College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains — 19 years without crypto key rotation ends in predictable result as hacker sails through 7 layers of protection

Taiwan high speed rail line
(Image credit: Getty Images)

Techies and trains have always had a fairly close relationship, but some people seem to take that relationship to toxic levels. About a month ago, a 23-year-old Taiwanese student "hacked" the country's high-speed rail line using an SDR (Software-Defined Radio) filter and radios, remotely broadcasting a General Alarm sign, and triggering a manual emergency braking procedure.

The event brought four trains to a standstill for 48 minutes until the situation was verified as a false alarm, with reportedly no hard stops executed. Lin, the mind behind the operation, sailed through "seven verification layers" thanks to the fact that the TETRA (Terrestrial Trunked Radio) system in use hadn't had its cryptographic keys rotated in 19 years.

Latest Videos From

Lin reportedly also had information on how to access the comms of the New Taipei Fire City Department and the Taoyuan International Airport MRT Line. The incident triggered a round of political ping-pong to assess responsibilities for the weak security and a formal review of all aforementioned radio systems.

Democratic Progressive Party Legislator Ho Shin-chun clearly stated, "If a college student could hack into a system as sophisticated as that of the high-speed rail system, what would happen if the same thing happened with the Taiwan Railway Corp’s system?"

As for Lin, he's using the Looney Tunes defense that it was an accidental press of a button on the radio he had in his pocket. It would have been easy for him to conduct himself better and take the ethical route by disclosing the vulnerability to the relevant authorities, as Taiwan appears to have a highly progressive attitude towards civil hacking in all forms.

This is exemplified by the g0v initiative, which calls for open and transparent operations from regular citizens, an ethos that has official government support and was most useful during the COVID-19 pandemic. There's a yearly Presidential Hackathon, too, and Taiwan's National Institute of Cyber Security recently awarded $17,000 for 20 reported vulnerabilities across a range of products.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Bruno Ferreira
Contributor

Bruno Ferreira is a contributing writer for Tom's Hardware. He has decades of experience with PC hardware and assorted sundries, alongside a career as a developer. He's obsessed with detail and has a tendency to ramble on the topics he loves. When not doing that, he's usually playing games, or at live music shows and festivals.

  • 1_rick
    "Oh, sure, I programmed my Flipper Zero to send an emergency stop when I pressed a button, but I totes didn't mean to actually use it, I just did it for funsies!"

    That's like the guy in Florida several years ago that tried to rob a bank, and during the event, he dropped a gun he'd had in his pocket, and at trial tried to claim he didn't mean to use it so he shouldn't be subject to Florida's "automatic 10 years in jail for showing a gun during a violent crime" law.
    Reply
  • TechGuy_93
    This is Taiwan,
    They should be thanking him and offering him a consultancy or a job.
    Do they think if it had of been discovered by the Chinese they would have used it in such a manner?
    They would have targeted all systems they could and shut them down completely at the same time.
    Reply
  • 1_rick
    TechGuy_93 said:
    They should be thanking him and offering him a consultancy or a job.
    Gotta disagree. He could've tried to bring this to the attention of the railway authority first. Instead, he emergency stopped four trains from his home, where the police eventually tracked him down, as the article says.

    For that matter, if he just wanted to see if he could actually do anything, why not try something less potentially dangerous like changing a sign?
    Reply
  • USAFRet
    TechGuy_93 said:
    They should be thanking him and offering him a consultancy or a job.
    No.

    Having the skills is only part of it.
    A job in that realm would require one to not be an immature toolbag.
    Reply
  • Sluggotg
    TechGuy_93 said:
    This is Taiwan,
    They should be thanking him and offering him a consultancy or a job.
    Do they think if it had of been discovered by the Chinese they would have used it in such a manner?
    They would have targeted all systems they could and shut them down completely at the same time.
    Sorry, but I disagree. You don't hire a child molester to babysit your kids. You don't have a drug addict guard/inventory drugs.
    Integrity matters. Just because someone has a few skills does not make them a good employee or a good person.
    Reply
  • forestation
    TechGuy_93 said:
    This is Taiwan,
    They should be thanking him and offering him a consultancy or a job.
    Do they think if it had of been discovered by the Chinese they would have used it in such a manner?
    They would have targeted all systems they could and shut them down completely at the same time.
    By that logic if a bank robber exposes a faulty alarm system you'd reward them too?
    Reply
  • derekullo
    That was really funny
    We love your work!
    What's your name?

    Lin! ... aww crap

    "Hangs up"
    Reply