Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

51–60 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#51
post #14

Earlier quoted context omitted.

Care to elaborate on why you believe this?

It's like being in 1995 and predicting that Windows botnets will be created. The coming disaster is inevitable. State-sponsored hackers are not going to ignore the opportunity. They probably have the capability already, in dozens of countries, and are just waiting for orders from the leaders. If war is starting, the order will be given. Sanctions could be enough to trigger it.

[deleted]

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#52

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

Maybe, maybe not. What happened to Garmin's share price?

How is that even remotely similar?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#53
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

Whoever did this would likely select some combination of valuable/soft/flammable targets. Control over a sizable fraction of all vehicles in a country would enable them to create utter pandemonium in tunnels, bridges and underpasses during rush-hour - even larger highways. Aside from fire, I'd imagine that the "disable vehicle on sensing a crash" functionality would end up being hackable as well. Cars on the whole had become less effective as murder weapons up until now, but I suppose that all changes when you can control them remotely via software at scale.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#54
post #8

Can y'all add "in 2017" to the title here?

This article is from three days ago (August 27th, 2020). I suspect the underlying issue was under a 3 year NDA/agreement. It would be misleading to label an article from three days ago from "2017," particularly as this is the first reporting about this ever.

> (I will note, I was never barred from disclosing any of this publicly in any way. As a courtesy, I felt it would be the right thing to do to hold off on public disclosure for a while, potentially indefinitely. Years later, it seems worthwhile to disclose this information and highlight just how far things have come and how Tesla's software security has improved dramatically since then.)

From https://news.ycombinator.com/item?id=24327485, so no NDA.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#55

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I think, if this had been abused, Tesla would be out of business.

But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#56
post #44

Earlier quoted context omitted.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

I definitely think Tesla can be over aggressive with their updates. However that doesn't mean that the basic idea of remote updating cars is inherently flawed or unsafe when compared with the alternative. It is all about trade-offs. Both the Prius[1] and the Model 3[2] had similar software bugs related to their anti-lock brakes. Both companies had a software fix a few days after the bugs were discovered. Tesla's fix…

> You have to consider situations like this when discuss banning remote updating.

Isn't that exactly what we're doing? If someone pushes out a malicious change, do you know how long it would take for that change to propagate to the entire Toyota fleet?

It wouldn't.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#57
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#58
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

lol wtf

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#59

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder if at some level of bounty payment, you run into the problem of encouraging people to introduce bugs to get a bounty. Probably no one with commit access in a major tech company would risk their career for a few months salary. But for ten years' salary...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#60
post #12
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

the guys who make power drills are writing the software for Self-Driving Cars[1]? Who is running that ship lol [1] https://www.bosch.com/stories/future-vehicles/

Perhaps due to knowing quite a few people whose careers were spent working with Siemens and Bosch machines in heavy industry, it seems unfathomable and mildly alarming to me that one can

- know of the existence of Bosch,

- be completely ignorant of the company being an absolute giant in the engineering space, and

- be confident enough that they're some tiny power drill manufacturer to mock them publicly without pausing to look them up

It's like hearing someone say "the guys who make the Xbox are providing cloud services for the Pentagon? Who is running that ship lol".

Post reply on HN