Earlier quoted context omitted.
This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.
How is unintended behavior not a bug?
Tesla PowerWall 2 Hack
11–20 of 175 posts
Re: Tesla PowerWall 2 Hack
#12Earlier quoted context omitted.
A bug is when something is not working as intended. Tesla's intention was to quickly deliver without considering the security aspects of the product. This is potentially dangerous as attacker can just drive around hacking power walls and schedule an attack on the grid.
> Tesla's intention was to quickly deliver without considering the security aspects of the product. [Citation needed] You're assigning intentionality where incompetence would suffice.
Re: Tesla PowerWall 2 Hack
#13Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.
This is what corporations claim, an example that makes you think about the "irresponsibility" of disclosure is the Intel security bugs, Intel sits quiet for 1 year (and more if it's bribe would have worked) and customers are tricked to buy insecure products. As a possible future customer you would like to know that something is insecure before you buy it , keeping it hidden will just increase the number of affected people.
Re: Tesla PowerWall 2 Hack
#14Earlier quoted context omitted.
How is unintended behavior not a bug?
This is unintended behavior in the same way that a locksmith leaving a copy of a key under your doormat after installing a new lock is unintended behavior. They didn't intend to cause a security issue, but they also didn't care enough to make sure that what they were doing was safe.
Posting 0-days on GitHub isn't responsible disclosure. The real test will be to see how fast it gets fixed and what the fixes end up being.
Re: Tesla PowerWall 2 Hack
#15Earlier quoted context omitted.
This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.
How is unintended behavior not a bug?
I guess it boils down to a definition of the term "bug." But I feel like a lot of the knee-jerk responses (and voting) didn't read the article carefully enough.
It is a core design weakness rather than a "bug" (implying an error) in an actual good design. I think the distinction is subtle but it is there.
[0] https://www.tesla.com/support/energy/powerwall/own/monitorin...
[1] http://azmag.gov/Portals/0/Documents/MagContent/Tesla_Powerw...
Re: Tesla PowerWall 2 Hack
#16Earlier quoted context omitted.
This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.
How is unintended behavior not a bug?
The worst thing they did was the default password.
Re: Tesla PowerWall 2 Hack
#17I wonder if this was an off-the-shelf solution they're using here, or was developed by external contractors, for lack of a better explanation.
Re: Tesla PowerWall 2 Hack
#18Earlier quoted context omitted.
> Tesla's intention was to quickly deliver without considering the security aspects of the product. [Citation needed] You're assigning intentionality where incompetence would suffice.
I would argue that "building, and leaving open" Wifi connectivity that is not even remotely obfuscated is proof in itself of "failure to consider security aspects".
But I agree that it indicates that they haven't gave any consideration to it, and in 2019 that doesn't count as trying anymore. At least because we're talking about a well-established hardware and software vendor, not my grandma.
Re: Tesla PowerWall 2 Hack
#19Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.
>this is pretty irresponsible disclosure. This is what corporations claim, an example that makes you think about the "irresponsibility" of disclosure is the Intel security bugs, Intel sits quiet for 1 year (and more if it's bribe would have worked) and customers are tricked to buy insecure products. As a possible future customer you would like to know that something is insecure before you buy it , keeping it hidden w…
I agree that a year is too long. I think 30 days is about right, but it depends on how fast the product is selling, how many new customers might be harmed during the 30-day period vs. how many existing customers there are.
How many customers do you think have already purchased a PowerWall, vs. how many would have purchased in the next 30 days?
Re: Tesla PowerWall 2 Hack
#20Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…