Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

181–190 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#181

Earlier quoted context omitted.

Tesla uses a pretty different architecture from the dumpster fire that was OnStar. And probably other manufacturers will use their own designs. Unfortunately, this is one of those issues where we have to be lucky every time, and the bad guys only have to be lucky once. Given the number of different manufacturers whose systems have demonstrably been compromised in the past, the odds of avoiding catastrophic compromise…

I guess we should just give up and leave everything wide open then right? No point in trying to do defense in depth if someone will eventually hack something?

I didn't say that at all.

One plausible alternative is that we don't deploy systems like this, which have the ability to cause widespread damage including loss of life in moments, until we have worked out how to secure them properly against a single point of catastrophic failure like that. There are things that could be done to mitigate that threat in the meantime.

This is set against the knowledge that existing human-driven vehicles are involved in many tragic accidents per year, also causing widespread damage including loss of life. But there are other things that can be done to limit the damage there as well, without relying on autonomous vehicles as a silver bullet.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#182

Earlier quoted context omitted.

I think the key here...is to allow the user to gain control over his device and/or take it offline if it pleases him. I wonder how long it will be before we start to see legal or regulatory interventions in this area. Mandatory self-updating and phone-home functionality is rapidly infecting technologies we rely on every day, from our cars to our home computers to our TV sets. This always-connected, always-updated app…

Rest assured, the 'regulatory interference' will be in the direction of forbidding the user to gain control over his device and/or take it offline. Consumers don't have a voice here, and (given the Democrats' record) I don't see that changing regardless of who wins the upcoming election.

Fortunately, there is a world outside the US, and much of it is more enlightened. If other large markets impose limitations on this kind of technology or create a penalty regime for failures that makes it worthwhile for the manufacturers to invest in more reliable systems, that will probably benefit everyone indirectly, even users in the US if a US government of whatever colour sells them out.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#183

Earlier quoted context omitted.

The problem is that total separation is difficult to achieve with the requirements being placed on these vehicles. Sure, whatever is playing your favourite music tracks over the speakers probably doesn't need to know anything about steering and acceleration. However, your self-driving software is going to have a tough time getting your car to a location it doesn't know exists because its onboard navigation maps preda…

As others have pointed out, self driving software is inherently unsafe at this moment - we don't know how to make safe network-connected software yet. Anyway, this is moot in most cars, as they don't have sold driving software anyway.

If you read my comments elsewhere in this discussion, you'll see that I've been one of those people.

In this thread, I'm simply observing that there can't be a clear separation between control systems and information systems if we're going to achieve these kinds of autonomous functionality. We need a more nuanced solution.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#184

This is another reason why I think it's incredibly foolish to own a vehicle with an internet connection. Even if the vehicle doesn't support remote control like Tesla there may be a chain of bugs that could be used to do just that or cause other problems. That's not even considering the major privacy issues that come with such vehicles.

I remember a long time ago reading about the updates to mandated car electronics and thinking I never wanted to own a car newer than...1996 maybe? And now I can't even remember what I was thinking and why. It might have been OBD-II. Even a hard core luddite gets worn down.

There's a difference between local computer control and remote control. I prefer an ECU to all mechanical engines. I'm not a luddite.

I understand the security and privacy implications of always on internet connected GPS tracking and remote control.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#185
post #93

Earlier quoted context omitted.

> Another off the top of my head - competitors. Car manufacturers do plenty of shady things, but this would be ridiculously over the top. I don't think that would be a serious concern at all.

Did you hear about what eBay execs did?

Go on...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#186
post #135

Earlier quoted context omitted.

Yet this person did the right thing anyway and reported the vulnerability responsibly. So seemingly the level of the bounty was reasonable enough that it worked as intended, and a much higher bounty would have been a waste of money for Tesla. I think the high likelihood of being caught and going to prison is also already a pretty big deterrent for people. Just think of all the challenges of actually pulling a hack li…

What would be the legality of sharing the hack publicly and allowing someone else to exploit it while shorting the stock? I also wonder when something becomes a "hack". Some systems are so insecure you can almost accidentally exploit them. In this case the API just required an ID for access. How would someone know if that was by design, or a mistake?

> I also wonder when something becomes a "hack"

As soon as you access something you're not supposed to. If a house is left unlocked and you walk in and take a look around, you're trespassing and it's a crime. And of course if you cause any damage or steal something, that's an even bigger crime.

Except with hacking, the punishments can be even more severe relative to the actual crime committed, because almost nobody in the legal system will understand the details of what happened so they can make you seem as dangerous as they want. Just look at Aaron Swartz and countless other examples of the heavy charges that have been given out for very minor, borderline cases of "hacking".

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#187
post #180

Earlier quoted context omitted.

What was the half-life on that vulnerability? From the moment Lastpass wrote whatever the fix was to the point at which attackers can no longer exploit it afresh, how much time elapses? If it's a serverside fix, so that the number is something like "a day or so while it's deployed", that's your answer about why nobody is outbidding Lastpass for this bug.

I rather thought it was honesty that kept it from being bid on by bad guys. Even if they wouldn't bid more it's a big risk to pay so low. It's kind of a treasure trove to be able to read all passwords from a user of lastpass simply by showing them a website. It made me think that the next zero day on lastpass would probably be sold to someone else.

Who would buy it? That's the question I'm asking.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#188

Earlier quoted context omitted.

I remember a long time ago reading about the updates to mandated car electronics and thinking I never wanted to own a car newer than...1996 maybe? And now I can't even remember what I was thinking and why. It might have been OBD-II. Even a hard core luddite gets worn down.

There's a difference between local computer control and remote control. I prefer an ECU to all mechanical engines. I'm not a luddite. I understand the security and privacy implications of always on internet connected GPS tracking and remote control.

Sure, but ECUs existed before OBD-II. Obviously even OBD existed prior. Those standards are about communication and control.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#189

Earlier quoted context omitted.

> Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? The article says the max bug bounty was increased to $15k eventually, so it was even less than that at the time even though they gave him $50k. Kudos to whoever at Tesla stepped up and gave him extra. I'd seriously consider not reporting something like that for $15k unless I was worried…

It's pretty silly to suggest that a state-level adversary needs the help of the person who stumbled across the baked-in credentials in an obfuscated Python binary to accomplish a CNE task. If a state wants to target Tesla, someone will submit a petty cash request to contract someone else to develop Tesla vulnerabilities. If you're able to sell a Tesla vulnerability to the supply chain of a state-level actor, it's pro…

> It's pretty silly to suggest that a state-level adversary needs the help of the person who stumbled across the baked-in credentials in an obfuscated Python binary to accomplish a CNE task.

I didn't mean they'd want your help. I meant you might end up on some hacker watchlist. You'll get extra attention and scrutiny from government agencies which wouldn't have much upside IMO. Maybe at airports you'll be randomly selected more often so security agencies can look at your devices and try to clone them.

Would you really feel 100% comfortable going to China after being in the news as the person that could have controlled the entire Tesla fleet? I think there are hard to measure social costs for gaining that kind of notoriety and current bug bounty programs aren't properly compensating for them.

Post reply on HN