Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

151–160 of 175 posts

Re: Tesla PowerWall 2 Hack

#151
post #81

Earlier quoted context omitted.

> If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. Wouldn't that behave identically to a sudden loss of generation? The power grids I know of have schemes to deal with that, by automatically shedding large blocks of load in several stages.

Yes - but IMO, as soon as you've shed any significant amount of load, you've failed. If just 10% of a nationwide grid is down, there's a good chance the phone network won't work, internet will be down, trains won't run, credit card/payment systems won't work, etc. All those things have primary and backup systems, but somewhere in the chain of dependencies there will be both a primary and backup that have been shed, a…

Fortunately many critical infrastructure system and life safety systems have on-site backup energy generation capability, as long as diesel is available. At least in the USA, our internet, payment, and phone systems have all withstood significant medium-term regional power outages.

A major infrastructure cyberattack seems effective either as an opening salvo in a traditional military war or to multiply the chaos after a terrorist attack. Taking out the power grid would worsen traffic congestion and create increased demand on emergency services in the short term, and have major economic impacts and high visibility in the long term.

Re: Tesla PowerWall 2 Hack

#152
post #114

Earlier quoted context omitted.

IMHO, these stories aren’t unexpected from a tech company that grows 80% year over year, developing and expanding as fast as technology and market forces allow. Yes, there are mistakes and unfortunate incidents in the organization of people and tech priorities here, but this is inevitable in an engineering org that moves this fast. You really need to measure this up against Tesla’s achievements: Growing high double d…

> For the sake of enlightening discussion, could you please express your disagreement in words rather than the downvote button? I'll give it a try: maybe it's because someone made an off-hand comment about Tesla shipping a default password, and you chimed in with an apologetic post that reads a lot like astro-turfing? > did this with almost zero paid marketing Traditional marketing. Tesla spends millions on marketing…

> Traditional marketing. Tesla spends millions on marketing annually, it's right there in their financials. Just recently a pile of pro-Tesla Twitter bot accounts were banned. Did you know that Tesla is paying people to post messages on social media?

Umm what? I can assure you that most pro-Tesla Twitter accounts are happy owners. I know cause I am one. The amount of FUD on Twitter directed against Tesla is insane!

I created my Twitter account in February 2008 and it has pretty much stayed dormant for the most part. Until I bought a Model S and discovered the TSLAQ trolls and often challenge their B.S. claims with actual sources. Case in point: https://twitter.com/teslahistorian

> Just recently a pile of pro-Tesla Twitter bot accounts were banned.

> Did you know that Tesla is paying people to post messages on social media?

Care to cite your source on these?!

Re: Tesla PowerWall 2 Hack

#153
post #146

Earlier quoted context omitted.

> For the sake of enlightening discussion, could you please express your disagreement in words rather than the downvote button? I'll give it a try: maybe it's because someone made an off-hand comment about Tesla shipping a default password, and you chimed in with an apologetic post that reads a lot like astro-turfing? > did this with almost zero paid marketing Traditional marketing. Tesla spends millions on marketing…

I am not affiliated with Tesla or paid by them in any way, if you're implying that. Was also not making apologies for shipping devices with guessable passwords, that's obviously a serious screwup that needs to be fixed - ideally at a level of changing the engineering culture if that's what it takes. But the rest of this thread treats that subject in depth, and I wouldn't contribute anything material to that discussio…

> Wasn't aware that they're paying people to astroturf though; first I hear of this. Do you have proof of it?

They are not and he can't/will not be able to provide proof because it's a false claim.

Re: Tesla PowerWall 2 Hack

#154
post #36

This is an amazing lack of security best practices. To me, this screams outsourced. Given how many people hate Tesla, they need to be taking this seriously. This truly blows me away. This is "people should be fired" levels of organizational incompetence. There's no way some of these issues haven't already been noticed and put in the issue tracker. They're just not taking it seriously. It reminds me of Boeing to be pe…

It does not strike me as outsourced, given what we know about software engineering practices at Tesla: https://twitter.com/atomicthumbs/status/1032939617404645376

Yeah, some random Twitter account that was never substantiated. Fact: He never provided proof he is who he said he was.

Re: Tesla PowerWall 2 Hack

#155

Earlier quoted context omitted.

Could always send out fake registration emails/postcards to collect serial numbers (which most people wouldn't consider especially sensitive info)...

I had a very similar thought regarding gaining API keys for Tesla vehicles after realizing I can get generate API key knowing only my Tesla Account user name and password only. Honeypot free WiFi at a Tesla Super Charger with a legit looking login page: “Free WiFi for Tesla Customers, Login to your Tesla account to access.” API End points include vehicle unlocking, speed limit settings, etc. Some are not available wh…

That Honeypot vulnerability is true of any service that has a login. Go to say Comcast sales office or whole foods for Amazon.

Re: Tesla PowerWall 2 Hack

#156
post #38

Earlier quoted context omitted.

> Just don't buy it if you don't like it. You say that about a security issue that could blow California's power grid in minutes.

In fairness, so could a strong breeze, apparently. Thanks, PG&E!

Alright, I'll admit you made me laugh :D

Re: Tesla PowerWall 2 Hack

#157
post #20

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

Reminds me of a time when an ISP would provide their customers routers where their default Wifi passwords could be derived from their SSIDs. A free app would allow you to connect instantly to practically any Wifi network in the city.

If anyone wondering https://github.com/ProZsolt/upc-keys

Re: Tesla PowerWall 2 Hack

#158

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

> and anything you can do without blowing that fuse won't damage the grid That's what you'd think. But I have actually done damage to the grid and had that fuse still in one piece. I accidentally connected the -HV line of a neon light installation to ground. After I could see again I realized the power had gone out. I called my boss (landline still worked) who lived more than a kilometer away from the workshop and th…

I'm sorry, but I don't believe one bit of your story.

Ohm's law dictates that it's be impossible for your HV generator (neon transformer) to outpout a HV voltage when connected to the grid (you'd need thousands of kWs).

Just impossible

Re: Tesla PowerWall 2 Hack

#159
As I'm reading comments here I can't help but remember that Elon Musk was restrained at PayPal from switching the company's server platform from Linux to Windows.

It wasn't until Microsoft tried converting Hotmail from FreeBSD to Windows (and failed, and then overhauled Windows) that Windows Server was both fast and reliable enough to be used in this way.

Security review for products like this requires a real world appetite for testing. Switching PayPal from Linux to Windows requires testing. The bulletproof glass on the cybertruck obviously should have first undergone testing...

Re: Tesla PowerWall 2 Hack

#160
post #89

Earlier quoted context omitted.

Yes - but IMO, as soon as you've shed any significant amount of load, you've failed. If just 10% of a nationwide grid is down, there's a good chance the phone network won't work, internet will be down, trains won't run, credit card/payment systems won't work, etc. All those things have primary and backup systems, but somewhere in the chain of dependencies there will be both a primary and backup that have been shed, a…

American here. Trains already don't run, no real net change.

Trains still very much run in the US.
Post reply on HN