Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

91–100 of 175 posts

Re: Tesla PowerWall 2 Hack

#91
post #20

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

Reminds me of a time when an ISP would provide their customers routers where their default Wifi passwords could be derived from their SSIDs. A free app would allow you to connect instantly to practically any Wifi network in the city.

The router from my cable ISP has admin:admin. So do all of the neighbors that I can sniff.

Re: Tesla PowerWall 2 Hack

#92

Earlier quoted context omitted.

It doesn’t disrupt the grid anymore than turning a heater on and off.

Can your heater push power into the grid?

An increase in embedded generation is the same as a decrease in load to the system. So turning a heater off is akin to “pushing power in to the system”, unless the embedded generation is larger than the load on a feeder, in which case the direction of power flow would be reversed, which may or may not cause problems depending on the protection settings at the substation.

The peak system load and generation on the Western North American grid is 167,000 MW. There is so much inertia there a 10kW power wall isn’t going to do anything.

Re: Tesla PowerWall 2 Hack

#93

Earlier quoted context omitted.

> This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up. > It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur. I could be misunderstanding you, but do you seriously think that there are not more destabilizing attacks already available? From my reading the US power g…

Any power grid is very vulnerable to attack. Anyone who can cause a sudden surge in demand can take a power grid down. If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. I'm struggling to think of any companies who could do that though... Someone with malicious access to teslas servers couldn't even do that... For example, instruct all plugged in tesla cars t…

I'd assume that the power grid is much more vulnerable than that at least some of the time in some regions. What if due to natural load variations the network already is close to the capacity reserve (which could be measured by tracking AC phase) when somebody mounts an overload attack?

What happens if the attacker generated a (e.g. periodic) pattern of load changes that excites control mechanisms at their resonant frequency?

Maybe the book "Blackout" [1] (which I haven't read myself) has more (fictional) details about what can go wrong.

[1] https://en.wikipedia.org/wiki/Blackout_(Elsberg_novel)

Re: Tesla PowerWall 2 Hack

#94
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

These issues seem fairly obvious to me. Anyone interested in powerwall vulnerabilities would find them trivially. In this case I think the value is in embarrassing Tesla for their gross negligence so they do better in this area before shipping. When you disclose such things quietly with the vendor, it mostly just saves their face. Not everyone values saving Tesla's face.

> Anyone interested in powerwall vulnerabilities would find them trivially.

What about those who become invested in powerwall vulnerabilities because they read an article on HN that showed how easy it is?

> When you disclose such things quietly with the vendor, it mostly just saves their face.

I don't see how. They still get put on blast for ever being vulnerable in the first place. If you're goal is to get them in more trouble at the expense of their consumers, then that seems like pretty irresponsible disclosure to me.

> Not everyone values saving Tesla's face.

And not everyone cares one way or another about Tesla. This is about responsible disclosure. It's about protecting the consumers. It has nothing to do with the vendor.

Re: Tesla PowerWall 2 Hack

#95
post #76
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

There is no such thing as irresponsible disclosure. You are allowed and encouraged to publish your security research WHENEVER YOU FEEL LIKE. The term “responsible disclosure” is a shady tactic to frame publishing immediately and in full to those affected by the vulnerability as irresponsible. It is not.

> The term “responsible disclosure” is a shady tactic to frame publishing immediately and in full to those affected by the vulnerability as irresponsible. It is not.

What? Have you even tried to understand what responsible disclosure is?

It is about giving the vendor a chance to protect their consumers before teaching the public how to exploit a vulnerability.

The vendor still gets put on blast when the vulnerability is eventually disclosed. But at least there is less risk of the vulnerability being exploited in the mean time.

And if the vendor doesn't fix the vulnerability in a reasonable time frame, they get extra blast. We've seen this happen many times. The recent Valve and Intel incidents stand out to me as good examples.

Re: Tesla PowerWall 2 Hack

#97

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

The fast switching ability isn't a bug by itself, but it makes the insecure authentication much worse. Shitty IOT auth does not mix with power electronics.

Whether Tesla is worse than other providers in this space is another question, and may well have a depressing answer.

Re: Tesla PowerWall 2 Hack

#98

Earlier quoted context omitted.

Rate of Change of Frequency protection (ROCOF) in embedded storage and generation systems is what will kill the grid in a massive cascading failure. ROCOF works well to keep things safe when only a small percentage of the grid demand is met by residential solar/powerwalls. As soon as any significant proportion is residential solar (and thats already the case in some countries at some times of day) it acts as a cascad…

I believe the solution to this problem is to ban ROCOF protection, and the related phase shift protection, and instead instruct a few big energy producers to transmit a gold code on top of the 50 Hz AC, bandlimited to 48-52Hz and power limited to 0.01% of the system power. Transmitting that code would be easy (cheap) for anyone who does DC/AC conversion with solid state electronics, so that's normally solar, wind far…

Would a better long term fix be to upgrade grid hardware such that it can survive an inadvertent largish island?

Sometimes I think that a DC grid would be better. Issues like frequency synchronization wouldn’t exist.

Re: Tesla PowerWall 2 Hack

#99

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

You don’t see any difference between an individual switching a multi-kilowatt heater every few milliseconds vs a malicious actor automating this attack on 100,000 properties over an entire state?

Re: Tesla PowerWall 2 Hack

#100

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

Charging or dumping a single powerwall will not damage the grid. However, if someone causes many of them to do so in sync, the current grid control systems are definitely not going to cope well with that sort of behavior.
Post reply on HN