Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

71–80 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#71
post #55

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

[deleted]

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#73
post #57
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

I think the key here...is to allow the user to gain control over his device and/or take it offline if it pleases him.

I wonder how long it will be before we start to see legal or regulatory interventions in this area. Mandatory self-updating and phone-home functionality is rapidly infecting technologies we rely on every day, from our cars to our home computers to our TV sets.

This always-connected, always-updated approach inevitably introduces some risks. It often causes intrusions into privacy or brings changes after purchase that users of these technologies don't necessarily want.

Competition in these markets is evidently insufficient to provide alternatives for those who don't want anything to do with this modern culture. I don't believe that is limited to a small group of eccentric tinfoil-hat fans any more.

Hopefully it won't take some sort of widespread disaster to wake the politicians up to the dangers here, though given the past performance of the political class around the world when it comes to technology issues, I'm not particularly optimistic.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#74
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

It's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income".

People who assume the world is fair will always find the justifications for why any status quo is valid.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#75
post #55

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#76
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

>Someday, all cars from a particular brand will be made to crash during rush hour.

This is also why it's always very, very wrong to compare potential faults of automated cars to humans as in "the automated car is X percent safer!", becuase it ignores the fact that mistakes in automated systems, at least as they are built now, are highly correlated.

If there is one bug in an ML system that is rolled out to an entire fleet that results in an unknown weather condition leading to fatal crashes you may create mass carnage.

Human driver errors are not correlated like this, which makes them much more robust as an ecosystem.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited

But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000?

Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Neither of those groups seem particularly likely to change their mind for an extra zero or two.

The "pay more than the black market will" model works for smaller bugs, but for ones like this that would immediately get every three letter agency on the planet trying to find you, the $50,000 isn't a valuation of the worth of that bug report, it's a gratuity. And for the average bug reporter, that's an extremely nice one.

Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No.

The solution to this is to have legal requirements for security, and extremely heavy fines for having released dangerous software (some portion of this fine financing a similar bug bounty program). Take the option of how much money to hand out away from the companies, and they'll be incentivised to take security much more seriously in the first place.

Of course, this requires lawmakers to have a basic understanding of technology, so we're at least 20 years and 3 major catastrophes away from getting anywhere near that actually occurring.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#78
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.

It was $50,000:

> He didn’t end up getting a new Tesla, but the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit:

You're looking at the $5,000 bounty awarded for exposing Supercharger-related data that Tesla "didn't want [...] out there", which is obviously a much less severe issue than remote control of the entire fleet.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#79
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.

No, $5k was for an earlier bug. "the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit"

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#80
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

Whoever did this would likely select some combination of valuable/soft/flammable targets. Control over a sizable fraction of all vehicles in a country would enable them to create utter pandemonium in tunnels, bridges and underpasses during rush-hour - even larger highways. Aside from fire, I'd imagine that the "disable vehicle on sensing a crash" functionality would end up being hackable as well. Cars on the whole ha…

>disable vehicle on sensing a crash

Most vehicles won’t let you reprogram the firmware without power cycling the car. Disable sensing of a crash is definitely its own ECM that is on a high priority bus. I am assuming your common <$40k car. When you head into bmw, merc Benz land this statement changes slightly.

Post reply on HN