Live data from Hacker News

Hacking my Tesla Model S

su-tesla.space

21–30 of 30 posts

Re: Hacking my Tesla Model S

#21
post #7

a) Useless article b) Previously on HN [1]: 12 and 16 [2] hours ago, the first one has some (mostly: 'The article is light on details') discussions. 1: https://news.ycombinator.com/item?id=11441113 2: https://news.ycombinator.com/item?id=11440612

Dang, Can we ask for an investigation here? I'd like to know: - Do the IPs of the 3 people who posted the articles match an IP of Tesla Motors? - How did the 3 people discover the articles? - How come they posted different urls, with different titles, to the same article? If my intuition is correct, you might flag the accounts; but even more interesting is you might happen to uncover an deceiving behaviour from Tesla…

For this submission, I can say I'm definitely not working for Tesla. I found the link in my twitter feed ( https://twitter.com/chrismatthieu/status/717797775912480772 RT by Brendan Eich ). Didn't realise it's been posted before, apologies for that.

Re: Hacking my Tesla Model S

#22
post #5

Tesla heavily disappoints me here. This looks like pure PR: - It is a blog with only 1 entry. - The Whois entry is "WhoisGuard Protected" in Panama: http://who.is/whois/www.su-tesla.space . Very bad timing with the #panamapapers. The non-technical depth and the naive writing let me imagine that a junior social media employee could have done it. And I'm disappointed if Tesla hired such people / let an intern write a P…

WhoisGuard is Namecheap's privacy protection service. There is nothing unusual or untoward about not wanting your contact information being used for spear phishing, spam, ... I'm not convinced contact information should be required when registering a domain. Why should it matter who owns the domain?

Time for a quick rant:

Because

* when I ask CloudFlare to stop resolving phishing domains with their nameservers they don't care.

* when I ask amazon to remove the content from their networks that's clearly against their TOS, they don't care.

* when I try to get in touch with PrivacyGuard about this domain, they don't care either.

* I ask aweber.com to cut off this customer who they are providing mailinglistservice for, they don't care.

These are all at least semi-reputable companies, who through inaction continue to allow criminals to abuse their infrastructure, and do not allow me to directly contact this offending customer.

So there is no way for me to find out which entity is responsible for actually creating this phishing operation. Granted, they'd probably fake whois data anyhow, but it's my last straw :-)

Now, I'm actually all for anonymity, I'm just frustrated with trying to remove this phishing site that's been up for months now.

Re: Hacking my Tesla Model S

#23
post #3

If the story holds, I think it is interesting to know more details about why Tesla has chosen Ubuntu server as the underlying OS and nothing else? I can see that ubuntu server has proven itself in a lot of real-world environments, but wouldn't they have to run their own fork of Ubuntu at some point? Or is the distro management toolchain in the Ubuntu world more advanced than for example some bsd or centos? Edit: I am…

If indeed Tesla uses a custom version of Ubuntu, then it is guilty of not redistributing the source code.

As per the license... the license to use it is revoked, not until they distribute the code, but until all licensors grant a new one.

It would really be funny "if" this were an organized leak.

Re: Hacking my Tesla Model S

#25
post #5

Tesla heavily disappoints me here. This looks like pure PR: - It is a blog with only 1 entry. - The Whois entry is "WhoisGuard Protected" in Panama: http://who.is/whois/www.su-tesla.space . Very bad timing with the #panamapapers. The non-technical depth and the naive writing let me imagine that a junior social media employee could have done it. And I'm disappointed if Tesla hired such people / let an intern write a P…

- Yeah, it's a blog with 1 entry because I literally just set the thing up. I was up till 3AM Tuesday night.

- Namecheap's WhoisGuard. Do you really think I'd not try and protect myself? I was debating for a week whether I should post anything at all. Tesla sure as hell knows someone new is doing something somewhere. I'm trying REALLY hard to make it so absolutely nothing can be easily linked back to me. The "dramatic reenactment" had to be done. I have pictures of me actually rooting but the PS1 on the car is tesla@cid-$ Can't really show that if I'm trying to be anonymous. Funny anecdote: I had posted it Tuesday night before bed, but I didn't show anyone. In the morning I was driving to work and looked down at my IC. So, you can name your cars, and the name I gave my car was on the IC. Sure enough, the factory mode IC picture had that name. It was a fairly unique name, and I had to hurry up and censor that one too.

