Live data from Hacker News

Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

twitter.com

1–10 of 43 posts

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#2
I’m having a hard time coming up with a reason why there needs to be any replay protection here. That port is supposed to open without unlocking the car. You can approach a locked Tesla and press the button on a charging connector and it’ll open. The whole thing is unauthenticated by design.

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#3
This seems to firmly be in the realm of "eh, working as intended, who cares".

The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine.

Even if they did require some sort of signed message from the charger, since anyone can buy a "wall connector" charger for home the private key would already be out there (unless a visitor had to pair their per-car key before they could use your charger? That sounds like bad ux)

There's already some people in the twitter comments talking about this as a security issue, so I'll respond do that too.

I guess you can sort of say this is a security issue (like I'm sure with enough work you could short the battery or such)... but jamming such a device into a car would be about as obvious as shoving a brick through the window, keying the paint, or any of a number of other physical attacks. This is the same sort of security issue as the security issue of "car's glass windows can be broken by a determined malicious individual". We don't run around with a fear of "cars aren't secure because a malicious person could put a brick through the glass", and a fear of "a malicious person could open the charge port and do something" is way further down the list of any reasonable person's concerns imo.

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#4
With the rise in gas prices this could be an issue on a traditional combustion vehicle. But outside of pranks and demos of potential issues for other products that use similar simple protocols I don’t really see how this can be useful on an EV.

But sometimes these sorts of things have a larger impact than it seems at first. Looking forward to future stories of how teen hacker activists use this security flaw to take down “the man”.

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#5
post #3

This seems to firmly be in the realm of "eh, working as intended, who cares". The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine. Even if they did require some sort of signed message from the charger, since…

But it is Tesla, so people has to make a drama about it

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#6
post #5
post #3

This seems to firmly be in the realm of "eh, working as intended, who cares". The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine. Even if they did require some sort of signed message from the charger, since…

But it is Tesla, so people has to make a drama about it

The OP on twitter says its not going to help you pwn Teslas, and as of the time of commenting every comment on this post has the same opinion that this is ok.

Where's the drama?

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#8
post #2

I’m having a hard time coming up with a reason why there needs to be any replay protection here. That port is supposed to open without unlocking the car. You can approach a locked Tesla and press the button on a charging connector and it’ll open. The whole thing is unauthenticated by design.

On my 2017 model x the charging port is locked shut when the car is locked.

I get a strange amount of vitriol from anti-EV folks where I live, I could imagine somebody putting a metaphorical potato in the metaphorical tailpipe. Although that type of person is more likely to use a screwdriver than a replay attack.

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#9
post #5

Earlier quoted context omitted.

But it is Tesla, so people has to make a drama about it

The OP on twitter says its not going to help you pwn Teslas, and as of the time of commenting every comment on this post has the same opinion that this is ok. Where's the drama?

Here:

'...some people in the twitter comments talking about this as a security issue...'

Re: Tesla's charging ports use a standard msg to open on 315MHz and can be replayed

#10
post #2

I’m having a hard time coming up with a reason why there needs to be any replay protection here. That port is supposed to open without unlocking the car. You can approach a locked Tesla and press the button on a charging connector and it’ll open. The whole thing is unauthenticated by design.

The main issue will be TV-b-Gone style trolling tools. And the open charge ports may attract vandalism.

Doesn't mean that it is a bad design.

Post reply on HN