Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

71–80 of 175 posts

Re: Tesla PowerWall 2 Hack

#71

This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up. It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur.

Rate of Change of Frequency protection (ROCOF) in embedded storage and generation systems is what will kill the grid in a massive cascading failure. ROCOF works well to keep things safe when only a small percentage of the grid demand is met by residential solar/powerwalls. As soon as any significant proportion is residential solar (and thats already the case in some countries at some times of day) it acts as a cascad…

I believe the solution to this problem is to ban ROCOF protection, and the related phase shift protection, and instead instruct a few big energy producers to transmit a gold code on top of the 50 Hz AC, bandlimited to 48-52Hz and power limited to 0.01% of the system power. Transmitting that code would be easy (cheap) for anyone who does DC/AC conversion with solid state electronics, so that's normally solar, wind farms, and long distance undersea transmission lines.

That gold code could be received and decoded anywhere on the network. If power islanding occurs, embedded generation will detect the loss of the gold code (since they are no longer connected to the generator injecting the code), and cease supply.

The only disadvantage is it introduces a security vulnerability by design: Anyone could transmit the gold code from their house, effectively disabling islanding protection in their neighbourhood. If power islanding were to occur, and if there was sufficient embedded generation to keep a stable power island, grid hardware could be destroyed through overvoltage, overheating, and circuits closing without frequency synchronisation. I think it's a worthwhile tradeoff though - damage will be localized and minimal, and a very unusual set of circumstances have to happen outside the attackers control for the attack to do damage.

Re: Tesla PowerWall 2 Hack

#72

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

No it's not, it's also the CT Sensor.

What a garbage product.

Re: Tesla PowerWall 2 Hack

#73
post #36

This is an amazing lack of security best practices. To me, this screams outsourced. Given how many people hate Tesla, they need to be taking this seriously. This truly blows me away. This is "people should be fired" levels of organizational incompetence. There's no way some of these issues haven't already been noticed and put in the issue tracker. They're just not taking it seriously. It reminds me of Boeing to be pe…

It does not strike me as outsourced, given what we know about software engineering practices at Tesla: https://twitter.com/atomicthumbs/status/1032939617404645376

Re: Tesla PowerWall 2 Hack

#74
post #34

Earlier quoted context omitted.

The password format is `ST 0001 `. * YY is a year, with the first year being 2015. So right now there's only five options. * L is the revision, of which there is D, E, F, G, H, I- for six options total. * XYZ is literally the last three digits of the SSID, which means you get that for free. With all of this information it will take at most 30 attempts to log into the network.

Yes, but the only time that this would be an issue is if someone, somehow decides to install it themselves or the Tesla technicians installing it forget to change the password which is very unlikely considering it's part of the standard process that you have to sign for upon install. You have to choose your own password either way or accept that you didn't.

>someone, somehow decides to install it themselves

Funny!

https://teslamotorsclub.com/tmc/threads/misbehaving-powerwal...

Re: Tesla PowerWall 2 Hack

#75
post #54

Earlier quoted context omitted.

I think this comment highlights a lack of understanding what responsible disclosure is about. It's there to reach the best possible tradeoffs to protect consumers and force a quick turnaround with fixes. Just publishing vulns, which the vendor might not even see or learn about(!), will not help in getting things improved and puts consumers knowingly at risk at scale.

I understand perfectly well what it is. But see my sibling comments, that reflect an agreement with the concept of "coordinated disclosure", rather than "responsible disclosure", which gives an implication that I am being irresponsible if I do not work to the vendor's needs and priorities.

Publishing vulnerability details without informing the vendor is irresponsible.

Re: Tesla PowerWall 2 Hack

#76
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

There is no such thing as irresponsible disclosure. You are allowed and encouraged to publish your security research WHENEVER YOU FEEL LIKE.

The term “responsible disclosure” is a shady tactic to frame publishing immediately and in full to those affected by the vulnerability as irresponsible. It is not.

Re: Tesla PowerWall 2 Hack

#77
Is there an alternative to the powerwall that is functionally similar, in terms of power density and utility, but doesn't have things like a network stack and other wifi / IoT / "smart" features ?

We are just about to install lithium battery backups in our home and, of course, the Tesla powerwalls are an obvious choice, but I don't look forward to having to disable/reenable the network connectivity on them, manually, in some cat-and-mouse with Tesla for updates or whatever...

In fact, I'll bet that most (all ?) of the updates that Tesla has to send the powerwalls are for the update system, and accompanying network stack, itself ...

Re: Tesla PowerWall 2 Hack

#78
post #77

Is there an alternative to the powerwall that is functionally similar, in terms of power density and utility, but doesn't have things like a network stack and other wifi / IoT / "smart" features ? We are just about to install lithium battery backups in our home and, of course, the Tesla powerwalls are an obvious choice, but I don't look forward to having to disable/reenable the network connectivity on them, manually,…

Nothing close in terms of cost per kwh.

Re: Tesla PowerWall 2 Hack

#79
post #77

Is there an alternative to the powerwall that is functionally similar, in terms of power density and utility, but doesn't have things like a network stack and other wifi / IoT / "smart" features ? We are just about to install lithium battery backups in our home and, of course, the Tesla powerwalls are an obvious choice, but I don't look forward to having to disable/reenable the network connectivity on them, manually,…

Used Nissan leafs are pretty affordable, might make a nice powerwall.

Re: Tesla PowerWall 2 Hack

#80
post #77

Is there an alternative to the powerwall that is functionally similar, in terms of power density and utility, but doesn't have things like a network stack and other wifi / IoT / "smart" features ? We are just about to install lithium battery backups in our home and, of course, the Tesla powerwalls are an obvious choice, but I don't look forward to having to disable/reenable the network connectivity on them, manually,…

What is the reason you can't store excess on the grid?
Post reply on HN