Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Wednesday, July 16th, 2025

    Time Event
    7:15p
    Hacking Trains

    Seems like an old system system that predates any care about security:

    The flaw has to do with the protocol used in a train system known as the End-of-Train and Head-of-Train. A Flashing Rear End Device (FRED), also known as an End-of-Train (EOT) device, is attached to the back of a train and sends data via radio signals to a corresponding device in the locomotive called the Head-of-Train (HOT). Commands can also be sent to the FRED to apply the brakes at the rear of the train.

    These devices were first installed in the 1980s as a replacement for caboose cars, and unfortunately, they lack encryption and authentication protocols. Instead, the current system uses data packets sent between the front and back of a train that include a simple BCH checksum to detect errors or interference. But now, the CISA is warning that someone using a software-defined radio could potentially send fake data packets and interfere with train operations.

    << Previous Day 2025/07/16
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org