Live data from Hacker News

Running Tesla Model 3's computer on my desk using parts from crashed cars

bugs.xdavidhu.me

161–170 of 356 posts

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#161
post #27

I used to work for a company that made third party scan tools. We had racks of ecus disconnected from the car with just a diagnostic connector and power. nothing got to a real car without first trying it on the rack. I remember on time we figured out a bmw (pre obdii) had the bytes offset from the standard documentation (it was a semi-standard protocol that some other cars used at the time), we went from we communica…

That's super cool, I'm currently struggling with scan tools for a 1999 Mercedes E300 Turbodiesel. I had one that worked OK for about a decade (Autel something or other) with a 38pin connector, but it recently bricked itself with a message like "connect via USB to Updata" which I assume means its firmware somehow erased itself. Cannot figure out how to "updata" it, doesn't seem to connect via USB, the Autel software r…

> All that is to say, this space is ripe for some open hardware/software love.

There's just so many computers and what-not in modern cars that this is a very tall ask. You'd need a project on-par with HomeAssistant to get anywhere.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#162

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

No, one can do that anyway. There is basically no real way to stop folks from modifying their cars. It can be made more difficult, sure.

This is about selling tools and access. It's another profit pipeline for car OEMs.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#163
Anyone finding this fascinating, please check out Openinverter Forum [0]. Ton of work has been done in decoding CAN messages, DBC files are floating around, open source firmware and controllers are available for Tesla and others components, mostly inverters and chargers but there are overlaps with the VCU and displays as well.

[0] - https://openinverter.org/forum/

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#164
post #142
post #21

Earlier quoted context omitted.

> Whilst cranking, an ICE car will drop to around 6 volts (then maximum power is extracted according to thevenim's theorem). > That means all computers etc will work at 6v. Not necessarily all of them. Plenty of stuff will drop out while cranking; hopefully not the computers that run the fuel injection and ignition, though.

Interesting. I now know why my windshield wipers quit for a sec when my vw auto stop/start kicks back on.

Not a car engineer, but those motors can be pretty high A, so this could also just be a feature that helps the starter get as much power as it can while cranking.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#165

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

You can feel that way, but plenty of car configuration has always been locked away and walled off, and manufacturers make a tidy profit selling software licenses to dealers and mechanics to perform basic diagnostics. Proprietary software is big business what can you do.

Definitely not always. It used to be that a mechanic or a skilled owner could tune, modify, repair or replace absolutely anything in your car. That was basically since the invention of the car, up to somewhere in the 2000s. And even then, various hackers and pirates made sure almost anyone could get their hands on the software. In fact, many mechanics these days use 3rd party software because the manufacturer refuses to sell them their version or even that version doesn't have all the features.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#166

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

You can translate that to corresponding car-purchases, i.e. vote with your wallet.

Really? Which car manufacturer officially provides you a root access to your vehicle?

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#167
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#168

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

That kind of thing is always the stated justification but never the real reason.

Almost invariably when that excuse is trotted out, there are are usually many things that are much more common that are also far more dangerous. For example, texting while driving or driving with bald tires in the wet are both 100x more dangerous than anything almost anybody would do by modifying the car's software.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#169
post #162

Earlier quoted context omitted.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

No, one can do that anyway. There is basically no real way to stop folks from modifying their cars. It can be made more difficult, sure. This is about selling tools and access. It's another profit pipeline for car OEMs.

Perhaps it is also about liability. Otherwise, we would have people installing OpenClaw on their Teslas.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#170

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

> The underlying tension is that "you own the car" means something very different from "you own the software running the car."

How is this different from the 2000s, or the 90s, or even before, when the normal thing to do with commercial software was to purchase a license to use said software and a physical medium containing a copy? You'd also then not "own the software", but you owned the right to install a copy on your own computer and use it. That worked without having to hand over the keys to your own computer.

Sure, the physical delivery medium is gone, but that's just a detail. Why do we now think that just because we license software for use, we can't be in ultimate charge of our own devices?

Post reply on HN