Bananabot (talk | contribs)
Added archive URLs for 18 citation(s) using CRWCitationBot
Bananabot (talk | contribs)
Added archive URLs for 3 citation(s) using CRWCitationBot
Line 8: Line 8:
|Logo=Newag Group logo.svg}}
|Logo=Newag Group logo.svg}}


'''{{wplink|Newag|Newag S.A.}}''' (pronounced ''"nevag"'') is a publicly traded<ref>https://www.gpw.pl/company-factsheet?isin=PLNEWAG00012</ref> Polish company based in {{wplink|Nowy Sącz}} that specializes in the production, maintenance, and modernization of railway rolling stock.<ref>https://www.newag.pl/en/company/history/ ([http://web.archive.org/web/20250120130623/https://www.newag.pl/en/company/history/ Archived])</ref> Their most notable products include: the families of electric locomotives '''Griffin'''<ref>https://www.newag.pl/en/offer/griffin/ ([http://web.archive.org/web/20250125122434/https://www.newag.pl/en/offer/griffin/ Archived])</ref><ref>https://twojsacz.pl/kolejne-lokomotywy-griffin-z-nowego-sacza-trafily-do-pkp-intercity/ ([http://web.archive.org/web/20251024145656/https://twojsacz.pl/kolejne-lokomotywy-griffin-z-nowego-sacza-trafily-do-pkp-intercity/ Archived])</ref> and '''Dragon''',<ref>https://www.newag.pl/en/offer/dragon/ ([http://web.archive.org/web/20250209153246/https://www.newag.pl/en/offer/dragon/ Archived])</ref> as well as the '''Impuls''' family of multiple units.<ref>https://www.newag.pl/en/offer/impuls/</ref>
'''{{wplink|Newag|Newag S.A.}}''' (pronounced ''"nevag"'') is a publicly traded<ref>https://www.gpw.pl/company-factsheet?isin=PLNEWAG00012</ref> Polish company based in {{wplink|Nowy Sącz}} that specializes in the production, maintenance, and modernization of railway rolling stock.<ref>https://www.newag.pl/en/company/history/ ([http://web.archive.org/web/20250120130623/https://www.newag.pl/en/company/history/ Archived])</ref> Their most notable products include: the families of electric locomotives '''Griffin'''<ref>https://www.newag.pl/en/offer/griffin/ ([http://web.archive.org/web/20250125122434/https://www.newag.pl/en/offer/griffin/ Archived])</ref><ref>https://twojsacz.pl/kolejne-lokomotywy-griffin-z-nowego-sacza-trafily-do-pkp-intercity/ ([http://web.archive.org/web/20251024145656/https://twojsacz.pl/kolejne-lokomotywy-griffin-z-nowego-sacza-trafily-do-pkp-intercity/ Archived])</ref> and '''Dragon''',<ref>https://www.newag.pl/en/offer/dragon/ ([http://web.archive.org/web/20250209153246/https://www.newag.pl/en/offer/dragon/ Archived])</ref> as well as the '''Impuls''' family of multiple units.<ref>https://www.newag.pl/en/offer/impuls/ ([http://web.archive.org/web/20250112104016/https://www.newag.pl/en/offer/impuls/ Archived])</ref>


