Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

11–20 of 175 posts

Re: Tesla PowerWall 2 Hack

#11
post #4
post #3

Earlier quoted context omitted.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

This is unintended behavior in the same way that a locksmith leaving a copy of a key under your doormat after installing a new lock is unintended behavior. They didn't intend to cause a security issue, but they also didn't care enough to make sure that what they were doing was safe.

Re: Tesla PowerWall 2 Hack

#12
post #8
post #5

Earlier quoted context omitted.

A bug is when something is not working as intended. Tesla's intention was to quickly deliver without considering the security aspects of the product. This is potentially dangerous as attacker can just drive around hacking power walls and schedule an attack on the grid.

> Tesla's intention was to quickly deliver without considering the security aspects of the product. [Citation needed] You're assigning intentionality where incompetence would suffice.

I would argue that "building, and leaving open" Wifi connectivity that is not even remotely obfuscated is proof in itself of "failure to consider security aspects".

Re: Tesla PowerWall 2 Hack

#13
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

>this is pretty irresponsible disclosure.

This is what corporations claim, an example that makes you think about the "irresponsibility" of disclosure is the Intel security bugs, Intel sits quiet for 1 year (and more if it's bribe would have worked) and customers are tricked to buy insecure products. As a possible future customer you would like to know that something is insecure before you buy it , keeping it hidden will just increase the number of affected people.

Re: Tesla PowerWall 2 Hack

#14
post #11
post #4

Earlier quoted context omitted.

How is unintended behavior not a bug?

This is unintended behavior in the same way that a locksmith leaving a copy of a key under your doormat after installing a new lock is unintended behavior. They didn't intend to cause a security issue, but they also didn't care enough to make sure that what they were doing was safe.

Unauthorized access (in the legal sense) is definitely unintended, regardless of whether it's caused by weak design or code defect.

Posting 0-days on GitHub isn't responsible disclosure. The real test will be to see how fast it gets fixed and what the fixes end up being.

Re: Tesla PowerWall 2 Hack

#15
post #4
post #3

Earlier quoted context omitted.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

If it is documented in the manual[0][1] is it a "bug?" I think the design is poor (bad default WiFi password, WiFi always on, inverting sensors with no sanity checks) but this is how it was designed to work, it is officially documented as doing so.

I guess it boils down to a definition of the term "bug." But I feel like a lot of the knee-jerk responses (and voting) didn't read the article carefully enough.

It is a core design weakness rather than a "bug" (implying an error) in an actual good design. I think the distinction is subtle but it is there.

[0] https://www.tesla.com/support/energy/powerwall/own/monitorin...

[1] http://azmag.gov/Portals/0/Documents/MagContent/Tesla_Powerw...

Re: Tesla PowerWall 2 Hack

#16
post #4
post #3

Earlier quoted context omitted.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

How is unintended behavior not a bug?

It's not clear that most of this is even "unintended behavior" rather than just abuse. It's like calling it a "hack" to fill water balloons with electrically conductive fluid and throw them at a substation. The people responsible for stopping you from doing that are the police, not the makers of water balloons.

The worst thing they did was the default password.

Re: Tesla PowerWall 2 Hack

#17
I'm amazed Tesla went ahead and used easily guessable and unchangeable passwords. It's just such a trivial and obvious issue that it seems strange Tesla engineers let this happen.

I wonder if this was an off-the-shelf solution they're using here, or was developed by external contractors, for lack of a better explanation.

Re: Tesla PowerWall 2 Hack

#18
post #8

Earlier quoted context omitted.

> Tesla's intention was to quickly deliver without considering the security aspects of the product. [Citation needed] You're assigning intentionality where incompetence would suffice.

I would argue that "building, and leaving open" Wifi connectivity that is not even remotely obfuscated is proof in itself of "failure to consider security aspects".

Well, to be fair and comparing to not having a password at all - as they put those passwords in place they have somehow tried to protect it. Or make it look protected.

But I agree that it indicates that they haven't gave any consideration to it, and in 2019 that doesn't count as trying anymore. At least because we're talking about a well-established hardware and software vendor, not my grandma.

Re: Tesla PowerWall 2 Hack

#19
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

>this is pretty irresponsible disclosure. This is what corporations claim, an example that makes you think about the "irresponsibility" of disclosure is the Intel security bugs, Intel sits quiet for 1 year (and more if it's bribe would have worked) and customers are tricked to buy insecure products. As a possible future customer you would like to know that something is insecure before you buy it , keeping it hidden w…

You're worried about future customers, but what about Tesla's existing customers? For their sake, researchers should at least give the company a chance to respond and fix the issue before public disclosure.

I agree that a year is too long. I think 30 days is about right, but it depends on how fast the product is selling, how many new customers might be harmed during the 30-day period vs. how many existing customers there are.

How many customers do you think have already purchased a PowerWall, vs. how many would have purchased in the next 30 days?

Re: Tesla PowerWall 2 Hack

#20

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

Reminds me of a time when an ISP would provide their customers routers where their default Wifi passwords could be derived from their SSIDs. A free app would allow you to connect instantly to practically any Wifi network in the city.
Post reply on HN