Live data from Hacker News

Tesla Model S Ethernet Network Explored

dragtimes.com

101–110 of 112 posts

Re: Tesla Model S Ethernet Network Explored

#101
post #31

Earlier quoted context omitted.

Agreed. There should be a large warning on the console: "Warning to passengers: The Vehicle Systems have been Compromised. Please do not ride in this vehicle. A Service tow truck has been dispatched." Also, the car should not move.

Wow, as someone who grew up "hacking" on my car (i.e., on the engine) this attitude is pretty amazing. What a dangerous, mysterious thing a car must seem to you.

I can see both sides of this one. If I R&R my brakes or repair the steering rack, I can reasonably claim that I did so using good mechanical skills and practices, and prove it in court if necessary. But if I tinker around with a closed-source software system in my car, I literally have no idea what I'm doing. The changes I'm making could affect any and every other system on the car... and nobody but the factory engineers would know for sure.

The best solution is the simplest: no closed-source systems allowed in cars used on public roads. But I wouldn't hold my breath until everyone gets on board with that.

Re: Tesla Model S Ethernet Network Explored

#102
post #88

Earlier quoted context omitted.

Sadly, the segregation between CAN buses is not nearly as good as you would think. ONSTAR, for example, sits on the drive critical bus (and is exploitable). Of course, this is not on a Tesla, but still. http://www.autosec.org/pubs/cars-usenixsec2011.pdf

A few years back, a joint UW-UCSD team showed that car systems are remotely exploitable. They were able to literally call the car's cell phone number and control the brakes/gas/door locks remotely. http://youtu.be/bHfOziIwXic

The above paper is one of two the UW/UCSD group wrote.

Re: Tesla Model S Ethernet Network Explored

#103

I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. Automotive systems communicate over a CAN [1] bus, not ethernet. In fact, this bus is usually physically separated between drive-critical bus (which controls things like ABS) and "comfort" bus (such as electric window controls, central door locks, wheel-mounted audio controls). Ethernet has none of…

What about cars where you can enable/disable features like traction control and auto-break from the entertainment system? They must have some sort of connection, and that connection probably has bugs that could be exploited.

Re: Tesla Model S Ethernet Network Explored

#104
post #23

Earlier quoted context omitted.

And that's a mighty hacker-unfriendly stance to take for a company whose client base is made up of a disproportionately large number of engineers and computer scientists, many of whom will doubtless be curious as to the inner workings of their car computer systems. I mean, could you imagine if a car manufacturer took this attitude toward car owners who were exploring the car's transmission, which is clearly just as c…

I think there is a difference between hacking (or even exploring) something like a phone, game console or router and a car, plane or any other thing that can immediately put in danger the live and health of many unrelated persons. Therefore I thinks Tesla acts as responsible as they should when detecting and reacting upon active (as opposed to passively analyzing radio transmissions) manipulation of their cars inner…

Car modification has been around since cars started coming off assembly lines - everything from purely aesthetic stuff to lifting or lowering the suspension, turbos, nitrous oxide etc. Software is just the next step. There are even open source ECUs now http://hackaday.com/2014/01/01/building-an-engine-control-un... https://www.kickstarter.com/projects/312898525/rusefi-gpl-au...

Re: Tesla Model S Ethernet Network Explored

#105
post #31

Earlier quoted context omitted.

Agreed. There should be a large warning on the console: "Warning to passengers: The Vehicle Systems have been Compromised. Please do not ride in this vehicle. A Service tow truck has been dispatched." Also, the car should not move.

Wow, as someone who grew up "hacking" on my car (i.e., on the engine) this attitude is pretty amazing. What a dangerous, mysterious thing a car must seem to you.

I've done plenty to cars. Have done plenty with computers too. I wouldn't let my family and friend ride in a car with compromized safety systems.

Re: Tesla Model S Ethernet Network Explored

#106
post #54

Earlier quoted context omitted.

Cutting the brake lines or using a kitchen knife (or a gun bought off Craigslist in the US) to kill the person you hate works just as well and is much simpler. I personally would like to see various "hacks" adjusting the suspension, brakes, spark timings and other things for a better ride in certain conditions (racing, drifting, mountain roads, etc).