- Sorry my blog doesn't pass your technical writing course. Thank God it's just a blog and I can write it however I want.

- There's no reason to mention the previous hacks from other people. Are they me? No. You can read that stuff somewhere else.

- Ahh, you caught me on the "2 months of research". That's the term I use when I'm actually saying "2 months of slacking." I was distracted by new coloring books for a while. Also I really didn't want to have to make the cable. I was trying to get a salvaged one for a while. Eventually I had to suck it up.

So, sooooorry to disappoint you that it's not an organized leak from Tesla and that it's not the "best case". I knew the post would be somewhat popular, but nowhere near this popular. I thought it'd be the later posts where I'm actually showing stuff instead of me just ripping my car apart that people would love. It's actually funny when a friend of mine told me about this thread. Here I am terrified out of my mind that Tesla was going to figure out who I was, and then everyone is saying I AM Tesla.

Re: Hacking my Tesla Model S

#27

a) Useless article b) Previously on HN [1]: 12 and 16 [2] hours ago, the first one has some (mostly: 'The article is light on details') discussions. 1: https://news.ycombinator.com/item?id=11441113 2: https://news.ycombinator.com/item?id=11440612

I never said the article was a howto. I only wrote it to document my experiences, not to tell people how to do it. It really doesn't matter if you find it useless; I don't owe you anything. I'm having a blast with this and made the blog because I thought others might be interested in seeing my experiences.

As for the actual HN posts, I only posted the first one, then moved on with my life. Others told me that the second one was then posted, so I went in there to clear up any misconceptions. I woke up this morning being told by a friend that this one had been posted.

Re: Hacking my Tesla Model S

#28
post #15
post #5

Tesla heavily disappoints me here. This looks like pure PR: - It is a blog with only 1 entry. - The Whois entry is "WhoisGuard Protected" in Panama: http://who.is/whois/www.su-tesla.space . Very bad timing with the #panamapapers. The non-technical depth and the naive writing let me imagine that a junior social media employee could have done it. And I'm disappointed if Tesla hired such people / let an intern write a P…

From the images this seems a big parking space. Strange that you consider disassembling your car in such a place as a private individual. What if you run into a problem, it gets late and you have to go home? Story is different if this is the parking of your company and the vehicle isn't yours.

JorgeGT, I'd just like to tell you, this is absolutely my favorite comment out of this entire thread. You completely made my day. I invite you to come over to my blog and post comments on every post from now on.

Re: Hacking my Tesla Model S

#29
post #3

If the story holds, I think it is interesting to know more details about why Tesla has chosen Ubuntu server as the underlying OS and nothing else? I can see that ubuntu server has proven itself in a lot of real-world environments, but wouldn't they have to run their own fork of Ubuntu at some point? Or is the distro management toolchain in the Ubuntu world more advanced than for example some bsd or centos? Edit: I am…

That screenshot is labelled "dramatic reenactment", which I believe is just another expression for "fake".

The stuff above is fake. The actual login is real. Running uname -a gives that same output.

Re: Hacking my Tesla Model S

#30
post #7

a) Useless article b) Previously on HN [1]: 12 and 16 [2] hours ago, the first one has some (mostly: 'The article is light on details') discussions. 1: https://news.ycombinator.com/item?id=11441113 2: https://news.ycombinator.com/item?id=11440612

Dang, Can we ask for an investigation here? I'd like to know: - Do the IPs of the 3 people who posted the articles match an IP of Tesla Motors? - How did the 3 people discover the articles? - How come they posted different urls, with different titles, to the same article? If my intuition is correct, you might flag the accounts; but even more interesting is you might happen to uncover an deceiving behaviour from Tesla…

For the future: please send questions like this to hn@ycombinator.com. It's totally hit and miss whether we'll see them in the threads like this.

I looked and found no evidence, not even a tinge, of the things you're asking about. Seems most likely that a bunch of people ran across the story on the internet and thought HN would like it. Tesla is one of a few strains of high-grade local catnip, so they weren't wrong.

Btw other users posted the article too but hit the dupe detector. The ones who varied the URL made it past the dupe detector, which is how it's designed to work.

Post reply on HN