frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A vulnerability that can be exploited to tamper with a train’s brakes

https://www.securityweek.com/train-hack-gets-proper-attention-after-20-years-researcher/
20•01-_-•6mo ago

Comments

bestouff•6mo ago
USA trying to make is public transport system even less popular.
persolb•6mo ago
I believe this is only used on one passenger line in the entire country. This is really a freight based system intended to transmit brake apply signals as speed of light instead of speed of sound.

Since passenger trains are usually short and often have a wired bus) they don’t really need this system.

senectus1•6mo ago
>“The End-of-Train (EOT) and Head-of-Train (HOT) vulnerability has been understood and monitored by rail sector stakeholders for over a decade. To exploit this issue, a threat actor would require physical access to rail lines, deep protocol knowledge, and specialized equipment, which limits the feasibility of widespread exploitation—particularly without a large, distributed presence in the U.S.

Sure, thats reaaaally unlikely hey... /S

kotaKat•6mo ago
While this is bad… keep in mind you can also stop trains with a jumper cable across the tracks, too.

https://hackaday.com/2016/12/14/protesters-use-jumper-cables...

persolb•6mo ago
Yeah. Exactly. The consequence of this club is either:

1) The brakes take an extra couple seconds to apply (note: this is only used on long trains… so stopping is over a minute anyway)

2) The emergency brakes apply. This is considered a safe condition, and for Positive Train Control is considered the ‘safe state’.

If someone tries to utilize this vulnerability, the EOT device will be shutoff. On the few tracks where it’s actually required, there are mitigations to still operate safely.

This would be really easy to annoy a single train crew. This would be really hard to do to geographically diverse trains.

BikDk•6mo ago
This looks like an exploit for all future train control systems (TCS)
IAmBroom•6mo ago
Does including a three-letter acronym (TLA) make your answer look informed (ALI)?

Because it's an article about outdated systems. Radio-controlled systems built in the last ten years, and in the future, are all mandated to be encrypted.

Furthermore, very few passenger train systems are radio-controlled. Instead, just like cars and buses, control is decentralized to the individual vehicle, and automated based on feedback from the track. No feedback, and the train stops.

BikDk•6mo ago
This ist a standard and ancient sender/receiver problem of communication. However, I'm glad you like big machines and seem interested enough to dive deeper into this topic. The official acronym TCS is still no match to your creativeness, please take it easy, as if you plan to do some research on this you will encounter a lot of those.
xtiansimon•6mo ago
Don’t know about today, but you used to be able to drop the gates with a nail.
marklubi•6mo ago
Shocking, not shocking. Worked for a company more than two decades ago that ran a lot of shortlines.

Called out several different vulnerabilities that I found while researching how to make things more efficient (the company owning the tracks get charged for the car lease while it's on their tracks).

Nothing came of it though. They were more worried about replacing infrastructure after several cars toppled because the ties had rotted.

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
209•theblazehen•2d ago•63 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
686•klaussilveira•15h ago•204 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
959•xnx•20h ago•553 comments

How we made geo joins 400× faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
127•matheusalmeida•2d ago•35 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
65•videotopia•4d ago•3 comments

Jeffrey Snover: "Welcome to the Room"

https://www.jsnover.com/blog/2026/02/01/welcome-to-the-room/
28•kaonwarb•3d ago•24 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
44•jesperordrup•5h ago•23 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
236•isitcontent•15h ago•26 comments

ga68, the GNU Algol 68 Compiler – FOSDEM 2026 [video]

https://fosdem.org/2026/schedule/event/PEXRTN-ga68-intro/
8•matt_d•3d ago•2 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
230•dmpetrov•15h ago•122 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
334•vecti•17h ago•146 comments

Where did all the starships go?

https://www.datawrapper.de/blog/science-fiction-decline
26•speckx•3d ago•16 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
499•todsacerdoti•23h ago•244 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
384•ostacke•21h ago•97 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
360•aktau•21h ago•183 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
295•eljojo•18h ago•186 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
421•lstoll•21h ago•280 comments

PC Floppy Copy Protection: Vault Prolok

https://martypc.blogspot.com/2024/09/pc-floppy-copy-protection-vault-prolok.html
67•kmm•5d ago•10 comments

Dark Alley Mathematics

https://blog.szczepan.org/blog/three-points/
95•quibono•4d ago•22 comments

Was Benoit Mandelbrot a hedgehog or a fox?

https://arxiv.org/abs/2602.01122
21•bikenaga•3d ago•11 comments

Delimited Continuations vs. Lwt for Threads

https://mirageos.org/blog/delimcc-vs-lwt
33•romes•4d ago•3 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
262•i5heu•18h ago•211 comments

Female Asian Elephant Calf Born at the Smithsonian National Zoo

https://www.si.edu/newsdesk/releases/female-asian-elephant-calf-born-smithsonians-national-zoo-an...
38•gmays•10h ago•13 comments

I now assume that all ads on Apple news are scams

https://kirkville.com/i-now-assume-that-all-ads-on-apple-news-are-scams/
1074•cdrnsf•1d ago•460 comments

Introducing the Developer Knowledge API and MCP Server

https://developers.googleblog.com/introducing-the-developer-knowledge-api-and-mcp-server/
61•gfortaine•13h ago•27 comments

Understanding Neural Network, Visually

https://visualrambling.space/neural-network/
294•surprisetalk•3d ago•45 comments

I spent 5 years in DevOps – Solutions engineering gave me what I was missing

https://infisical.com/blog/devops-to-solutions-engineering
153•vmatsiiako•20h ago•72 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
14•1vuio0pswjnm7•1h ago•1 comments

Why I Joined OpenAI

https://www.brendangregg.com/blog/2026-02-07/why-i-joined-openai.html
159•SerCe•11h ago•146 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
187•limoce•3d ago•103 comments