The scary thing would be if people started writing viruses aimed at infecting Tesla's. And when I say viruses, I don't mean the type that mine doge :)

I'd mine doge on a Tesla. Maybe it would mine enough to pay for a rapid battery change once a year on its own.

Re: Tesla Model S Ethernet Network Explored

#107
post #90
post #78

Earlier quoted context omitted.

Assassination via physical-access car hacking (cutting brake lines, etc.) has been around for a long time. Seems like a small jump to electronic.

Has there ever been a successful assassination using this method? If some cut my brake lines I would know about it the moment I started the engine and applied the service brakes while putting the car into drive/releasing the e-brake, or become aware of it while maneuvering out of a parking space at speeds under 5mph.

Not necessarily -- it would take a good few pumps of the pedal to introduce enough air into the system for the brakes to become ineffective.

Re: Tesla Model S Ethernet Network Explored

#108
How can the car communicate with the Internet? Does it have a cell modem or something? Is a lifetime subscription included in the purchase price of the vehicle, or does the user get a monthly bill?

Wouldn't a real industrial espionage operation disconnect or Faraday cage the vehicle's remote communications capability as their very first step? If you were trying to reverse engineer Tesla's secrets, would you really care about voiding the warranty?

Re: Tesla Model S Ethernet Network Explored

#109
post #90

Earlier quoted context omitted.

Has there ever been a successful assassination using this method? If some cut my brake lines I would know about it the moment I started the engine and applied the service brakes while putting the car into drive/releasing the e-brake, or become aware of it while maneuvering out of a parking space at speeds under 5mph.

Not necessarily -- it would take a good few pumps of the pedal to introduce enough air into the system for the brakes to become ineffective.

There are a bunch of cases of amateurs who do this. http://www.dailymail.co.uk/news/article-2081590/Man-arrested... http://www.ktbs.com/story/22346692/man-accused-of-trying-to-...

I'm more used to people just putting car bombs on the vehicles, though.

You should be good with the e-brakes, and should never 100% depend on your primary brakes when driving, but in practice I'm sure a lot of people get into situations where they wouldn't know to switch to e-brake if the main brakes failed, or wouldn't have time. The biggest risk to the assassin is that car accidents in modern cars just aren't that fatal -- you can hit another car head-on at 60mph and, with seatbelts, non-offset crash, airbags, etc., either walk away or at least survive at a hospital. It also leaves enough forensic evidence, especially if the driver survives and reports "my brakes just didn't work!" that it wouldn't be surreptitious.

A bomb isn't likely to be taken as an accident, either, but is at least likely to be effective.

Re: Tesla Model S Ethernet Network Explored

#110

Earlier quoted context omitted.

I think there is a difference between hacking (or even exploring) something like a phone, game console or router and a car, plane or any other thing that can immediately put in danger the live and health of many unrelated persons. Therefore I thinks Tesla acts as responsible as they should when detecting and reacting upon active (as opposed to passively analyzing radio transmissions) manipulation of their cars inner…

> Tesla... of their cars This is the key point. If I've bought it, the car does not belong to Tesla anymore and they have no valid reason to be policing what the owner of the car is doing with it. If there should be rules against modification, then that should be the purview of vehicle licensing, not Tesla (and while you're at it, you should probably outlaw people maintaining their own cars or building them from scra…

It's certainly true that the manufacturer should have no say over what you do with your car (if they had what would stop them from going the way of the printer industry and force you to only use their tires etc).

I might have misused the words "their" in this sentence so what I was trying to say is that since modifying software can very easy (no special tools, garage or knowledge required, just an unchecked download and a 5€ self made adapter of ebay) I'm in the favour of locking down security critical systems (the WHOLE car) as much as possible since not only you but everyone around you is concerned at least until checks associated with getting a valid license are updated and enforced.

What would be really great is if manufactures where to offer an API to allow developers and hackers customizations where they make sense (like adding your favourite online service) and not forcing them through the whole process of trial and error.

Post reply on HN