The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
The Big Tesla Hack: A hacker gained control over the entire fleet
71–80 of 195 posts
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#72Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#73This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…
I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).
I wonder how long it will be before we start to see legal or regulatory interventions in this area. Mandatory self-updating and phone-home functionality is rapidly infecting technologies we rely on every day, from our cars to our home computers to our TV sets.
This always-connected, always-updated approach inevitably introduces some risks. It often causes intrusions into privacy or brings changes after purchase that users of these technologies don't necessarily want.
Competition in these markets is evidently insufficient to provide alternatives for those who don't want anything to do with this modern culture. I don't believe that is limited to a small group of eccentric tinfoil-hat fans any more.
Hopefully it won't take some sort of widespread disaster to wake the politicians up to the dangers here, though given the past performance of the political class around the world when it comes to technology issues, I'm not particularly optimistic.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#74Earlier quoted context omitted.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
It's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income".
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#75The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#76Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.
This is also why it's always very, very wrong to compare potential faults of automated cars to humans as in "the automated car is X percent safer!", becuase it ignores the fact that mistakes in automated systems, at least as they are built now, are highly correlated.
If there is one bug in an ML system that is rolled out to an entire fleet that results in an unknown weather condition leading to fatal crashes you may create mass carnage.
Human driver errors are not correlated like this, which makes them much more robust as an ecosystem.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#77The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000?
Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Neither of those groups seem particularly likely to change their mind for an extra zero or two.
The "pay more than the black market will" model works for smaller bugs, but for ones like this that would immediately get every three letter agency on the planet trying to find you, the $50,000 isn't a valuation of the worth of that bug report, it's a gratuity. And for the average bug reporter, that's an extremely nice one.
Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No.
The solution to this is to have legal requirements for security, and extremely heavy fines for having released dangerous software (some portion of this fine financing a similar bug bounty program). Take the option of how much money to hand out away from the companies, and they'll be incentivised to take security much more seriously in the first place.
Of course, this requires lawmakers to have a basic understanding of technology, so we're at least 20 years and 3 major catastrophes away from getting anywhere near that actually occurring.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#78Earlier quoted context omitted.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.
> He didn’t end up getting a new Tesla, but the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit:
You're looking at the $5,000 bounty awarded for exposing Supercharger-related data that Tesla "didn't want [...] out there", which is obviously a much less severe issue than remote control of the entire fleet.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#79Earlier quoted context omitted.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#80Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.
Whoever did this would likely select some combination of valuable/soft/flammable targets. Control over a sizable fraction of all vehicles in a country would enable them to create utter pandemonium in tunnels, bridges and underpasses during rush-hour - even larger highways. Aside from fire, I'd imagine that the "disable vehicle on sensing a crash" functionality would end up being hackable as well. Cars on the whole ha…
Most vehicles won’t let you reprogram the firmware without power cycling the car. Disable sensing of a crash is definitely its own ECM that is on a high priority bus. I am assuming your common <$40k car. When you head into bmw, merc Benz land this statement changes slightly.