Live data from Hacker News

Running Tesla Model 3's computer on my desk using parts from crashed cars

bugs.xdavidhu.me

201–210 of 356 posts

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#201
post #192

Earlier quoted context omitted.

Then why wasn't it a problem before? People have always been able to install aftermarket or possibly even hacked together physical parts. If there was liability you'd expect some sort of shield blocking access to, for example, the hydraulic system for the brakes. As it turns out though blatant irresponsibility is quite rare (depending on your definition anyway) since people have a strong self interest in not endanger…

> Then why wasn't it a problem before? It is. Thousands of people have died because of aftermarket headlights. Harder to assess, but probably much larger, is the number of excess deaths from nitrous oxide etc. emitted by modified cars.

There are about 3000 deaths per year in Sweden attributed to position from cars, and 300 physical accidents. So it is a really big issue, but it is almost impossible to make people understand that their car use and modification mains people.

Modified cars can release 1000x more polution, on streets with 800 daily cars that will have an affect.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#203
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

And as we all know, if you're smart enough to get root access, your neighbours children playing football in the street should be subject to the risk of you driven a car that claims to have full self driving with custom code on it.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#204
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

The interesting part is this implies that Tesla cars have static certifcates that don't rotate. (Whoops.)

My read of the output in the post when they tried to SSH to the device was that Tesla are actually doing the right thing here and using an SSH certificate authority, which allows issuing certificates signed with a private key authorising access to a subset of devices (optionally for a defined period of time). https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Certificate-b... has more information, but in summary unless the private signing key is compromised in some way this is entirely legit. I'd hope that they also have some mechanism for distributing a new public key if the signing key does get compromised but who knows.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#205

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

> Tesla treats the firmware as licensed software

This would be okay if there's a way to reject the license and install my own firmware.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#206
post #27

I used to work for a company that made third party scan tools. We had racks of ecus disconnected from the car with just a diagnostic connector and power. nothing got to a real car without first trying it on the rack. I remember on time we figured out a bmw (pre obdii) had the bytes offset from the standard documentation (it was a semi-standard protocol that some other cars used at the time), we went from we communica…

You don't know anything about late-90s Lucas/SAGEM GEMS ECUs do you, or Range Rover BeCMs?

I'm currently picking apart the firmware in those because it is now impossible to get replacement ignition key fobs, and it just can't be that difficult...

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#208
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#209
post #179

Earlier quoted context omitted.

Normies get scammed on Discord into pasting commands into their browser console. As a pedestrian I prefer for most people to not have root access to their multi-ton fast-moving killing machine.

Agrred, but it is remote root access is the danger, they already have root access to the physical dangerous things.

That is blatant whataboutism. Stop performing mental gymnastics and accept that what you personally want is not what’s good for society as a whole.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#210

Earlier quoted context omitted.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

I don’t think that’s the reason, seeing as a car is already endangering everyone around it by existing. More likely about keeping the tooling to diagnose issues proprietary and expensive.

You could screenshot this and put it under the definition of “perfect being the enemy of good”
Post reply on HN