Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

1–10 of 175 posts

Re: Tesla PowerWall 2 Hack

#2
Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

Re: Tesla PowerWall 2 Hack

#3
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

Re: Tesla PowerWall 2 Hack

#4
post #3
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

Re: Tesla PowerWall 2 Hack

#5
post #4
post #3

Earlier quoted context omitted.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

A bug is when something is not working as intended. Tesla's intention was to quickly deliver without considering the security aspects of the product.

This is potentially dangerous as attacker can just drive around hacking power walls and schedule an attack on the grid.

Re: Tesla PowerWall 2 Hack

#6
Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1).

Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the spirit.

Link to bill: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...

Re: Tesla PowerWall 2 Hack

#7
post #4
post #3

Earlier quoted context omitted.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

Complete negligence in security is hardly the kind of thing people think about as "bugs". The larger problem is that Tesla has put out software without any sensible considerations for security - that the result behaves badly can't really be called unintended behaviour, unless you are allowed to design software by pipe dream.

Re: Tesla PowerWall 2 Hack

#8
post #5
post #4

Earlier quoted context omitted.

How is unintended behavior not a bug?

A bug is when something is not working as intended. Tesla's intention was to quickly deliver without considering the security aspects of the product. This is potentially dangerous as attacker can just drive around hacking power walls and schedule an attack on the grid.

> Tesla's intention was to quickly deliver without considering the security aspects of the product.

[Citation needed]

You're assigning intentionality where incompetence would suffice.

Re: Tesla PowerWall 2 Hack

#9
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more).

Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

Re: Tesla PowerWall 2 Hack

#10
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

This doesn't really even seem like much of a disclosure to be had. The system is mostly open without authentication, and what little auth exists is behind a trivial-to-break password.

I mean hell, the main "hack" is looking at the API calls.

Post reply on HN