Dieselgate, but for trains – some heavyweight hardware hacking

A Polish train maker is accused of embedding hidden “digital sabotage” in its locomotives, allegedly bricking trains if they spend time at rival maintenance depots or reach certain dates, in order to force operators back to its own, more expensive service contracts. Commenters see this as going beyond ordinary vendor lock‑in into potential criminal obstruction of critical infrastructure, drawing comparisons with Dieselgate, John Deere’s repair restrictions, and Boeing’s software failures. The case fuels broader concerns about opaque, safety‑critical firmware, weak regulatory oversight, and whether open or escrowed source code and stricter liability rules are needed for public infrastructure systems.

Alleged sabotage mechanisms

  • Firmware contained multiple lockout schemes:
    • GPS-based logic that disabled trains after ~10 days at specific coordinates corresponding to third‑party maintenance depots.
    • Time‑based logic that triggered fake compressor failures around maintenance dates.
    • Hidden reset sequences known only to the manufacturer.
  • Commenters stress this goes beyond obscurity/DRM into actively engineering false failures and immobilization.
  • Some skeptics argue context is missing (full codebase, entire 20k‑page manual set), but others note the presence of competitor GPS coordinates in firmware as inherently damning.

Vendor lock‑in and financial motives

  • Strong consensus that the goal was to sabotage a cheaper competitor’s maintenance contract and force work back to the OEM.
  • Maintenance on rolling stock is described as a long‑term, high‑margin revenue stream (“subscription money”), sometimes exceeding initial sale value.
  • Some highlight that tender rules explicitly required trains to be maintainable by third parties, making hidden lockouts especially egregious.

Legal, ethical, and responsibility debates

  • Many label this as sabotage, fraud, or even critical‑infrastructure interference; Polish penal code article on obstructing rail operations is cited.
  • Disagreement on likely outcomes:
    • Some expect serious criminal cases and possibly jail time.
    • Others predict mainly civil breach‑of‑contract claims and fines, citing the difficulty of pinning intent on individuals in a corporate hierarchy.
  • Discussion about who is “responsible”: individual engineers vs managers vs “the company as a whole,” with suggestions of investigating repos, change logs, and internal comms.

Software quality and safety concerns

  • Broader criticism of modern train firmware: long boot times, crashes on direction changes, and general unreliability compared with older, simpler rolling stock.
  • Root causes suggested:
    • Management cultures treating software as an afterthought.
    • Underpaid, under‑tooled embedded/PLC programming practices.
    • Increasing complexity and poor interoperability between systems and fleets.
  • Some argue that adding software to previously mechanical systems frequently reduces reliability and maintainability.

Open source, transparency, and regulation

  • Many see this as a “right to repair” and transparency failure.
  • Proposals:
    • Mandatory source or at least binary escrow for public‑infrastructure systems.
    • Government or independent bodies compiling firmware via reproducible builds and verifying deployed binaries.
    • Contractual requirements that public rolling stock come with full code access and tooling.
  • Counterpoint: malicious OEMs could still ship different code than they submit, but transparency is viewed as a strong deterrent.

Comparisons to other cases

  • Compared variously to:
    • Dieselgate (hidden context‑dependent firmware behavior).
    • John Deere/Apple DRM and repair lockouts (but here with faked failures and safety‑critical infrastructure).
    • Boeing 737 MAX (management‑driven software malfeasance).
  • Several argue Deere‑style vendor‑lock‑in is the closer analogy than emissions cheating.

Polish and systemic context

  • Frustration that Polish regulators were slow to act; some view this as evidence of local corruption or regulatory capture.
  • Others place it in a global frame: the West is still relatively less corrupt, but private‑sector scandals often fall outside classic corruption indices.