==Anti-competitive practices==
==Anti-competitive practices==
In 2022, a regional Polish train operator commissioned a third-party repair service - '''SPS''' - to complete maintenance on Impuls trains<ref name=":0">https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/ ([http://web.archive.org/web/20260222173559/https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/ Archived])</ref>. The repair service could not, however, bring the trains to move despite them being in working order. This, alongside accusations of "interfering with the trains' security systems"<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=227 ([http://web.archive.org/web/20251231190317/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref> by Newag caused a tarnishing of SPS's reputation.<ref>https://www.youtube.com/watch?v=IXlYjgVpVIg ([https://preservetube.com/watch?v=IXlYjgVpVIg Archived])</ref><ref name=":0" /> In 2023, however, a group of Polish cybersecurity experts from Dragon Sector,<ref name=":0" /><ref>https://dragonsector.pl/ ([http://web.archive.org/web/20251228081649/https://dragonsector.pl/ Archived])</ref> after being hired by SPS, disclosed findings that a number of lock-up mechanisms were placed in the trains' software.<ref>https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure#t=691 ([http://web.archive.org/web/20260202053339/https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure Archived])</ref><ref>https://social.hackerspace.pl/@q3k/111528162462505087</ref><ref>https://arstechnica.com/tech-policy/2023/12/manufacturer-deliberately-bricked-trains-repaired-by-competitors-hackers-find/?utm_source=chatgpt.com ([http://web.archive.org/web/20251105052028/https://arstechnica.com/tech-policy/2023/12/manufacturer-deliberately-bricked-trains-repaired-by-competitors-hackers-find/?utm_source=chatgpt.com Archived])</ref> These allegedly include:
In 2022, a regional Polish train operator commissioned a third-party repair service - '''SPS''' - to complete maintenance on Impuls trains<ref name=":0">https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/ ([http://web.archive.org/web/20260222173559/https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/ Archived])</ref>. The repair service could not, however, bring the trains to move despite them being in working order. This, alongside accusations of "interfering with the trains' security systems"<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=227 ([http://web.archive.org/web/20251231190317/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref> by Newag caused a tarnishing of SPS's reputation.<ref>https://www.youtube.com/watch?v=IXlYjgVpVIg ([https://preservetube.com/watch?v=IXlYjgVpVIg Archived])</ref><ref name=":0" /> In 2023, however, a group of Polish cybersecurity experts from Dragon Sector,<ref name=":0" /><ref>https://dragonsector.pl/ ([http://web.archive.org/web/20251228081649/https://dragonsector.pl/ Archived])</ref> after being hired by SPS, disclosed findings that a number of lock-up mechanisms were placed in the trains' software.<ref>https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure#t=691 ([http://web.archive.org/web/20260202053339/https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure Archived])</ref><ref>https://social.hackerspace.pl/@q3k/111528162462505087 ([http://web.archive.org/web/20260129142943/https://social.hackerspace.pl/@q3k/111528162462505087 Archived])</ref><ref>https://arstechnica.com/tech-policy/2023/12/manufacturer-deliberately-bricked-trains-repaired-by-competitors-hackers-find/?utm_source=chatgpt.com ([http://web.archive.org/web/20251105052028/https://arstechnica.com/tech-policy/2023/12/manufacturer-deliberately-bricked-trains-repaired-by-competitors-hackers-find/?utm_source=chatgpt.com Archived])</ref> These allegedly include:


#'''A "lack of movement timer"''', which would disable the train after it has not moved for a set amount of time.<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1625 ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>
#'''A "lack of movement timer"''', which would disable the train after it has not moved for a set amount of time.<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1625 ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>
#'''Geofencing''' - the train would disable itself once it detects that it is in one of Newag's competitors' workshops.<ref>[https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1685 https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1713] ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref><ref name=":1">https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure#t=1293 ([http://web.archive.org/web/20260116035645/https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure Archived])</ref><ref>https://social.hackerspace.pl/@q3k/111528162462505087</ref>
#'''Geofencing''' - the train would disable itself once it detects that it is in one of Newag's competitors' workshops.<ref>[https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1685 https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1713] ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref><ref name=":1">https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure#t=1293 ([http://web.archive.org/web/20260116035645/https://media.ccc.de/v/38c3-we-ve-not-been-trained-for-this-life-after-the-newag-drm-disclosure Archived])</ref><ref>https://social.hackerspace.pl/@q3k/111528162462505087 ([http://web.archive.org/web/20260129142943/https://social.hackerspace.pl/@q3k/111528162462505087 Archived])</ref>
#'''Serializing''' the CAN bus extension device of the train, disabling it if a change in the CAN's serial number is detected.<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1814 ([http://web.archive.org/web/20251231190317/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>
#'''Serializing''' the CAN bus extension device of the train, disabling it if a change in the CAN's serial number is detected.<ref>https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1814 ([http://web.archive.org/web/20251231190317/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>
#'''A date check,''' which would cause the train to lock up if it was not serviced by Newag before the 21st of November 2022, claiming compressor failure.<ref name=":2">https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1891 ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>
#'''A date check,''' which would cause the train to lock up if it was not serviced by Newag before the 21st of November 2022, claiming compressor failure.<ref name=":2">https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains#t=1891 ([http://web.archive.org/web/20260218204654/https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains Archived])</ref>