Live data from Hacker News

I'm being cyberattacked by Tesla, Inc

dreamstation.systems

71–80 of 127 posts

Re: I'm being cyberattacked by Tesla, Inc

#71
post #58

I'd try to contact Assetnote. Most (sadly not all) managed vuln scan companies are pretty sensitive to scanning stuff that doesn't belong to their client and could expose them to liabilities because they don't have permission.

Yeah, I'll try to do this, but I can't find anything better than the generic contact form.

Try search on LinkedIn. Often turns up folks who work there who you can reach out to.

Re: I'm being cyberattacked by Tesla, Inc

#72

> unintentionally be being a nuisance. As opposed to intentionally being a nuisance?

It’s just laziness on Tesla’s part because working your bare bones crew to failure isn’t the exception but the SOP. Same why you can’t reach anyone about Supercharger issues, this is by design to run as lean as possible for profits.

I see this in cyber clients that are perpetually short staffed and simply accept the degraded system because the consequences are minimal. If nothing important breaks, nothing changes.

Re: I'm being cyberattacked by Tesla, Inc

#73

I've been consistently attacked by ShadowServer who have the following sponsors, Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nih…

Report it https://www.cisa.gov/reporting-cyber-incident

Re: I'm being cyberattacked by Tesla, Inc

#74

Earlier quoted context omitted.

a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.

That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record. Hell, they issue certificates to IP addresses now. For cloud systems, ownership of an IP could be a few hours. This has almost certainly been deemed an acceptable risk.

This is why IP certificates are limited to a max lifetime of 6 days.

> IP address certificates allow server operators to authenticate TLS connections to IP addresses rather than domain names. Let’s Encrypt supports both IPv4 and IPv6. IP address certificates must be short-lived certificates, a decision we made because IP addresses are more transient than domain names, so validating more frequently is important.

https://letsencrypt.org/2026/01/15/6day-and-ip-general-avail...

Re: I'm being cyberattacked by Tesla, Inc

#75

I've been consistently attacked by ShadowServer who have the following sponsors, Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nih…

Calling vuln scanning from a non-profit a felony is a bit of a stretch. Many for-profit companies do similar vuln scanning and then threaten companies with security "scorecards". That is borderline extortion.

If the non-profit was walking down the road and rattling everybody’s door lock to see which are unlocked, and having a look around the windows to see if any are open, would that be a crime?

Because that is exactly what all of these vulnerability scanning companies are doing, and all of us sort of just… let them.

Re: I'm being cyberattacked by Tesla, Inc

#76
post #71

Earlier quoted context omitted.

Yeah, I'll try to do this, but I can't find anything better than the generic contact form.

Try search on LinkedIn. Often turns up folks who work there who you can reach out to.

Oh, and be sure to include "you're scanning a pool address so you're probably scanning a lot of other sites that don't belong to your customer". They should know it's potentially not one little web site.

Re: I'm being cyberattacked by Tesla, Inc

#77
post #75

Earlier quoted context omitted.

Calling vuln scanning from a non-profit a felony is a bit of a stretch. Many for-profit companies do similar vuln scanning and then threaten companies with security "scorecards". That is borderline extortion.

If the non-profit was walking down the road and rattling everybody’s door lock to see which are unlocked, and having a look around the windows to see if any are open, would that be a crime? Because that is exactly what all of these vulnerability scanning companies are doing, and all of us sort of just… let them.

If the neighborhood was constantly being canvased by criminals checking doorknobs, so your concerned neighbor went over to your house to check your doorknob, and then let you know if you accidentally left it open, would you also accuse your neighbor of being a criminal trying to break in?

Re: I'm being cyberattacked by Tesla, Inc

#78

I would assume the fastest way to actually make this stop would be to setup a bunch of honeypot exploits, trigger their detection and someone will figure out what they did wrong. Other than not, with these huge companies you have 0 recourse.

I did something like this a few weeks ago on my photography site: https://robertmay.photography/journal/meta-has-tried-to-scra... Meta not only hasn't noticed, but is currently sending about 11 requests per second to my site. I've also seemingly trapped one of those TV proxy scraper nets as I'm getting absolutely hammered by requests from all over the place now. I get maybe 10 legit visitors per day, and I'm currentl…

Return a HTTP 301 pointing to https://facebook.com?

Might make them scan themselves instead.

Re: I'm being cyberattacked by Tesla, Inc

#79

As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla , and my agents will probe anything under there as it is presumed to have explicit authorization. Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they…

One solution is to not set up and run a computer program that relies on bad information to perform automated cyber-attacks on third parties.

Re: I'm being cyberattacked by Tesla, Inc

#80

Earlier quoted context omitted.

Isn't this technically a crime, since they're actively attempting to access a computer system they don't own?

In today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.

Tesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else.

The scanner is likely illegal.

The pointing is… so stupid nobody thought to make a law about it.

Post reply on HN