Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

21–30 of 175 posts

Re: Tesla PowerWall 2 Hack

#21

Earlier quoted context omitted.

>this is pretty irresponsible disclosure. This is what corporations claim, an example that makes you think about the "irresponsibility" of disclosure is the Intel security bugs, Intel sits quiet for 1 year (and more if it's bribe would have worked) and customers are tricked to buy insecure products. As a possible future customer you would like to know that something is insecure before you buy it , keeping it hidden w…

You're worried about future customers, but what about Tesla's existing customers? For their sake, researchers should at least give the company a chance to respond and fix the issue before public disclosure. I agree that a year is too long. I think 30 days is about right, but it depends on how fast the product is selling, how many new customers might be harmed during the 30-day period vs. how many existing customers t…

I would agree if and only if is a super hard to find issue, but if any curious teenager can find and abuse this then keeping is secret is making more harm.

If your car had a bug where it could be controlled remotely by any teenager with a laptop and a program do you want to know and stop using the car or block it's internet connection or prefer Tesla has it's 90 days to find a fix.

Anyway let's see what harm comes from this being revealed and maybe I will change my mind.

Re: Tesla PowerWall 2 Hack

#22
So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products.

Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.

Re: Tesla PowerWall 2 Hack

#23

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

Umm, why would a wall battery even need a password???

Re: Tesla PowerWall 2 Hack

#24
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

Irresponsible disclosure is releasing products and services with flaws like these onto the open market - the rest is corporate doublespeak.

Re: Tesla PowerWall 2 Hack

#25

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

Umm, why would a wall battery even need a password???

Because you might want to control it from your phone or laptop .

Re: Tesla PowerWall 2 Hack

#26
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more). Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

You're always welcome to disclose to the company and follow your own timelines and policies.

Presumably this doesn't change whether you tell the company first or post it on your GitHub. Shitty either way but irrelevant.

Re: Tesla PowerWall 2 Hack

#27

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.

Re: Tesla PowerWall 2 Hack

#28
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more). Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

You can do responsible disclosure without following a vendor's timeline. Project Zero comes to mind. It's not like the only options are either dropping 0 days or doing exactly as the vendor says. Simply give a date.

At the end of the day the point of security research is to make things more secure. Oftentimes that is best achieved by working with the vendor.

Re: Tesla PowerWall 2 Hack

#29
I have a couple of PW2s installed, connected via ethernet only (isolated on its own VLAN, though Tesla is total garbage about basics like "what firewall rules are needed"), no cellular here either. But the TEG-$(SERIAL){3} network has always been right there anyway, which is just really lazy design. I happen to be physically far enough away from anyone else that it's very unlikely to be a security issue in practice, but it's still unnecessarily polluting WiFi even beyond that. This has been noticeable for a long time too, it's not hard to find threads going back a long ways with people asking how to disable the gateway WiFi, ie., ( https://teslamotorsclub.com/tmc/threads/disable-gateway-wifi... ), or people speculating about the obvious vuln/interference implications. From that thread back in June:

>It would be nice to find a way to turn off the TBG's WiFi hotspot. I already have too many WiFi hotspots in my area for my taste. TBG's broadcasting WiFi is just a exploit waiting to happen.

The whole thing is genuinely perplexing. Dependence on WiFi, while regrettable, I guess can sometimes make sense from a "user friendly" perspective for a lot of typical consumer installed gear. But the PowerWalls are absolutely not consumer installable, nor obviously in any way inherently wireless. They represent serious electrical infrastructure, and require professional installation with a lot of run cable. Adding in some shielded cat 5 or whatever along with that is frankly trivial for multi-thousand/ten-thousand dollar professional projects, even when not dealing with people who can do a drop themselves.

Minimizing attack area is really trivial security, and here it's got other bonuses like just being more reliable. The entire IOT space is full of shit of course, but it seems much stranger in this instance to me than something like lightbulbs. And why even have passwords at all for access versus using keys? None of this is supposed to be generally accessible anyway. It's not like this would cost Tesla anything extra.

Edit to add: HOSTNAME INCLUDES THE FULL SERIAL. I thought I'd take a second look at this and just pulled up the client info for the PW2 Gateway on my network, and hostname is 11XXXXX-00-J--S$(SERIAL). So no local physical access is required, the gateway itself just broadcasts the whole serial, which in light of this is an, interesting, decision. I can confirm that using the hostname with an added S at the front (so on mine serial was T[...], I used the password ST[...]) I was able to connect to the WiFi spot, and in turn to the management page described. Incredible.

Incidentally DPI is also kind of wacky now that I look, just running a simple Suricata setup but connections are all over the place (why is YouTube showing up?). About 4.5 GB down and 9 GB up, down I assume would be updates of some kind, up monitoring data though that seems like a significant amount for what should generally be text. I haven't had it that long, must be kind of chatty.

Re: Tesla PowerWall 2 Hack

#30
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more). Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

> "Responsible disclosure" is an invention of vendors who want you conforming to their policies and timeline

No it’s not. It’s an invention of ethical hackers and academic security researchers who are mature enough to realize that dropping 0-days to the public is worse for society than giving the vendor a reasonable opportunity to fix it.

“Economics of information security” is a field that publishes some studies about vulnerability disclosure strategies and maximizing the social good.

Post reply on HN