this post was submitted on 05 Nov 2025
263 points (97.5% liked)

Cybersecurity

8584 readers
123 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
 

different source (Danish)

It's no surprise, as kill switches are pretty much ubiquitous.

you are viewing a single comment's thread
view the rest of the comments
[–] HobbitFoot@thelemmy.club 56 points 3 days ago (3 children)

Killswitches may be common, but it is major security implications if infrastructure is sold with them without the buyer knowing about them, which appears to the case here.

It also makes a case to not buy hardware from China if their manufacturers install these killswitches and don't notify their owners.

[–] Alcoholicorn@mander.xyz 17 points 3 days ago* (last edited 3 days ago) (3 children)

There's no kill switch, the bus uses OTA updates like 95% of new buses, and soon 100% that could conceivably be used as a kill switch.

The article lies by omission.

[–] floofloof@lemmy.ca 27 points 3 days ago (2 children)

One form of lying by omission is not to discuss whether this is unique or unusual to Chinese vehicles.

[–] HobbitFoot@thelemmy.club 21 points 3 days ago (2 children)

Similar backdoor control capabilities, usually at least officially frowned upon in Western tech companies, weren’t found in buses bought from Dutch company VDL.

Looks like that was discussed in the article.

[–] fort_burp@feddit.nl 7 points 3 days ago (2 children)

No I think floofloof meant that the article doesn't point out that Tesla and John Deere products have that same feature.

Common John Deere L

[–] stray@pawb.social 2 points 3 days ago* (last edited 3 days ago)

It specifically mentions Tesla and John Deere in the article.

[–] Alcoholicorn@mander.xyz 3 points 3 days ago (2 children)

I looked up the top 5 bus manufacturers in Europe, accounting for a combined 80-90% of new buses.

All of them use OTA updates.

The author picks a very unusual bus without telling the reader to make the reader believe this is a chinese problem and not standard practice in 2025.

[–] yetAnotherUser@discuss.tchncs.de 9 points 3 days ago (1 children)

There's a difference between consensual OTA updates (meaning the bus company would manually need to confirm the update) and non-consensual OTA updates (meaning it is done regardless of the bus company's wishes).

The Chinese buses are capable of the latter which is a gigantic security vulnerability. You do not want any operating system anywhere to update itself without consent.

[–] Alcoholicorn@mander.xyz 1 points 3 days ago (1 children)

Does Iveco(41%) or any other manufacturer with a meaningful market share do that?

[–] stray@pawb.social 3 points 3 days ago (1 children)
[–] Alcoholicorn@mander.xyz 1 points 2 days ago

Operators of the chinese bus can pull the SIM card and reinsert it as desired as mentioned in the article, I'm not sure there is a meaningful difference if that is how the Iveco works.

[–] stray@pawb.social 1 points 3 days ago

You obviously didn't read the article because the author talks about non-Chinese products as well. They specifically describe a possible future where Trump disables all Danish iPhones. It has nothing to do with China and everything to do with the problem of "smart" devices and how little control we have over our own possessions.

[–] stray@pawb.social 7 points 3 days ago

Vi skal vænne os til, at hvis du køber en amerikansk Tesla eller kinesisk BYD, kan den – i hvert fald i teorien – i morgen godt være en ubrugelig klods på omkring et ton bilskrald, der bare holder ude i din indkørsel. Det samme, hvis du køber iPhone eller en mobiltelefon fra Huawei eller for den sags skyld en europæisk telefon.

Translating very loosely because I don't actually speak Danish:

If you buy an American Tesla or Chinese BYD it can in theory be bricked tomorrow. Same if you buy an iPhone, Hwawei, or even a European phone.

Other countries, brands, and varieties of products are also discussed throughout the article.

[–] 6nk06@sh.itjust.works 2 points 3 days ago

There's no kill switch

You cannot know that, and it's a big problem.

[–] stray@pawb.social 0 points 3 days ago

How is it lying by omission why it describes exactly what you said?

Anyone who installs kill switches in shit they sell should be legal to kill.

[–] orioler25@lemmy.world 2 points 3 days ago

Yeah, imagine if a signiticant portion of crucial infrastructure was owned by a foreign party eh