Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

31–40 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#31
https://medium.com/@mpesce/the-great-hack-part-one-attack-70...

"The first thing that happens is nothing. Your smartphone stays black while you swipe at it and press the various buttons. Has the battery gone flat? You could have sworn you left the house with a full charge. Now you start to wonder how you’ll get your car out of the parking structure without a working mobile. That thought hadn’t occurred to you before. It’s the least of your worries. Still fussing with your smartphone, you gradually begin to realise you’re not the only one having this problem. In fact, it would seem that everyone waiting at the pick-up area is in various stages of agitation with their own smartphones. Some are pressing odd combinations of buttons, trying to reset the little beasties. Others, who have clearly had rough days now made worse, start to swear at their dead screens, as if cursing might shock them into life. It’s weird, and almost a bit funny. For a brief moment. The first smashing can be felt more than heard, a subsonic strike something like a vast drumhead being struck with a metre-wide mallet, but so quick, you barely even notice it until it’s over. The second one, however, isn’t far behind, and it’s a bit louder. That second thump gives away its location — whatever it was seems to be happening quite close by — in the direction of the parking structure. At just this moment a car cruises through the pick-up zone at full speed, barreling along at least 100 kmh. It’s only because of some very fast reactions that no one gets hurt as it passes by. As it zooms past, you notice there’s no one behind the wheel. Before you have any time to process that, another huge thump nearby causes a section of the barrier wall of an upper floor of the concrete parking structure to shear off. A pile of rubble falls to the ground not very far away from you."

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#32

Earlier quoted context omitted.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

Certified autoshops are a solution in the same way that Norton is a solution for PC malware. Problem solved?

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible if we allow personal vehicles to support the attack vector.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#34
> The hacker shared the data on the Tesla Motors Club forum, and the automaker seemingly wasn’t happy about it.

> Someone who appeared to be working at Tesla posted anonymously about how they didn’t want the data out there.

> Hughes responded that he would be happy to discuss it with them.

> 20 minutes later, he was on a conference call with the head of the Supercharger network and the head of software security at Tesla.

> They kindly explained to him that they would prefer for him not to share the data, which was technically accessible through the vehicles. Hughes then agreed to stop scraping and sharing the Supercharger data.

> After reporting his server exploit through Tesla’s bug reporting service, he received a $5,000 reward for exposing the vulnerability.

What's the difference between this and what Uber's former Security Chief was charged with?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#35
Isn't a "fleet-wide hack of autonomous vehicles" an oxymoron? They clearly aren't autonomous if they are controlled by an outside force that can be hacked.

Maybe it depends on perspective, with the manufacturer seeing owners as outside forces, from which their vehicles are autonomous? Rolled up with the liability question is the question of who does control the vehicles and who they are autonomous from.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#36

Earlier quoted context omitted.

Certified autoshops are a solution in the same way that Norton is a solution for PC malware. Problem solved?

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible…

I don't see how certification solves anything that just not doing OTA updates doesn't also solve.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#37

Earlier quoted context omitted.

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible…

I don't see how certification solves anything that just not doing OTA updates doesn't also solve.

It reduces the attack surface to places that have been verified to be following security obligations. Otherwise a physical attack becomes much easier because you just need to work at an auto-shop that doesn't pay much attention to you. The same sort of attack is still possible with certs but it's more difficult because it would require compromising both the shop and the person who vets their practices.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#38
post #12

Earlier quoted context omitted.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

A “fire extinguisher” company makes many of the fire/smoke/overheat detection and suppression systems used in commercial and military aircraft. These kinds of companies are massive and have a lot more depth to them than you seem to realize.

Wait until they learn a jar company makes aerospace parts...

https://en.m.wikipedia.org/wiki/Ball_Aerospace_%26_Technolog...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#39
post #12
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

If anything, Bosch is more of a car component supplier that happens to also make power drills on the side.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#40
post #8

Can y'all add "in 2017" to the title here?

This article is from three days ago (August 27th, 2020). I suspect the underlying issue was under a 3 year NDA/agreement.

It would be misleading to label an article from three days ago from "2017," particularly as this is the first reporting about this ever.

Post reply on HN