Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

81–90 of 175 posts

Re: Tesla PowerWall 2 Hack

#81

Earlier quoted context omitted.

> This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up. > It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur. I could be misunderstanding you, but do you seriously think that there are not more destabilizing attacks already available? From my reading the US power g…

Any power grid is very vulnerable to attack. Anyone who can cause a sudden surge in demand can take a power grid down. If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. I'm struggling to think of any companies who could do that though... Someone with malicious access to teslas servers couldn't even do that... For example, instruct all plugged in tesla cars t…

> If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail.

Wouldn't that behave identically to a sudden loss of generation? The power grids I know of have schemes to deal with that, by automatically shedding large blocks of load in several stages.

Re: Tesla PowerWall 2 Hack

#82
post #41

Earlier quoted context omitted.

Yes, but the only time that this would be an issue is if someone, somehow decides to install it themselves or the Tesla technicians installing it forget to change the password which is very unlikely considering it's part of the standard process that you have to sign for upon install. You have to choose your own password either way or accept that you didn't.

"The password can not be changed. It is not possible to disable the WiFi network." You can only change the password for management portal not the WiFi.

So you can change the password to the management portal and prevent access to the API / admin panel which provides access to all of the mentioned settings?

Re: Tesla PowerWall 2 Hack

#83
post #38

So many people like to nitpick when it comes to Tesla, It reminds me of the Apple critics in the early days of the iphone. They assume Tesla should have the highest standard and be absolutely impeccable with all their products. Just don't buy it if you don't like it. Let the rest of us enjoy a sustainable future with insanely safe full self-driving electric cars.

> Just don't buy it if you don't like it. You say that about a security issue that could blow California's power grid in minutes.

In fairness, so could a strong breeze, apparently. Thanks, PG&E!

Re: Tesla PowerWall 2 Hack

#84
post #81

Earlier quoted context omitted.

Any power grid is very vulnerable to attack. Anyone who can cause a sudden surge in demand can take a power grid down. If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. I'm struggling to think of any companies who could do that though... Someone with malicious access to teslas servers couldn't even do that... For example, instruct all plugged in tesla cars t…

> If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. Wouldn't that behave identically to a sudden loss of generation? The power grids I know of have schemes to deal with that, by automatically shedding large blocks of load in several stages.

Yes - but IMO, as soon as you've shed any significant amount of load, you've failed.

If just 10% of a nationwide grid is down, there's a good chance the phone network won't work, internet will be down, trains won't run, credit card/payment systems won't work, etc. All those things have primary and backup systems, but somewhere in the chain of dependencies there will be both a primary and backup that have been shed, and the system designers thought "these two data centers are 500 miles apart, so won't fail together".

Re: Tesla PowerWall 2 Hack

#85

Earlier quoted context omitted.

When home renewable reaches a level of penetration where simultaneous loss would be in excess of spinning reserve any further embedded generation will be regulated in such a way as to not contribute to the problem. For instance by prohibiting exporting energy back to the system, and separating your house from the system if the frequency is falling quickly and your embedded generation is going to trip,in order to avoi…

Isn't that the problem, that every home device will disconnect at roughly the same time? Leaving the atrophied generators to take up far too much slack.

Embedded generation will firstly displace local load before exporting any power back to the system. If the generation disconnects all you are left with is the load. If the frequency is falling and the ROCOF protection is going to cause the generation to trip, better to trip the load too otherwise the system just gets an increase in load.

Re: Tesla PowerWall 2 Hack

#86
post #72

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

No it's not, it's also the CT Sensor. What a garbage product.

In the same way a printer is a garbage product for printing a document landscape when you put the paper in the wrong way round?

Product works in safe but unexpected ways when not configured according to reality. News at 10.

Re: Tesla PowerWall 2 Hack

#87

Earlier quoted context omitted.

this is an exploit that allows an attacker to disrupt the electrical grid - even if it's only to the substation, that effects all of your neighbors that didn't encourage you to blindly support Tesla's endeavour. it's highly irresponsible to have this kind of control behind such a trivial login on something that connects to your power lines, something extremely dangerous. far from a "nitpick"

It doesn’t disrupt the grid anymore than turning a heater on and off.

Can your heater push power into the grid?

Re: Tesla PowerWall 2 Hack

#88

Earlier quoted context omitted.

> "Responsible disclosure" is an invention of vendors who want you conforming to their policies and timeline No it’s not. It’s an invention of ethical hackers and academic security researchers who are mature enough to realize that dropping 0-days to the public is worse for society than giving the vendor a reasonable opportunity to fix it. “Economics of information security” is a field that publishes some studies abou…

Some interesting commentary: https://news.ycombinator.com/item?id=14010010 https://news.ycombinator.com/item?id=12308246 > That may feel good to say, but as someone whose job it was to find these kinds of bugs in software from companies ranging from tiny startups to financial exchanges to major tech vendors, this is a kind of carelessness shared by virtually everyone shipping any kind of software anywhere. > That sai…

> That said, the term "responsible disclosure" is Orwellian, and you should very much avoid using it.

It seems you disapprove of the phrase "responsible disclosure" because it's ambiguous and can be used as a cudgel. That's no different than the term "Orwellian", which is ambiguous and can be used as a cudgel.

All people are saying is that it's better to give the vendor a heads up before releasing an exploit. Maybe they have something to tell you that might cause you to delay; maybe not. Surely responsible disclosure implies to most people some amount of due diligence in choosing a timeline for disclosure. If you don't give a vendor any opportunity to discuss, there's been no such due diligence on your part.

Re: Tesla PowerWall 2 Hack

#89
post #81

Earlier quoted context omitted.

> If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. Wouldn't that behave identically to a sudden loss of generation? The power grids I know of have schemes to deal with that, by automatically shedding large blocks of load in several stages.

Yes - but IMO, as soon as you've shed any significant amount of load, you've failed. If just 10% of a nationwide grid is down, there's a good chance the phone network won't work, internet will be down, trains won't run, credit card/payment systems won't work, etc. All those things have primary and backup systems, but somewhere in the chain of dependencies there will be both a primary and backup that have been shed, a…

American here. Trains already don't run, no real net change.

Re: Tesla PowerWall 2 Hack

#90

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

I guess you haven't seen this then.

https://www.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...

Post reply on HN