Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…
I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.
Tesla PowerWall 2 Hack
31–40 of 175 posts
Re: Tesla PowerWall 2 Hack
#32So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products. Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.
But at the same time, this is pretty genuinely bad security architecture, and it really needs to be exposed and embarrass the company that did it. Tesla does some great stuff. This thing seems a little mailed-in, though.
Re: Tesla PowerWall 2 Hack
#33Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…
Reminds me of a time when an ISP would provide their customers routers where their default Wifi passwords could be derived from their SSIDs. A free app would allow you to connect instantly to practically any Wifi network in the city.
They also ship with default SSIDs, numbered 100 to 999, so given 900 GPU days of precomputation you could create rainbow tables that allow for cracking every default password/ssid pair.
I can tell you from the wifi passwords I have been given by friends that many people are not changing them.
At least you need to capture a handshake to use your rainbow table...
Re: Tesla PowerWall 2 Hack
#34Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…
I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.
* YY is a year, with the first year being 2015. So right now there's only five options.
* L is the revision, of which there is D, E, F, G, H, I- for six options total.
* XYZ is literally the last three digits of the SSID, which means you get that for free.
With all of this information it will take at most 30 attempts to log into the network.
Re: Tesla PowerWall 2 Hack
#35So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products. Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.
When you're working in higher risk domains, higher safety standards are reasonably demanded.
Re: Tesla PowerWall 2 Hack
#36Re: Tesla PowerWall 2 Hack
#37Earlier quoted context omitted.
How is unintended behavior not a bug?
If it is documented in the manual[0][1] is it a "bug?" I think the design is poor (bad default WiFi password, WiFi always on, inverting sensors with no sanity checks) but this is how it was designed to work, it is officially documented as doing so. I guess it boils down to a definition of the term "bug." But I feel like a lot of the knee-jerk responses (and voting) didn't read the article carefully enough. It is a co…
The password is a level of incompetence beyond what you'd call a bug. It's clearly following a design decision that was imposed by someone with zero security experience.
Re: Tesla PowerWall 2 Hack
#38So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products. Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.
You say that about a security issue that could blow California's power grid in minutes.
Re: Tesla PowerWall 2 Hack
#39Earlier quoted context omitted.
I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.
The password format is `ST 0001 `. * YY is a year, with the first year being 2015. So right now there's only five options. * L is the revision, of which there is D, E, F, G, H, I- for six options total. * XYZ is literally the last three digits of the SSID, which means you get that for free. With all of this information it will take at most 30 attempts to log into the network.
Re: Tesla PowerWall 2 Hack
#40It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur.