Earlier quoted context omitted.
> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…
>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap. The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, ab…
The Big Tesla Hack: A hacker gained control over the entire fleet
111–120 of 195 posts
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#112The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
These days companies that take their security seriously are hopefully harder to exploit. If it takes someone a couple months of slow fuzzing/etc to find an exploit that is probably below market for the persons skills here in the US.
Maybe a part of these bug bounties should be not only how critical the bug is, but some metric of how much work the individual put in before finding the problem.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#113Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.
> Villainess: I want every with chip with a 0-day exploit in a two mile radius around that motorcade now.
> Computer guy: There's over a thousand of 'em
> Villainess: Hack ‘em all. It’s zombie time.
> [zombie cars drive around causing mayhem]
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#114Earlier quoted context omitted.
I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.
I wouldn't necessarily want the stock of a company that I just found a critical vulnerability with.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#115This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#116Earlier quoted context omitted.
Surely there’s more than 2 types. Another off the top of my head - competitors.
> Another off the top of my head - competitors. Car manufacturers do plenty of shady things, but this would be ridiculously over the top. I don't think that would be a serious concern at all.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#117The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
For the moment, rather than re-having this discussion, we can just note that bounty prices are what they are, and that no tech firm pays "existential" rates for new vulnerabilities (except, perhaps, Uber, where literally everyone involved in that story is now in the federal criminal court system).
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#118Earlier quoted context omitted.
Agreed. Another could be solo blackhats who just want to make money, who have no state sponsorship. Tangental, but I also hesitate to create such a massive bucket for "mental instability" like that. It's easy to find when someone who does something difficult to understand, or against what we would do ourselves, and then just say "well they're mentally unstable." Definitely the case for some, but it seems like a lazy…
I was using "maliciously exploit" here to describe what would basically be the worst case scenario of such a bug (instructing every Tesla to deliberately crash at high speed). I don't think it's in any way a stretch to characterise someone who would do that as mentally unstable. Of course there's many other ways you could exploit such a bug, but in the context of a "multi-billion dollar" event, it's really only The B…
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#119The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#120Earlier quoted context omitted.
> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…
Surely there’s more than 2 types. Another off the top of my head - competitors.