Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

21–30 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#21
post #12
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

Bosch has been doing electronic vehicle control systems since the first electric wiper motor. It is one of their core businesses.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#24
post #11

Earlier quoted context omitted.

Care to elaborate on why you believe this?

Not the OP, but the precedents are here: Always-connected cars (eg. teslas): check. Being able to take control of a car via the CAN bus[1]: check. The only thing missing in the exploit chain is something that allows the attacker to jump from the modem/infotainment system to the CAN bus or ecu. [1] https://www.wired.com/2016/08/jeep-hackers-return-high-speed...

Tesla uses a pretty different architecture from the dumpster fire that was OnStar.

Been a while since I looked in the details but from what I recall only very limited, well scrutinized communication is allowed to bridge the Ethernet subsystem over to the CAN bus.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#25
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#26
post #2

Pretty misleading to omit ", but fortunately he’s a good guy" in the title

Does it matter? Next time it might not be a good guy.

In the context of headlines, maybe. It seems a little more pessimistic with this omission.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#27
post #11

Earlier quoted context omitted.

Not the OP, but the precedents are here: Always-connected cars (eg. teslas): check. Being able to take control of a car via the CAN bus[1]: check. The only thing missing in the exploit chain is something that allows the attacker to jump from the modem/infotainment system to the CAN bus or ecu. [1] https://www.wired.com/2016/08/jeep-hackers-return-high-speed...

Tesla uses a pretty different architecture from the dumpster fire that was OnStar. Been a while since I looked in the details but from what I recall only very limited, well scrutinized communication is allowed to bridge the Ethernet subsystem over to the CAN bus.

Tesla uses a pretty different architecture from the dumpster fire that was OnStar.

And probably other manufacturers will use their own designs.

Unfortunately, this is one of those issues where we have to be lucky every time, and the bad guys only have to be lucky once. Given the number of different manufacturers whose systems have demonstrably been compromised in the past, the odds of avoiding catastrophic compromises in the future as cars gain more autonomous features don't look great here.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#28
post #12
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

The guys who have been making safety critical automotive electronics since it's infancy (https://en.m.wikipedia.org/wiki/Electronic_stability_control ) are getting questioned on core competency

-

Meanwhile there's the company who took Mobileye's LKA, which was already in cars with the same hardware but not continuously enabled because of inherent flaws related to non-moving objects... and turned it on all the time so they could call it Autopilot.

Then it killed some people because of the flaws that kept other manufacturers from using it the way they were.

And they're writing the software for self-driving cars? Who's running that ship lol

-

In a better world people with experience with safety critical stuff and the culture for it would partner with companies like Tesla to create something like a "plug in" system for SDCs. Where the safety guys could focus on defining a minimal viable envelope of operation the same way existing ABS and ESC systems mesh with drivers. Something like if the car is less than 100ms from crashing intervene separately of "normal" object avoidance

(And before someone nitpicks that's an arbitrary number of ms, yes there's no "isCrashing" variable, and yes it would be hard work to define how SDCs would handle intervention, but people crashing into parked firetrucks is worthwhile "hard thing" to solve)

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#29
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

Certified autoshops are a solution in the same way that Norton is a solution for PC malware. Problem solved?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#30
post #12
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

A “fire extinguisher” company makes many of the fire/smoke/overheat detection and suppression systems used in commercial and military aircraft. These kinds of companies are massive and have a lot more depth to them than you seem to realize.
Post reply on HN