I'm not saying that systems like ERTMS are un-hackable (mainly because I don't know if they are or not), but what I am saying is that terrorists tend to go for easy targets that have the best chance of success and the least chance of being disrupted prior to execution. Spending months hacking into ERTMS has the potential for discovery at every step and a very poor effort to effect ratio at the end of it. I think talk of a James Bond like cyber attack is just fantasy. Sadly, a crude explosive device in a public place is a very real proposition.
 
Last edited:

PermitToTravel

Established Member
Joined
21 Dec 2011
Messages
3,042
Location
Groningen
Precisely. Even then, hacking the signalling system won't allow an 'unsafe' movement to be executed im sure (unless you could dial into a points module and tell it to move at exactly the right time, but I'm not sure if that's even possible!!)

It's nothing really new, SSI equipment has been attached to the "internet" for a while now. Gaining access to somewhere, or doing damage on the ground is probably far easier than this hacking business :lol:

Yes, the easiest way for terrorists to dial into a points module will continue to be a points lever.
 

Baggypants

Member
Joined
24 Jul 2013
Messages
44
Useful update on the report here http://www.theregister.co.uk/2015/04/30/uk_rail_comms_safety_analysis/

The main thrust of the article is that most Northern European rail systems are converging on a standard and that need to be carefully observed and secured. There is an interesting link in the article about Moscow traffic monitoring.

For an example of the type of attacks the security boffins are talking about there is a nice simple example about possibly building monitoring into the hardware used in domestic ADSL routers.

http://www.revk.uk/2015/04/back-doors.html

I notice some people have minimised the idea of state sponsored hacking against the infrastructure of the British Railway but I'd suggest you're lacking imagination. Consider that if you're a state that manufactures equipment for another large collection of currently-wealthy-but-ideologically-opposed-in-some-policies nations and you're unsure how some those nations are going to behave towards you in the future you might want to ensure you have some Ace's up your sleeve.

Let's say the South China Sea dispute got rather serious and Europe and the US looked to mobilise a peacekeeping force (unlikely given the result of the Crimea but bear with me, Crimea doesn't make cheap T-Shirts). Disrupting transport and communications on a large scale (larger than one truck next to one line would achive) would be rather an important thing on your TODO.
 
Last edited:

Busaholic

Veteran Member
Joined
7 Jun 2014
Messages
14,671
So a guy from a bedroom in Hounslow is fighting extradition to USA charged with bringing down the American banking system but it's impossible/unlikely for anyone to hack into the UK signalling system?! I admit it's about as unlikely as a pilot choosing to deliberately crash his plane taking all his passengers and co-workers with him. Yes, right, think on. We're British, it can't possibly happen to us, being in denial is the national trait, among the English at least, hence UKIP.
 

carriageline

Established Member
Joined
11 Jan 2012
Messages
1,897
So a guy from a bedroom in Hounslow is fighting extradition to USA charged with bringing down the American banking system but it's impossible/unlikely for anyone to hack into the UK signalling system?! I admit it's about as unlikely as a pilot choosing to deliberately crash his plane taking all his passengers and co-workers with him. Yes, right, think on. We're British, it can't possibly happen to us, being in denial is the national trait, among the English at least, hence UKIP.


Two very different systems, that works in two very different ways.

No one said it's impossible, but a Seeing as the workstations are not linked to the Internet in the normal sense (AIUI), then it must be pretty hard.

Hence why it's more likely to be socially engineered, or some sort of inside job.
 

petersi

Member
Joined
24 Apr 2012
Messages
453
Plus the Hounslow guy did not hack.
His Access to the computer was legal what he did with access was illegal
 

AngusH

Member
Joined
27 Oct 2012
Messages
598
If we're talking about the man currently facing extradition, I'm not even entirely convinced that what he did was illegal.

The event was bad for the market as a whole, but I've also seen doubt cast as to whether he was actually responsible or merely a convenient scapegoat.

I'm not convinced there are any parallels between that and signalling, which would be more equivalent to industrial systems cracking, which happens occasionally

e.g
http://www.theregister.co.uk/2014/12/22/hackers_pop_german_steel_mill_wreck_furnace/

Though in a strict sense, even that was a human error, allegedly:

... was pulled off after a victim fell for a phishing email.
 
Last edited:
Status
Not open for further replies.

Top