neils Profile
neils

@midwestneil

Followers
992
Following
2K
Media
6
Statuses
531

Hardware Security Research | Radio | Data Centers

Joined December 2024
Don't wanna be here? Send us removal request.
@midwestneil
neils
3 days
The Railroads don't want you to know about this one hack that can crash the American economy:.
@ive_m5
M5IVE
3 days
Watching this now . CC @SenTedCruz @SecDuffy @BrendanCarrFCC . DEF CON 26 WIRELESS VILLAGE - Eric Reuter - Introduction to Railroad Tel. via @YouTube.
1
0
8
@midwestneil
neils
3 days
RT @OndasHoldings: 🔒 Rail safety starts with secure networks. Legacy wireless systems weren’t built for today’s cyber threats. IEEE 802.16t….
0
18
0
@midwestneil
neils
5 days
RT @Mayhem4Markets: Oh that sounds tremendous
Tweet media one
0
7
0
@midwestneil
neils
5 days
AAR's probable take "guys, we just happen to be upgrading radio technology. totally unrelated to anything else".
@Gizmodo
Gizmodo
5 days
Hackers Can Tamper With Train Brakes Using Just a Radio, Feds Warn
1
0
15
@midwestneil
neils
5 days
The statement from @AAR_FreightRail on this vulnerability is a master class on not acknowledging the vulnerability is real thus avoiding liability, and instead skips right over to "the devices are being replaced". WHY ARE THEY BEING REPLACED THEN??.
@ive_m5
M5IVE
5 days
CISA Issues EoT, HoT Device Advisory
0
0
9
@midwestneil
neils
5 days
A lot of words to say - "low attack complexity"
Tweet media one
1
0
17
@midwestneil
neils
5 days
RT @CeoOndas:
0
59
0
@midwestneil
neils
6 days
>ignores critical infrastructure vulnerability for 20years . "we're really committed to safety" 💀.
@AAR_FreightRail
AAR
6 days
Freight railroads are redefining safety through smart technology, data, and the skill of their workforce. At @BNSFRailway, that commitment moves on 1.5 million wheels each day across 32,500 miles of track. Their teams use advanced tools to catch issues early and keep trains.
1
2
33
@midwestneil
neils
6 days
RT @ive_m5: Mood
Tweet media one
0
1
0
@midwestneil
neils
7 days
RT @ive_m5: $ONDS In my opinion - the value of networks (rail) segment just 10X'd overnight considering the 450mhz and 802.16t will be the….
0
13
0
@midwestneil
neils
8 days
RT @EricReuter: @rixon @midwestneil Exactly. During a legitimate emergency brake application, the brake line is vented from both the front….
0
2
0
@midwestneil
neils
9 days
These devices are also on passenger rail operations! With that said: DO NOT TRY THIS AT HOME. YOU WILL PROBABLY GET SOMEONE HURT.
8
8
231
@midwestneil
neils
9 days
So how bad is this? You could remotely take control over a Train's brake controller from a very long distance away, using hardware that costs sub $500. You could induce brake failure leading to derailments or you could shutdown the entire national railway system.
4
17
239
@midwestneil
neils
9 days
CISA finally agreed with me that publication would be the only remaining option to pressure AAR to fix this issue. And it kinda worked. In April they announced 802.16t will replace the EOT/HOT vulnerable protocol. When will this happen by? 2027 at best.
4
4
144
@midwestneil
neils
9 days
AAR's Director of Information Security decided this was not that big of a deal, and they were not going to do anything about it as the devices and protocol were 'end of life' which is ironic because they are still in use today. AAR walked away from talking to CISA multiple times.
2
1
125
@midwestneil
neils
9 days
No one really knows what happened to it, BUT they were 100% behind getting it right this time. We went back and forth with vendors and the AAR for a few months trying to get the right parties involved to address this issue.
1
1
117
@midwestneil
neils
9 days
In 2024 I noticed that ICS-CERT had re-orged a few times and I decided to open a new ticket with them to see what ever happened to this? Did they just give up?.
1
1
112
@midwestneil
neils
9 days
In 2018 Eric Reuter independently found the same vulnerability, but only gave a talk at defcon on reverse engineering the protocol. I'd highly recommend checking out PyEOT if you want specifics on RE'ing this vulnerability.
1
2
146