Monday, August 28, 2023

The “cyberattack” on Poland's railway "doesn't seem to have involved any cyber at all"

Wired:

On Friday and Saturday, August 25 and 26, more than 20 of Poland's trains carrying both freight and passengers were brought to a halt across the country through what Polish media and the BBC have described as a “cyberattack.” Polish intelligence services are investigating the sabotage incidents, which appear to have been carried out in support of Russia. The saboteurs reportedly interspersed the commands they used to stop the trains with the Russian national anthem and parts of a speech by Russian president Vladimir Putin.

...

Because the trains use a radio system that lacks encryption or authentication for those commands, Olejnik says, anyone with as little as $30 of off-the-shelf radio equipment can broadcast the command to a Polish train—sending a series of three acoustic tones at a 150.100 megahertz frequency—and trigger their emergency stop function.

...

the ability to send the command has been described in Polish radio and train forums and on YouTube for years