Live data from Hacker News

Hackers manage to unlock Tesla software-locked features

electrek.co

91–100 of 773 posts

Re: Hackers manage to unlock Tesla software-locked features

#91
post #74
post #57

Earlier quoted context omitted.

The exact same way you should be able to install your own software on your iPhone

your phone isn't a 3500 lb metal box of death on public roads with other cars, cyclists, and pedestrians

The road worthiness of your modded car is a question between you and the DMV, though. Once you start adding a fifth wheel to your Lada, it's not the manufacturer's responsibility.

(Tesla's software killing people is also not their responsibility, because you're 'supposed' to use it in a way that nobody actually uses it.)

Re: Hackers manage to unlock Tesla software-locked features

#92
post #2

Good. People who buy things should own the things they buy.

I want to add agreement to this, but to be more precise: people should own the things they buy and artificial (software ) means of locking people out of features shouldn't be allowed.

Re: Hackers manage to unlock Tesla software-locked features

#93
post #35

Earlier quoted context omitted.

Does enabling FSD come with any liability / terms of service? If it is backdoor enabled and the vehicle crashes, what is Tesla's liability? If the OTA patches to the system are needed and the car is running the base, unupdated (buggy) build, what is Tesla's liability? Alternatively, if a vehicle is running software that hasn't gone through Tesla's subscription how much of the liability for any software problems will…

If something is opened or modified without manufacturer consent, there is no question of liability because there is none.

So if you're using unlocked a version of FSD that has been recalled and don't get an OTA update then any and all faults that may be traced back to FSD even if it was clear that this is a bug in the software (e.g. the reason for the recall) the vehicle owner has full liability?

https://www.cnbc.com/2023/02/16/tesla-recalls-362758-vehicle...

Re: Hackers manage to unlock Tesla software-locked features

#94
post #68
post #2

Good. People who buy things should own the things they buy.

I've been thinking about this as a thought experiment lately. Let's say there's two versions of the car. Higher spec has heated seats, lower spec doesn't. Let's say it's a $1000 price difference. At what point below are you ticked off ? Level 1: The higher spec car has the physical seat heaters, all the wiring, all the plugs and all the software. The lower spec car has none of that. (I think this is how cars have alw…

Level 6: The lower spec car has the physical seat heater, all the wiring, all plugged in, all the software, and a setting added (for extra production cost) that makes it not work and can't be changed by the car owner.

We are talking about this one. The entire thread is about this one, and none of your options even passed through the conversation.

Re: Hackers manage to unlock Tesla software-locked features

#95

[flagged]

Care to elaborate?

Let's say you have a Tesla, but you didn't buy the "full" self driving package. You sell your Tesla to a third-party. Tesla (of course) resets the system to disable "full" self driving, but you have the tool to activate it so you turn it on for the new owner. Presumably you received money in exchange for the vehicle, as is traditional in our culture. You take some of that money and buy a 1958 Dodge D100 pickup truck and the Hayes Manual so you know where the spark plugs go. You use the remainder of the money to purchase a mix of mutual funds, Ford Motors stock, artwork by mediocre, yet somehow popular modern artists and maybe a crate of 2018 red wine.

In 10 years you still have the D100, though you have spent more money on spark plugs and air filters than you would have imagined possible. The Hayes manual is covered with grease stains so it is no longer re-sellable. The Ford Motors stock has (of course) tanked, but it allows you to justifiably rant on internet message boards. The artwork has appreciated and you recently sold it to a European collector for a profit. The red wine would have appreciated in value, but by this time you've drunk all of it.

Re: Hackers manage to unlock Tesla software-locked features

#96

Pretty sophisticated attack vector: low voltage attack on AMD secure execution environment during boot. I wonder how many tries you need to get whatever bits you need in the right place. Also, I imagine you only need to cut 12V wires to do this, but I admire the willingness to get in there direct on these systems. I'd be a little nervous to make those cuts personally. Buried in the article is the claim that this will…

>that's got to be really bad news for someone in vehicle security at Tesla. It says in the article: " Generally, these exploits are shared with Tesla, and it helps the automaker secure its systems." So it's only a matter of time till Tesla patches it.

