Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
1–10 of 43 posts
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#2Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#3The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine.
Even if they did require some sort of signed message from the charger, since anyone can buy a "wall connector" charger for home the private key would already be out there (unless a visitor had to pair their per-car key before they could use your charger? That sounds like bad ux)
There's already some people in the twitter comments talking about this as a security issue, so I'll respond do that too.
I guess you can sort of say this is a security issue (like I'm sure with enough work you could short the battery or such)... but jamming such a device into a car would be about as obvious as shoving a brick through the window, keying the paint, or any of a number of other physical attacks. This is the same sort of security issue as the security issue of "car's glass windows can be broken by a determined malicious individual". We don't run around with a fear of "cars aren't secure because a malicious person could put a brick through the glass", and a fear of "a malicious person could open the charge port and do something" is way further down the list of any reasonable person's concerns imo.
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#4But sometimes these sorts of things have a larger impact than it seems at first. Looking forward to future stories of how teen hacker activists use this security flaw to take down “the man”.
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#5This seems to firmly be in the realm of "eh, working as intended, who cares". The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine. Even if they did require some sort of signed message from the charger, since…
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#6This seems to firmly be in the realm of "eh, working as intended, who cares". The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine. Even if they did require some sort of signed message from the charger, since…
But it is Tesla, so people has to make a drama about it
Where's the drama?
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#7Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#8I’m having a hard time coming up with a reason why there needs to be any replay protection here. That port is supposed to open without unlocking the car. You can approach a locked Tesla and press the button on a charging connector and it’ll open. The whole thing is unauthenticated by design.
I get a strange amount of vitriol from anti-EV folks where I live, I could imagine somebody putting a metaphorical potato in the metaphorical tailpipe. Although that type of person is more likely to use a screwdriver than a replay attack.
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#9Earlier quoted context omitted.
But it is Tesla, so people has to make a drama about it
The OP on twitter says its not going to help you pwn Teslas, and as of the time of commenting every comment on this post has the same opinion that this is ok. Where's the drama?
'...some people in the twitter comments talking about this as a security issue...'
Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
#10I’m having a hard time coming up with a reason why there needs to be any replay protection here. That port is supposed to open without unlocking the car. You can approach a locked Tesla and press the button on a charging connector and it’ll open. The whole thing is unauthenticated by design.
Doesn't mean that it is a bad design.