Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

141–150 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#142
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Aren't there a lot of people shorting Tesla stock? Some of those would probably stand to receive a significant amount of $$$ if this were to happen.

That kind of incentive has led to underhanded behaviour in the past, so it wouldn't be surprising to see it happen again.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#143
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

>There is a huge cost to not adopting new safety measures

That statement doesn't seem meaningful to me in a vacuum, without further qualification. It's not at all guaranteed that safety features have net benefits, either measured financially or in estimated human welfare. Have you noticed there are a lot of high tech safety features in modern cars, but insurance companies are selective about which ones receive discounts?

If self-driving cars are substantially safer, insurance companies will be able to give substantial discounts. I vaguely remember Tesla making noises about providing insurance to their own customers, but I don't know if it came to anything.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#144

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

We probably need to stop having these threads, because they're repetitive, usually pretty ill-informed, and prevent us from having discussions about the vulnerabilities themselves. All we do is recapitulate the same tedious discussion about how bounty prices work. That's fine, but maybe we should only have those discussions on stories about bug bounties , not any story where a bounty makes an appearance. For the mome…

Or you could just minimise this part of the discussion, which HN makes trivially easy to do.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#145

Earlier quoted context omitted.

Maybe, maybe not. What happened to Garmin's share price?

Great question. I think I'd say the big difference is that people, for the most part, aren't putting their/others lives in Garmin's hands when they use their devices. That said, I think they have some hiking/trekking oriented products which could cause problems if you were relying on them. The headline "electric car fleet hacked" is a lot scarier than "smart watches hacked". Then again, maybe people really don't give…

[deleted]

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#146
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

In a couple decades I suspect getting a license will be as common as people getting motorcycle licenses today. Might happen.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#147
post #97

Earlier quoted context omitted.

It just needs to be a subtle bug designed by someone much smarter than the comitter, that's plausibly deniable. They certainly don't need to understand how it works, or how it's going to be used months or years later. And I understand that this sort of thing happens with governments, and TLAs, and the people leave after a few years to start their own gig with VC funding and subsequent acquisitions and no-one's the wi…

> They certainly don't need to understand how it works They must need to know something about it in order to verify that it does the malicious thing correctly. It's hard enough to get code right when there's a whole team of people who know exactly what it's supposed to do.

It depends on how active the person has been in choosing the target and the exploit. If a nation-state actor has pored over the source code for some time before/after approaching a person in a tech company with commit privileges, they might be in a position to give them code to introduce that's as limited as possible and which does exactly what they need it to, while seemingly being entirely in keeping with that person's prior work and the organisation's development practices. For the attacker, the less exposure their insider has to actively thinking about how to subvert the system that they have access to (which they could later confess to if questioned/arrested/jailed) and the fewer opportunities there are for someone to notice that something's amiss and for the person to come under suspicion, the better.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#148

This is another reason why I think it's incredibly foolish to own a vehicle with an internet connection. Even if the vehicle doesn't support remote control like Tesla there may be a chain of bugs that could be used to do just that or cause other problems. That's not even considering the major privacy issues that come with such vehicles.

I remember a long time ago reading about the updates to mandated car electronics and thinking I never wanted to own a car newer than...1996 maybe? And now I can't even remember what I was thinking and why. It might have been OBD-II.

Even a hard core luddite gets worn down.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#149
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Aren't there a lot of people shorting Tesla stock? Some of those would probably stand to receive a significant amount of $$$ if this were to happen. That kind of incentive has led to underhanded behaviour in the past, so it wouldn't be surprising to see it happen again.

I'm shorting Tesla stock. I consider short Tesla an investment that makes sense over time.

And no, I'm not a hedge fund. Just an investor. Not going to be funding hackers.

lmao... this hack just underscores how exceedingly lame Tesla truly is.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#150
post #31

https://medium.com/@mpesce/the-great-hack-part-one-attack-70... "The first thing that happens is nothing. Your smartphone stays black while you swipe at it and press the various buttons. Has the battery gone flat? You could have sworn you left the house with a full charge. Now you start to wonder how you’ll get your car out of the parking structure without a working mobile. That thought hadn’t occurred to you before.…

This reminds me strongly of Daniel Suarez' book Daemon, https://amzn.com/0451228731

Yeah. That's a great read too.
Post reply on HN