Live data from Hacker News

Running Tesla Model 3's computer on my desk using parts from crashed cars

bugs.xdavidhu.me

261–270 of 356 posts

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#261

Earlier quoted context omitted.

That is blatant whataboutism. Stop performing mental gymnastics and accept that what you personally want is not what’s good for society as a whole.

It's not whataboutism, it's a legitimate question. How does it increase safety on the road to reject local SSH connections by a dumb user, when that same user can mess with the car physically?

How does adding another way to cause safety issues affect safety?

Give me root access so i can install openclaw.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#262
post #135

Earlier quoted context omitted.

I'd understand either of those, but I'd go with "tubing" https://www.3m.com/3M/en_US/p/c/electrical/wire-cable/tubing...

That's heat shrink tubing, but we're talking about one of these: [1]: https://www.holley.com/products/engine/engine_dress_up/hoses... [2]: https://www.oreillyauto.com/detail/c/dorman-conduct-tite/lig...

For performance vehicles I used adhesive-lined heat shrink tubing for basically everything.

[1] Braided tubing and [2] conduit, respectively.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#263

> " I needed this because both the computer and a screen were being sold with the cables cut a few centimeters after the connector (interestingly most sellers did that, instead of just unplugging the cables)." Can't you just solder some extra wires onto the cut off bits, rather than having to try and find a compatible cable? They've left the connectors in, and that's the hard bit, the rest is just wires

LVDS implies differential signals and are designed to minimize EMI and can be hard to splice while still maintaining signal integrity. They can support high data rates (ethernet cables also use twisted pair LVDS). Theoretically this should be feasible up to 100s or even 1000s of mbps

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#264

Earlier quoted context omitted.

That is blatant whataboutism. Stop performing mental gymnastics and accept that what you personally want is not what’s good for society as a whole.

It's not whataboutism, it's a legitimate question. How does it increase safety on the road to reject local SSH connections by a dumb user, when that same user can mess with the car physically?

Simplest example: a driver could probably disable attentive driving checks by pasting a script in from a web search in a few minutes. Nothing like an inattentive 3750 lbs weapon.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#265

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

I would love to lobby to change how the law works for these cases: for some definition of "firmware" (informally "software that ships with hardware and is not intended to be selected by the consumer like a computer operating system"), add a copyright exception so that modifying the firmware in situ is treated like modifying the physical hardware, because in practice they are in fact the same thing: a single component that does a single thing.

With this, the John Deere approach to gatekeeping vehicle repair would no longer be legally protected by the DMCA or by copyright law. All the other protections afforded by copyright law would still apply: you cannot rip the firmware off the hardware and distribute it, the manufacturer is under no obligation to help you modify it, etc.

However, tools which patch or circumvent antifeatures of the firmware would now be legal to use on hardware you own: it would be legal to patch out software locks, retune engine computers, etc.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#266
post #245

Earlier quoted context omitted.

Sure. Point is nothing has really changed. Largely there's no problem and to the extent that bad things happen it isn't something novel that's only just come up. It's not in and of itself an excuse to erode private ownership. If intervention is required then regulation should be passed deliberately by the legislature.

I dunno, I think there's a big difference between making digital modifications to software vs. making physical modifications to hardware. The risk profile is very different and non-obvious to your average car owner. It's the difference between trying to repair your leaky dishwasher vs. trying to repair the electrical panel in your basement.

Well both of those examples could potentially electrocute you or start a fire and both can be done by a homeowner if he feels like it.

I don't disagree that it's a bit different in certain ways but I feel like that's drifting off topic. It shouldn't be up to manufactures to determine these things unilaterally but rather the legislature. Particularly any justification to the contrary rings hollow in this case because there's a very strong conflict of interest.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#268
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

Having shell is extremely handy for further discovery. SO handy that if they were just gonna patch the bug and lock you out, you would simply not disclose it.

This is what happened. Tesla security received tons of bug reports that required root access to identify, yet they got a vanishingly small number of root vulnerability reports. This policy fixes that misincentive.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#270
post #45

Earlier quoted context omitted.

Automotive transients can be wild. I did a bringup with a board that had specified 100+v range specified for transients and finicky quality requirements on the output. The power supplies took up most of the (very large) board.

14v is not a transient, if your voltage was 12v with the car running, there's something wrong with the charging system (DC-to-DC in an EV, alternator/generator in an ICE) 13-14v is normal in all 12v automotive systems as the charging voltage

nit: Some vehicles can use a two stage charging system where if the ECU is not trying to charge the battery and the power draw is otherwise low, the voltage sits in a lower range rather than constantly float charging the battery. This can surprise you if you're trying to diagnose a battery issue!
Post reply on HN