Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

171–175 of 175 posts

Re: Tesla PowerWall 2 Hack

#171
post #25

Earlier quoted context omitted.

Because you might want to control it from your phone or laptop .

And so might anyone in WiFi range apparently.

Well, not when the security issue is fixed. Being able to do the things I described is not dependent on the existence of that security issue, ya know.

Re: Tesla PowerWall 2 Hack

#172

Earlier quoted context omitted.

> and anything you can do without blowing that fuse won't damage the grid That's what you'd think. But I have actually done damage to the grid and had that fuse still in one piece. I accidentally connected the -HV line of a neon light installation to ground. After I could see again I realized the power had gone out. I called my boss (landline still worked) who lived more than a kilometer away from the workshop and th…

This is exactly what RCDs are for - with a huge earth leak like that (and therefore L/N imbalance) it would have tripped within milliseconds, before cooking the grid. I am surprised by how infrequently they seem to be used outside of the U.K. - I’ve just rewired my house in Portugal as it was completely unearthed, and just had fuses, no RCDs.

Fuses or breakers? In the US everything is on individual breakers, but only bathrooms have GFCI (RCD) outlets.

Re: Tesla PowerWall 2 Hack

#173
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more). Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

> "Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more).

Ridiculous. Please don't put out this kind of nonsense. Responsible disclosure is to protect the users of software. Supply chains cannot and do not respond instantaneously. You cannot fix a security problem within microseconds. There MUST be some delay between disclosure to the software provider and the actual release. Otherwise you're just endangering the public. How much delay is certainly a point of discussion, but no one is saying "no delay".

Re: Tesla PowerWall 2 Hack

#174
post #54

Earlier quoted context omitted.

I think this comment highlights a lack of understanding what responsible disclosure is about. It's there to reach the best possible tradeoffs to protect consumers and force a quick turnaround with fixes. Just publishing vulns, which the vendor might not even see or learn about(!), will not help in getting things improved and puts consumers knowingly at risk at scale.

I understand perfectly well what it is. But see my sibling comments, that reflect an agreement with the concept of "coordinated disclosure", rather than "responsible disclosure", which gives an implication that I am being irresponsible if I do not work to the vendor's needs and priorities.

"coordinated disclosure" is a newly invented term that I've never seen used anywhere in industry. Please don't simply invent new vocabulary and then define it as the standard.

Re: Tesla PowerWall 2 Hack

#175
post #3
post #2

Did they even try to submit these issues to Tesla? They have a bug bounty program and have been reasonably good about patching issues in vehicle software. If not, this is pretty irresponsible disclosure.

This is not a bug. This is irresponsible behaviour on the side of Tesla, providing hardware that is so open to abuse. With potential effects to the grid as well.

Nonsense. You can twist any bug into "irresponsible behavior".
Post reply on HN