The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I get that it doesn't seem to make a lot of sense, but is there some market principle that can be used to explain why so many companies act as they do, and that it is in fact rational? Must it be a black swan fallacy?
The Big Tesla Hack: A hacker gained control over the entire fleet
131–140 of 195 posts
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#132Earlier quoted context omitted.
I was using "maliciously exploit" here to describe what would basically be the worst case scenario of such a bug (instructing every Tesla to deliberately crash at high speed). I don't think it's in any way a stretch to characterise someone who would do that as mentally unstable. Of course there's many other ways you could exploit such a bug, but in the context of a "multi-billion dollar" event, it's really only The B…
Someone could be sociopathic enough to cause the crashes, but still prefer the money. It definitely seems like you could negotiate for more if you can play the part of that sociopath and don't mind a little bit of extortion.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#133This was the biggest line in the story, for me. You can spend $100k+ on a vehicle and you can’t even have security to protect it that was standard FIVE YEARS AGO.
Lack of 2FA is a showstopper for services an order of magnitude less expensive than a vehicle. Tesla simply must not care about security very much, a fact reflected in their low bug bounty prices.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#134The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#135The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
Yet this person did the right thing anyway and reported the vulnerability responsibly. So seemingly the level of the bounty was reasonable enough that it worked as intended, and a much higher bounty would have been a waste of money for Tesla. I think the high likelihood of being caught and going to prison is also already a pretty big deterrent for people. Just think of all the challenges of actually pulling a hack li…
I also wonder when something becomes a "hack". Some systems are so insecure you can almost accidentally exploit them. In this case the API just required an ID for access. How would someone know if that was by design, or a mistake?
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#136Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#137The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
Yet this person did the right thing anyway and reported the vulnerability responsibly. So seemingly the level of the bounty was reasonable enough that it worked as intended, and a much higher bounty would have been a waste of money for Tesla. I think the high likelihood of being caught and going to prison is also already a pretty big deterrent for people. Just think of all the challenges of actually pulling a hack li…
I think it's more likely that the person who reported the vulnerability would have done the right thing regardless of any bounty.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#138Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#139The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
I’ll bet a few QA engineers would like to be paid based on how much a bug they reported would have cost the company if released into production.
Re: The Big Tesla Hack: A hacker gained control over the entire fleet
#140Earlier quoted context omitted.
Tesla uses a pretty different architecture from the dumpster fire that was OnStar. Been a while since I looked in the details but from what I recall only very limited, well scrutinized communication is allowed to bridge the Ethernet subsystem over to the CAN bus.
Tesla uses a pretty different architecture from the dumpster fire that was OnStar. And probably other manufacturers will use their own designs. Unfortunately, this is one of those issues where we have to be lucky every time, and the bad guys only have to be lucky once. Given the number of different manufacturers whose systems have demonstrably been compromised in the past, the odds of avoiding catastrophic compromise…