Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

151–160 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#151
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

> Specifically for the tech in vehicles example, it seems like a real double standard. Around 37,000 people in the US die in car accidents every year

Depends on the feature you're talking about. With self-driving cars, for example, there is no evidence that they are any safer than human drivers. In fact, it is possible that they are more dangerous than human drivers.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#152
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

When Coke's recipe was stolen and offered to Pepsi they turned them in. That is what every competitor should do.

https://thehustle.co/coca-cola-stolen-recipe

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#153
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

> Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? […] people who just like to cause chaos, and state-sponsored actors […].

Makes me think of the recent Twitter account take-overs. The amateur attackers acquired access which could have caused enormous damage, and used it to scam ~$100,000. The difference between $50k and $1m in bounty could have turned them towards responsible disclosure.

(That said: they probably hoped to scam much more. And they got caught. And the way they obtained access was probably way out of the scope of a bug bounty program / the law.)

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#154
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

How long do you think it takes for someone to find an exploit? Sure, a long time ago I found problems in web pages by clicking "view source" and going "I wonder what happens if.." and doing POST/GET with a huge buffer, or with "\");...." embedded in it. These days companies that take their security seriously are hopefully harder to exploit. If it takes someone a couple months of slow fuzzing/etc to find an exploit th…

Any one individual could put in an arbitrarily huge amount of work, or claim to have, in order find a bug.

How do we classify what constitutes work to find any particular bug?

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#155
post #57

Earlier quoted context omitted.

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

I think the key here...is to allow the user to gain control over his device and/or take it offline if it pleases him. I wonder how long it will be before we start to see legal or regulatory interventions in this area. Mandatory self-updating and phone-home functionality is rapidly infecting technologies we rely on every day, from our cars to our home computers to our TV sets. This always-connected, always-updated app…

Rest assured, the 'regulatory interference' will be in the direction of forbidding the user to gain control over his device and/or take it offline.

Consumers don't have a voice here, and (given the Democrats' record) I don't see that changing regardless of who wins the upcoming election.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#156

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.

[deleted]

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#157
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

You don’t need to pay more than the black market would, but the more you pay the more time people can spend on it. If the bounties are high enough, you can attract more, and better, white hats to test your system for you. The black hats are out there anyway doing what they will do.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#158
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

For a vulnerability of that scope, I assume selling it to a short-seller to publish in bad faith would be more valuable than selling on the actual black market anyway. Hell, the impression I get is that unless you're fairly well connected already, selling large $ value hacks on the black market isn't exactly easy (see Twitter hack).

I don't know if this is strictly legal either, but definitely more plausible deniability.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#159
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Are you kidding me? If money was my goal, 50k would be so insulting! A slightly more malicious person would brick the whole fleet as retribution.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#160
post #138

So how do vulnerabilities like this happen these days? I just work in games and everyone still knows having an API that takes a user ID (in this case the VIN) is asking to get abused. Is the description just a gross oversimplification of the hack or was Tesla security really that bad?

It seems like a classic case of mistaking (or not taking seriously enough) the difference between authentication and authorization. He accessed the server through the car's VPN, so there was an authenticated and authorized connection to the server.

However, an authorized connection to the server is not authorization to make any arbitrary request on the server.

It happens for the same reason that many games get MAX_INT high scores at launch.

Post reply on HN