Live data from Hacker News

Tesla PowerWall 2 Hack

github.com

101–110 of 175 posts

Re: Tesla PowerWall 2 Hack

#101

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

I guess you haven't seen this then. https://www.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...

This is amazing. It is all completely plausible, and clearly includes only the most easily explained horrors, with anything that would require explanation just omitted.

It is worse than I would have been able to invent.

Re: Tesla PowerWall 2 Hack

#102

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

You can't turn hundreds of them on and off in synchrony from your basement.

Re: Tesla PowerWall 2 Hack

#103
post #98

Earlier quoted context omitted.

I believe the solution to this problem is to ban ROCOF protection, and the related phase shift protection, and instead instruct a few big energy producers to transmit a gold code on top of the 50 Hz AC, bandlimited to 48-52Hz and power limited to 0.01% of the system power. Transmitting that code would be easy (cheap) for anyone who does DC/AC conversion with solid state electronics, so that's normally solar, wind far…

Would a better long term fix be to upgrade grid hardware such that it can survive an inadvertent largish island? Sometimes I think that a DC grid would be better. Issues like frequency synchronization wouldn’t exist.

To reconnect a powered island to the main grid, one needs to match frequency and phase with it.

There is currently no way to control the frequency or phase of the island.

Re: Tesla PowerWall 2 Hack

#104
post #99

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

You don’t see any difference between an individual switching a multi-kilowatt heater every few milliseconds vs a malicious actor automating this attack on 100,000 properties over an entire state?

But if only the true owner of each powerwall had the ability to control it (when the default password issue is fixed), an attacker can't get correlated control like that.

Re: Tesla PowerWall 2 Hack

#105

The only bug here is the default password. After authentication, the fact you can make it charge or dump power into the grid is by design. If I wanted the grid to suffer, I can do this by plugging in and unplugging a multi-kilowatt heater every few milliseconds too. Residential properties have a fuse (usually 60-100Amps), and anything you can do without blowing that fuse won't damage the grid.

Charging or dumping a single powerwall will not damage the grid. However, if someone causes many of them to do so in sync, the current grid control systems are definitely not going to cope well with that sort of behavior.

Without the default password, an attacker would need to actually own all those powerwalls to pull that one off... At that kind of money, there's better ways to be evil.

Re: Tesla PowerWall 2 Hack

#106

Can’t believe Tesla would ship something with anything resembling a default password. At first glance, I assumed this would be a clear violation of the requirements of CA SB-327 (goes into effect Jan 1). Reread the bill, and it actually says: “The preprogrammed password is unique to each device manufactured.” If the default is based on the serial number, I guess it’s “unique” under the letter, but certainly not the s…

I guess you haven't seen this then. https://www.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...

Of all the crazy things in there, "log uploading was flaky so we couldn't complete getting the log out of a burning car" may be the craziest.

Re: Tesla PowerWall 2 Hack

#107

Earlier quoted context omitted.

Any power grid is very vulnerable to attack. Anyone who can cause a sudden surge in demand can take a power grid down. If you can make power usage unexpectedly go up by more than ~10% within a minute, most power grids will fail. I'm struggling to think of any companies who could do that though... Someone with malicious access to teslas servers couldn't even do that... For example, instruct all plugged in tesla cars t…

I'd assume that the power grid is much more vulnerable than that at least some of the time in some regions. What if due to natural load variations the network already is close to the capacity reserve (which could be measured by tracking AC phase) when somebody mounts an overload attack? What happens if the attacker generated a (e.g. periodic) pattern of load changes that excites control mechanisms at their resonant f…

I highly recommend this book. It covers an entirely plausible scenario that could happen in real world, which is very interesting to read, but also - very scary to think about.

Re: Tesla PowerWall 2 Hack

#108
post #54

Earlier quoted context omitted.

"Responsible disclosure" is an invention of vendors who want you conforming to their policies and timelines (and more). Tesla is also "good" at disabling aspects of people's property (like ethernet ports, or ability to receive future firmware updates) when they dislike what people find "wrong" or otherwise in Tesla software.

I think this comment highlights a lack of understanding what responsible disclosure is about. It's there to reach the best possible tradeoffs to protect consumers and force a quick turnaround with fixes. Just publishing vulns, which the vendor might not even see or learn about(!), will not help in getting things improved and puts consumers knowingly at risk at scale.

Perhaps you should come up with your own term to describe such disclosures instead of co-opting the well established one that means something else entirely?

Re: Tesla PowerWall 2 Hack

#109
post #88

Earlier quoted context omitted.

Some interesting commentary: https://news.ycombinator.com/item?id=14010010 https://news.ycombinator.com/item?id=12308246 > That may feel good to say, but as someone whose job it was to find these kinds of bugs in software from companies ranging from tiny startups to financial exchanges to major tech vendors, this is a kind of carelessness shared by virtually everyone shipping any kind of software anywhere. > That sai…

> That said, the term "responsible disclosure" is Orwellian, and you should very much avoid using it. It seems you disapprove of the phrase "responsible disclosure" because it's ambiguous and can be used as a cudgel. That's no different than the term "Orwellian", which is ambiguous and can be used as a cudgel. All people are saying is that it's better to give the vendor a heads up before releasing an exploit. Maybe t…

>It seems you disapprove of the phrase "responsible disclosure" because it's ambiguous and can be used as a cudgel

This is like saying that a glock can be used as a weapon. Yes, it was carefully designed to be one.

>We must secure the existence of our people and a future for white children

This might also be ambiguous, but we all understand the genocidal connotations.

Post reply on HN