More relevant quotes from the article:

> The group of hackers claims that their “Tesla Jailbreak” is “unpatchable” and allows to run “arbitrary software on the infotainment.”

And the full quote of what you put:

> Electrek’s Take

> Generally, these exploits are shared with Tesla, and it helps the automaker secure its systems.

> In this case, the hackers said that despite the exploit, they believe Tesla’s security is better than other automakers.

Doesn't seem like the security researchers actually shared the exploit with Tesla, at least as far as I understand.

Re: Hackers manage to unlock Tesla software-locked features

#97
post #30
post #2

Good. People who buy things should own the things they buy.

Okay great, but now the lowest cost of the car is an extra $10k because the manufacturing just got a lot more complicated as a result of not being able to build every car the same way.

That sounds like problem of a manufacturer not problem of a user.

Re: Hackers manage to unlock Tesla software-locked features

#98

Earlier quoted context omitted.

I'm somewhat torn too. IBM and I'm sure others have shipped enterprise hardware for years that was partially locked. You might get a machine with 16 cpus but you only paid for 8, for example, but you could license the rest as you grew. It seems a little similar and it was in no way underhanded, everyone knew what the deal was. However I'll echo what another poster said. I say Tesla should be free to sell whatever the…

I don’t mind hardware shipping locked and being an optional fee to unlock. I have paid for the rear heated seats in my model 3. What I’m vehemently opposed to is ongoing fees for things that don’t have ongoing costs. BMW wants to charge monthly for seat heaters or carplay, but those things are not a service and don’t have ongoing costs for BMW to provide. If anything creating an ongoing software lock creates an avail…

I feel different about extra cores on a CPU than I do about heated seats.

The manufacturing price delta between an 8 core CPU and a 16 core, nowadays is functionally meaningless.

The manufacturing cost between a car with heated seats and without headset seats is functioningaflly meaningful.

The way I see it, for things like heated seats or CarPlay, I'm already paying for the base hardware cost (plus some margin) as part of the base price of the car, charging me for the upgrade is charging me a markup on what I already paid for. Making it a service is insult to injury.

Re: Hackers manage to unlock Tesla software-locked features

#99

I'm torn. On one hand, I absolutely think that a capability available in the vehicle/device when you purchased it should be available for you to use, and not behind a software lock (heated seats, etc). On the other hand, an "upgrade" or 100% new software delivered via OTA (self driving, etc) seems a little more like it should be a separate thing.

From the perspective of a customer, what is the difference between a heated seat that doesn't work because it doesn't exist, and one that is locked out by software? Assuming the customer isn't paying up front for that feature. Some people don't want to pay for heated seats. Turns out the manufacturer found it cheaper to just include the hardware anyway rather than differentiate on the production line. What's the big…

> From the perspective of a customer, what is the difference between a heated seat that doesn't work because it doesn't exist, and one that is locked out by software?

In the former case, I didn't pay you money, so you didn't give me a good / service / whatever. That feels fair, because you need money to provide those things.

In the latter case, I didn't pay you money, so you didn't flip a switch. That seems like a dick move.

So I guess the difference is that in only one of these cases does it feel like the manufacturer is an asshole.

Re: Hackers manage to unlock Tesla software-locked features

#100

Pretty sophisticated attack vector: low voltage attack on AMD secure execution environment during boot. I wonder how many tries you need to get whatever bits you need in the right place. Also, I imagine you only need to cut 12V wires to do this, but I admire the willingness to get in there direct on these systems. I'd be a little nervous to make those cuts personally. Buried in the article is the claim that this will…

>that's got to be really bad news for someone in vehicle security at Tesla. It says in the article: " Generally, these exploits are shared with Tesla, and it helps the automaker secure its systems." So it's only a matter of time till Tesla patches it.

Although this seems unpatchable without an HW upgrade
Post reply on HN