Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

41–50 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#42
post #11

Earlier quoted context omitted.

Care to elaborate on why you believe this?

Not the OP, but the precedents are here: Always-connected cars (eg. teslas): check. Being able to take control of a car via the CAN bus[1]: check. The only thing missing in the exploit chain is something that allows the attacker to jump from the modem/infotainment system to the CAN bus or ecu. [1] https://www.wired.com/2016/08/jeep-hackers-return-high-speed...

Try rental cars.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#43
post #34

> The hacker shared the data on the Tesla Motors Club forum, and the automaker seemingly wasn’t happy about it. > Someone who appeared to be working at Tesla posted anonymously about how they didn’t want the data out there. > Hughes responded that he would be happy to discuss it with them. > 20 minutes later, he was on a conference call with the head of the Supercharger network and the head of software security at Te…

The hack you are talking about is unrelated to the one that let him control the Tesla network. In that one it sounds like he just put together a custom client that requested supercharger data from Tesla, which I wouldn't really consider hacking.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#44
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

I definitely think Tesla can be over aggressive with their updates. However that doesn't mean that the basic idea of remote updating cars is inherently flawed or unsafe when compared with the alternative. It is all about trade-offs.

Both the Prius[1] and the Model 3[2] had similar software bugs related to their anti-lock brakes. Both companies had a software fix a few days after the bugs were discovered. Tesla's fix was pushed out immediately to every vehicle. Toyota couldn't push out a fix. They had to issue a recall and have a technician update the software whenever that car ended up being serviced. How many months or more likely years did it take for every Prius to be updated with the software? How many miles were driven in cars that were known to have faulty brake software because it was hard to update them? You have to consider situations like this when discuss banning remote updating.

[1] - https://www.networkworld.com/article/2245704/toyota-to-recal...

[2] - https://www.wired.com/story/tesla-model3-braking-software-up...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#45
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

Infosec is a worse gov regulation than drug prohibition. It will do little than make naive people feel better.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#46
This is what holds me back from 'smart' devices that have the potential to cause real harm...

We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with.

Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it.

Until then, I'll only want to buy cars made before 2010.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#47

Earlier quoted context omitted.

Certified autoshops are a solution in the same way that Norton is a solution for PC malware. Problem solved?

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible…

People still want regular map updates, live updating traffic information, and play back stuff from their phone on the in-car entertainment system. All this exposes cars to data communication outside of the car repair shop. Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#48
The pricing on these bug bounties always blows my mind.

If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#50

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

Maybe, maybe not. What happened to Garmin's share price?
Post reply on HN