Polish Hackers that repaired DRM trains threatened by train company

A Polish train manufacturer is accused of secretly installing software “lockouts” that disabled trains serviced by independent workshops, until hackers hired by a rail operator reverse engineered the code and restored operation. Commenters debate whether this constitutes illegal DRM circumvention or lawful repair under EU rules, and note that EU law increasingly protects decompilation for interoperability and bug fixing. The case is framed as a broader test of right-to-repair, safety and sabotage of critical infrastructure, and the power imbalance between equipment makers and those who own and maintain their products.

Legal status of reverse engineering and DRM in the EU

  • Several comments argue that EU and Polish law clearly allow reverse engineering and decompilation of software you own for repair, error correction, or interoperability (citing the EU Computer Programs Directive and recent CJEU rulings).
  • Others emphasize that EU law on DRM/“technological measures” can still create legal risk, especially around using or publishing extracted information beyond strict interoperability/bug-fixing purposes.
  • There is debate over “copyright” vs “authors’ rights” in Europe; some say EU regimes differ significantly from US-style copyright, others think the practical differences are overstated.

Is this DRM or sabotage/extortion?

  • Many see the vendor’s hidden lockouts and geofencing of third‑party workshops as more like sabotage or ransomware than conventional DRM.
  • Commenters note trains are critical infrastructure; introducing secret kill switches or remote lock capabilities is characterized by some as an attack on national sovereignty or potential terrorism.
  • A minority insists that legality depends heavily on contract terms and EULAs, and that lawyers can still “make your life hell” regardless of technical legality.

Right-to-repair and ownership

  • Strong support for the idea that the train owner has the right to hire third parties, reverse engineer, and “jailbreak” equipment.
  • This case is used as a high‑impact example to argue for broader right‑to‑repair protections, including for life‑critical devices (ventilators, safety gear).
  • Some skepticism: a few accept DRM in principle, even on life‑saving devices, on the grounds of respecting IP and contracts.

Safety, liability, and contracts

  • One concern: unauthorized software access on public transport could be abused; others reply that access is authorized by the owner, so it’s not “unauthorized” in any meaningful sense.
  • EU rail rules reportedly require unbundling maintenance from manufacturers and obligate provision of sufficient documentation; if true, that undercuts the vendor’s position.
  • Several ask what the original procurement and maintenance contracts actually say; these details are currently unclear.

PR, legal backlash, and “cybercriminal” narrative

  • Many expect the manufacturer’s threats to backfire, amplifying scrutiny of its conduct and harming future sales.
  • The company’s claim that it was itself a victim of “cybercriminals” who supposedly inserted the lockout logic is widely ridiculed as implausible.
  • Some speculate that criminal charges (sabotage, interference with rail operations) against the manufacturer are possible, but outcomes remain uncertain.