Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

101–110 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#101

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.

> I wonder why they aren’t paid in vesting stock.

Most people would far prefer cash

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#102

Earlier quoted context omitted.

There is some level of communication, but there really shouldn't be.

The problem is that total separation is difficult to achieve with the requirements being placed on these vehicles. Sure, whatever is playing your favourite music tracks over the speakers probably doesn't need to know anything about steering and acceleration. However, your self-driving software is going to have a tough time getting your car to a location it doesn't know exists because its onboard navigation maps preda…

As others have pointed out, self driving software is inherently unsafe at this moment - we don't know how to make safe network-connected software yet.

Anyway, this is moot in most cars, as they don't have sold driving software anyway.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#103
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

You're comparing apples and oranges. It can both be true that security (and overall software) quality is poor, and that automated buggy cars are better than erratic people.

However, when you are considering system risk (e.g. that a bad actor could crash 100k cars at the same time) the worst case outcome could be much worse than the mean outcome.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#104
post #61
post #14

Earlier quoted context omitted.

It's like being in 1995 and predicting that Windows botnets will be created. The coming disaster is inevitable. State-sponsored hackers are not going to ignore the opportunity. They probably have the capability already, in dozens of countries, and are just waiting for orders from the leaders. If war is starting, the order will be given. Sanctions could be enough to trigger it.

So you predicted botnets in 1995 and ..... nothing much happened. botnets suck but there wasn't some world crashing event like the person above is predicting for computer controlled cars. All Windows computers didn't shut off on one day.

I would disagree, sure botnets can't be used for threatening life directly; but botnets have been proven to be quite effective in attacking services and do denial of services attacks. The one thing we can take from botnets is, vulnerable and unpatched devices can be infiltrated in high numbers and attackers can lie low until they decide to pull the trigger.

Imagine even 0.1% cars being controlled, the mayhem and loss of life that they can cause is just immense.

Power plants are also dangerous targets in a similar sense, but hopefully there is network separation for control services.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#105
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

It's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income".

> It's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income".

That's maybe true for founders, but not really for hired executives:

> One major consideration that goes into how much a CEO should be paid is what other companies are paying. Compensation committees benchmark CEO pay against a self-selected peer group -- often 12 to 20 companies that may be of similar size and complexity, and have similar business models, according to Robin Ferracone, CEO of Farient Advisors, an executive compensation consulting firm.

https://www.cnn.com/2019/10/24/success/ceo-pay-packages/inde...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#106

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

Maybe, maybe not. What happened to Garmin's share price?

Great question. I think I'd say the big difference is that people, for the most part, aren't putting their/others lives in Garmin's hands when they use their devices.

That said, I think they have some hiking/trekking oriented products which could cause problems if you were relying on them.

The headline "electric car fleet hacked" is a lot scarier than "smart watches hacked".

Then again, maybe people really don't give a shit about this stuff, and these bounties are priced correctly.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#107
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

>Someday, all cars from a particular brand will be made to crash during rush hour. This is also why it's always very, very wrong to compare potential faults of automated cars to humans as in "the automated car is X percent safer!", becuase it ignores the fact that mistakes in automated systems, at least as they are built now, are highly correlated. If there is one bug in an ML system that is rolled out to an entire f…

I think this is a good point, and largely agree. However, there are also correlations in driver behavior, like it being more dangerous driving on July 4 or New Year's Eve in America as so many people celebrate and drive drunk, increasing accident rates.

According to NHSTA, 144 drunk-driving deaths on July 4, compared to 36 on average: https://www.bactrack.com/blogs/expert-center/35042821-the-mo...

I would say that's mass carnage.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#108

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.

I wouldn't necessarily want the stock of a company that I just found a critical vulnerability with.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#109

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

They only need to pay out as much as is necessary to incentivize you to be upfront and report it in private rather than starting a media fuss around it (you get fame and $0) or exploiting the bug yourself (you might get a jail term). Compared to these alternatives, $50K and a clean record isn't a bad deal.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#110
post #57
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

If you look at adversarial machine learning you'll see it is shaping up as a bit of an evolutionary battle. It is quite likely that a years-offline Telsa (or similar) could be deceived into a fatal collision.

We need safe updates with transparent documentation as to all the changes, with hardware enforced feature switches. Forcing them to go through an approval process doesn't sound bad until you've met regulators like the FAA -- or Apple.

Post reply on HN