Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

41–50 of 175 posts

Re: Tesla PowerWall 2 Hack

#41
post #34

Earlier quoted context omitted.

The password format is `ST 0001 `. * YY is a year, with the first year being 2015. So right now there's only five options. * L is the revision, of which there is D, E, F, G, H, I- for six options total. * XYZ is literally the last three digits of the SSID, which means you get that for free. With all of this information it will take at most 30 attempts to log into the network.

Yes, but the only time that this would be an issue is if someone, somehow decides to install it themselves or the Tesla technicians installing it forget to change the password which is very unlikely considering it's part of the standard process that you have to sign for upon install. You have to choose your own password either way or accept that you didn't.

"The password can not be changed. It is not possible to disable the WiFi network."

You can only change the password for management portal not the WiFi.

Re: Tesla PowerWall 2 Hack

#42
post #33
post #20

Earlier quoted context omitted.

Reminds me of a time when an ISP would provide their customers routers where their default Wifi passwords could be derived from their SSIDs. A free app would allow you to connect instantly to practically any Wifi network in the city.

An ISP around here still ships consumer routers with passwords consisting of a random 8 digit hex number, i.e. that could be cracked in a day on a GTX 970m (tested hash rate against my parent's wifi). They also ship with default SSIDs, numbered 100 to 999, so given 900 GPU days of precomputation you could create rainbow tables that allow for cracking every default password/ssid pair. I can tell you from the wifi pass…

> They also ship with default SSIDs, numbered 100 to 999, so given 899 GPU days of precomputation

That would be 900 GPU days actually - off by one error

Re: Tesla PowerWall 2 Hack

#43

So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products. Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.

this is an exploit that allows an attacker to disrupt the electrical grid - even if it's only to the substation, that effects all of your neighbors that didn't encourage you to blindly support Tesla's endeavour. it's highly irresponsible to have this kind of control behind such a trivial login on something that connects to your power lines, something extremely dangerous. far from a "nitpick"

Re: Tesla PowerWall 2 Hack

#44
post #33

Earlier quoted context omitted.

An ISP around here still ships consumer routers with passwords consisting of a random 8 digit hex number, i.e. that could be cracked in a day on a GTX 970m (tested hash rate against my parent's wifi). They also ship with default SSIDs, numbered 100 to 999, so given 900 GPU days of precomputation you could create rainbow tables that allow for cracking every default password/ssid pair. I can tell you from the wifi pass…

> They also ship with default SSIDs, numbered 100 to 999, so given 899 GPU days of precomputation That would be 900 GPU days actually - off by one error

[deleted]

Re: Tesla PowerWall 2 Hack

#45

Earlier quoted context omitted.

I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.

TFA makes it clear that the SSID is derived from the serial number and the SSID is being broadcast openly.

Exactly. If the SSID was “Password=BSSID MAC” and the password _was_ the MAC address of the BSSID device, I suppose it would technically be unique. This is barely more secure than that, IMO.

Re: Tesla PowerWall 2 Hack

#46
post #34

Earlier quoted context omitted.

I disagree. The spirit of the law is to ensure that logins cannot be automated. Unless the serial number can be read over the internet without authentication, using it is completely within the spirit of the law.

The password format is `ST 0001 `. * YY is a year, with the first year being 2015. So right now there's only five options. * L is the revision, of which there is D, E, F, G, H, I- for six options total. * XYZ is literally the last three digits of the SSID, which means you get that for free. With all of this information it will take at most 30 attempts to log into the network.

Could always send out fake registration emails/postcards to collect serial numbers (which most people wouldn't consider especially sensitive info)...

Re: Tesla PowerWall 2 Hack

#47
post #29

I have a couple of PW2s installed, connected via ethernet only (isolated on its own VLAN, though Tesla is total garbage about basics like "what firewall rules are needed"), no cellular here either. But the TEG-$(SERIAL){3} network has always been right there anyway, which is just really lazy design. I happen to be physically far enough away from anyone else that it's very unlikely to be a security issue in practice,…

>Edit to add: HOSTNAME INCLUDES THE FULL SERIAL. I thought I'd take a second look at this and just pulled up the client info for the PW2 Gateway on my network, and hostname is 11XXXXX-00-J--S$(SERIAL). So no local physical access it required, the gateway itself just broadcasts the whole serial, which in light of this is an, interesting, decision. I can confirm that using the hostname with an added S at the front (so on mine serial was T[...], I used the password ST[...]) I was able to connect to the WiFi spot, and in turn to the management page described. Incredible.

this is staggeringly irresponsible design! thanks for the confirmation

Re: Tesla PowerWall 2 Hack

#49

This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up. It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur.

> This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up.

> It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur.

I could be misunderstanding you, but do you seriously think that there are not more destabilizing attacks already available? From my reading the US power grid is already extremely vulnerable to attack.

Re: Tesla PowerWall 2 Hack

#50
post #36

This is an amazing lack of security best practices. To me, this screams outsourced. Given how many people hate Tesla, they need to be taking this seriously. This truly blows me away. This is "people should be fired" levels of organizational incompetence. There's no way some of these issues haven't already been noticed and put in the issue tracker. They're just not taking it seriously. It reminds me of Boeing to be pe…

And not just fired for this, but because they are incompetent enough to do something like this in the first place. And that needs to be at however high of a level it was that approved the security plan for this product.
Post reply on HN