Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

121–130 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#121

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

Yet this person did the right thing anyway and reported the vulnerability responsibly. So seemingly the level of the bounty was reasonable enough that it worked as intended, and a much higher bounty would have been a waste of money for Tesla.

I think the high likelihood of being caught and going to prison is also already a pretty big deterrent for people. Just think of all the challenges of actually pulling a hack like this off without being caught. For one thing, just the poking around that led to the discovery of the vulnerability has probably already logged a bunch of potentially suspicious activity linked to this guy's VIN number. So even if he sold it to someone else who did the hack he could probably be caught already. If he tried to orchestrate the hack himself, not only does he need to not be caught directly, but he'd also have to make a very large, very suspicious short trade right before the hack without it being traced back to him. Plus there's always a possibility that Tesla would have been able to lock him out quickly anyway or had some other kind of rate-limiting or other measures in place to prevent significant damage, or that even if he pulled off the hack perfectly the stock price wouldn't drop as much as expected.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#122
post #96
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap. The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, ab…

Props to you for realizing that. That's a good move you took, I feel not many would do the same, sadly.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#123

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

When you sell to the bad guys you have to factor in the risk-price of 20 years in the US prison system.

Bounty payers enjoy a hefty discount when they waive their right to prosecute.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#124

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I get that it doesn't seem to make a lot of sense, but is there some market principle that can be used to explain why so many companies act as they do, and that it is in fact rational? Must it be a black swan fallacy?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#125
post #61
post #14

Earlier quoted context omitted.

It's like being in 1995 and predicting that Windows botnets will be created. The coming disaster is inevitable. State-sponsored hackers are not going to ignore the opportunity. They probably have the capability already, in dozens of countries, and are just waiting for orders from the leaders. If war is starting, the order will be given. Sanctions could be enough to trigger it.

So you predicted botnets in 1995 and ..... nothing much happened. botnets suck but there wasn't some world crashing event like the person above is predicting for computer controlled cars. All Windows computers didn't shut off on one day.

I'm struggling to understand your point. It's a different threat model; of course it will manifest differently, no? A mothership-style model seems much more vulnerable to every node being compromised than the decentralized vector Win95 botnets have to go through.

I could see arguing with the inevitability of the exploit -- Win95 botnets seemed much more inevitable to me than this Tesla mothership threat does. But it seems like you're arguing that they will both have similar impact if exploited. That doesn't make sense to me, because they're completely different threats, but it's possible I'm misunderstanding your argument in some way.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#126

Earlier quoted context omitted.

I wonder if at some level of bounty payment, you run into the problem of encouraging people to introduce bugs to get a bounty. Probably no one with commit access in a major tech company would risk their career for a few months salary. But for ten years' salary...

It just needs to be a subtle bug designed by someone much smarter than the comitter, that's plausibly deniable. They certainly don't need to understand how it works, or how it's going to be used months or years later. And I understand that this sort of thing happens with governments, and TLAs, and the people leave after a few years to start their own gig with VC funding and subsequent acquisitions and no-one's the wi…

Theoretically, one person who's reviewing a pull request could notice a flaw and decide to say nothing about it, hoping to exploit it later. That would be less risky than introducing the flaw themselves—although it does require lying in wait for the opportunity and could take arbitrarily long. But if person A introduces the flaw by mistake, and person B sees the opportunity...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#127
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

I've noticed a lot of older software engineers seem to avoid anything "smart", and quite a few of them are into vintage cars too. I don't think that's coincidental; my daily driver is approaching 50, and completely lacks any computer or electronics for its main purpose.

I dunno if that means anything. Some of my software engineer friends have Tesla cars and love that kinda stuff. Others have old cars with very little in the way of electronics. Some have both!

Gotta remember, that every day people entrust their lives to lots of software and electronic systems. Of course, it's important to have reasonable security measure taken, but just because something's electronic doesn't make that a bad thing.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#128
post #96
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap. The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, ab…

What indicators are you using to tell?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#129
post #78

Earlier quoted context omitted.

The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.

It was $50,000: > He didn’t end up getting a new Tesla, but the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit: You're looking at the $5,000 bounty awarded for exposing Supercharger-related data that Tesla "didn't want [...] out there", which is obviously a much less severe issue than remote control of the entire fleet.

Ah okay, thank you. Not sure why the $5000 figure stuck with me

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#130
Shit like this is why cars need to be functional without cellular / wifi access, and updates impossible without the user pressing a button, along with direct connection to the the car for features like summon.

Which is pretty much the opposite like Tesla operates.

Post reply on HN