Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

111–120 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#111
post #96
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap. The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, ab…

What was the half-life on that vulnerability? From the moment Lastpass wrote whatever the fix was to the point at which attackers can no longer exploit it afresh, how much time elapses? If it's a serverside fix, so that the number is something like "a day or so while it's deployed", that's your answer about why nobody is outbidding Lastpass for this bug.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#112
post #55

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

How long do you think it takes for someone to find an exploit? Sure, a long time ago I found problems in web pages by clicking "view source" and going "I wonder what happens if.." and doing POST/GET with a huge buffer, or with "\");...." embedded in it.

These days companies that take their security seriously are hopefully harder to exploit. If it takes someone a couple months of slow fuzzing/etc to find an exploit that is probably below market for the persons skills here in the US.

Maybe a part of these bug bounties should be not only how critical the bug is, but some metric of how much work the individual put in before finding the problem.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#113
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

As someone who’d already been a bit worried about future mass-car hacks, I found the zombie car hacking sequence in 2017's "The Fate of the Furious" particularly terrifying to see in the theater. Rewatching it now, it actually looks somewhat tame compared to what might be since the hacked cars only inflict property damage, not injury.

> Villainess: I want every with chip with a 0-day exploit in a two mile radius around that motorcade now.

> Computer guy: There's over a thousand of 'em

> Villainess: Hack ‘em all. It’s zombie time.

> [zombie cars drive around causing mayhem]

https://www.youtube.com/watch?v=TQmMnRQu9YQ

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#114

Earlier quoted context omitted.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.

I wouldn't necessarily want the stock of a company that I just found a critical vulnerability with.

Then you wouldn't want the stock of any tech companies, because people find critical vulnerabilities in all of them.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#115
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

I've noticed a lot of older software engineers seem to avoid anything "smart", and quite a few of them are into vintage cars too. I don't think that's coincidental; my daily driver is approaching 50, and completely lacks any computer or electronics for its main purpose.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#116
post #93
post #83

Earlier quoted context omitted.

Surely there’s more than 2 types. Another off the top of my head - competitors.

> Another off the top of my head - competitors. Car manufacturers do plenty of shady things, but this would be ridiculously over the top. I don't think that would be a serious concern at all.

Did you hear about what eBay execs did?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#117

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

We probably need to stop having these threads, because they're repetitive, usually pretty ill-informed, and prevent us from having discussions about the vulnerabilities themselves. All we do is recapitulate the same tedious discussion about how bounty prices work. That's fine, but maybe we should only have those discussions on stories about bug bounties, not any story where a bounty makes an appearance.

For the moment, rather than re-having this discussion, we can just note that bounty prices are what they are, and that no tech firm pays "existential" rates for new vulnerabilities (except, perhaps, Uber, where literally everyone involved in that story is now in the federal criminal court system).

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#118
post #98
post #88

Earlier quoted context omitted.

Agreed. Another could be solo blackhats who just want to make money, who have no state sponsorship. Tangental, but I also hesitate to create such a massive bucket for "mental instability" like that. It's easy to find when someone who does something difficult to understand, or against what we would do ourselves, and then just say "well they're mentally unstable." Definitely the case for some, but it seems like a lazy…

I was using "maliciously exploit" here to describe what would basically be the worst case scenario of such a bug (instructing every Tesla to deliberately crash at high speed). I don't think it's in any way a stretch to characterise someone who would do that as mentally unstable. Of course there's many other ways you could exploit such a bug, but in the context of a "multi-billion dollar" event, it's really only The B…

Someone could be sociopathic enough to cause the crashes, but still prefer the money. It definitely seems like you could negotiate for more if you can play the part of that sociopath and don't mind a little bit of extortion.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#119

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.

You can always take the $50K and buy Tesla stock with it. How is it any different?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#120
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

Public confidence is priceless in the automative space. The risk of bleedover onto the market segment as a whole would make that an incredibly risky (read: stupid) stunt for a competitor to pull, not to mention the legal and reputational risk if they're discovered.
Post reply on HN