Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

161–170 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#161
post #31

https://medium.com/@mpesce/the-great-hack-part-one-attack-70... "The first thing that happens is nothing. Your smartphone stays black while you swipe at it and press the various buttons. Has the battery gone flat? You could have sworn you left the house with a full charge. Now you start to wonder how you’ll get your car out of the parking structure without a working mobile. That thought hadn’t occurred to you before.…

It's pretty well written, but somewhat unrealistic from technical standpoint.

The first part is OK (except author forgot about "fire exit" laws, so the mall doors would not be locked)

The second part, the one which describes "consensus" system from technical standpoint, is wrong. The protection does not work this way. As in, it can surely be implemented, but it has no benefits that author claims and would not protect from stuxnet-like "viruses" (sic!) at all.

The third part, where the bitcoin is mentioned, is outright science fiction.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#162
post #57

Earlier quoted context omitted.

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

It's not possible without rooting your car and losing the warranty. This is legal as long as you don't touch the odometer.

> rooting your car

Something has gone terribly wrong with modern technology.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#163
post #11

Earlier quoted context omitted.

Not the OP, but the precedents are here: Always-connected cars (eg. teslas): check. Being able to take control of a car via the CAN bus[1]: check. The only thing missing in the exploit chain is something that allows the attacker to jump from the modem/infotainment system to the CAN bus or ecu. [1] https://www.wired.com/2016/08/jeep-hackers-return-high-speed...

Tesla uses a pretty different architecture from the dumpster fire that was OnStar. Been a while since I looked in the details but from what I recall only very limited, well scrutinized communication is allowed to bridge the Ethernet subsystem over to the CAN bus.

Well fundamentally, they can be breached. Since the self-driving AI system can be updated (afaik), then vehicle control can certainly be remotely altered.

I guess those risks are a bit like nuclear launch risks. Someone, somewhere (that controls the right key) could unleash an enormous accident. You just hope the system as a whole has enough redundancy for it to be sufficiently unlikely. In nuclear arms technology we have multiple authorizations required for launches. Then of course the underlying system has to be robust enough so none of those measures can be bypassed.

There is no fundamental barrier that I can see -- we know how to build incredibly robust systems using methods like formal verification of software and just thorough quality assurance and testing. In a way, much of the world is already exposed to those kinds of risks: most individuals's phones, laptops and even industrial computers can be remotely updated and incapacitated, exposing a risk of generalized trouble.

The adequate amount of resources to be allocated on those risky but extremely remote scenarios is what's important. I think there needs to be oversight guaranteeing every system is getting verification, testing and attention proportional to risk for society. The usual punitive incentives don't work very well for those cases. I don't think we have any agencies with this wide of an outlook currently.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#164
post #55

Earlier quoted context omitted.

I think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.

The bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.

$50k is not alot considering how much it would have harmed the share price with the negative press reports around the world. It could have even taken the company to the brink of extinction. For comparison, to get middle section, right hand side 1/2 page article written in the Sunday Times and Observer would have cost you about £30k 10 years ago to be introduced to the journalists writing your advert masquerading as a story. Multiply that up for all the global news outlets and the $50k bug bounty was a pittance. I wouldnt have been surprised if Musks day to day wine cellar was several times more expensive than that $50k bug bounty.

18 years ago my peak earning rate was £5k an hour so dont knowingly undersell yourselves in your day job or with bug bounty's. Simple letter govt agency's will also cover stuff up, using state broadcasters and other so called free press media outlets to put a spin on things or outright mislead. Seen this twice now.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#165
post #44

Earlier quoted context omitted.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

I definitely think Tesla can be over aggressive with their updates. However that doesn't mean that the basic idea of remote updating cars is inherently flawed or unsafe when compared with the alternative. It is all about trade-offs. Both the Prius[1] and the Model 3[2] had similar software bugs related to their anti-lock brakes. Both companies had a software fix a few days after the bugs were discovered. Tesla's fix…

> Toyota couldn't push out a fix. They had to issue a recall and have a technician update the software whenever that car ended up being serviced.

This gives all the more incentive to get the software correct in the first place. The model of "get the software as bug-free as possible upfront using stringent processes, testing, formal methods, and not using software in the first place when it's not actually needed" is better than the model of "put software into as many components as possible to make it shiny and get the software good enough to release before our competitors and play whack-a-mole on the bugs later through updates". Instantaneous updates make it easier for an attacker to take control of the update infrastructure and push an update that will trigger a mass-crash of cars during rush hour. When people have to asynchronously take the car to dealerships over many months, it makes this attack harder to go undetected.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#166
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

> Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000?

The article says the max bug bounty was increased to $15k eventually, so it was even less than that at the time even though they gave him $50k. Kudos to whoever at Tesla stepped up and gave him extra.

I'd seriously consider not reporting something like that for $15k unless I was worried about someone else exploiting it and having a trail of access logs lead back to me. People that discover bugs like that with massive destructive potential must be on every TLA list on the planet afterwards and I don't think that's worth $15k.

$1 million is life changing and puts you into a higher social class. IE: Poor == probably a criminal. Rich == probably not a criminal. It's sad, but that's the way it works and I'd rather be rich if I were on a short list of "dangerous" hackers.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#167
post #159
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Are you kidding me? If money was my goal, 50k would be so insulting! A slightly more malicious person would brick the whole fleet as retribution.

Alternatively, document it with trusted timestamps and don't report it. Then if someone else exploits it you could parlay the media frenzy into a lot of publicity that's probably worth more than the tiny bounties many companies pay.

"Oh, we discovered that 2 years ago, but the bug bounty program didn't make it worth reporting. Want to buy a security audit?"

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#168
post #57

Earlier quoted context omitted.

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

If you look at adversarial machine learning you'll see it is shaping up as a bit of an evolutionary battle. It is quite likely that a years-offline Telsa (or similar) could be deceived into a fatal collision. We need safe updates with transparent documentation as to all the changes, with hardware enforced feature switches. Forcing them to go through an approval process doesn't sound bad until you've met regulators li…

You have to weigh the risks of manipulating cars one at a time because they don't have the latest updates with the risk of manipulating all cars at once because they can be remote controlled. A more expensive alternative to over the air updates is requiring regular updates done by a mechanic, e.g. when the vehicle is due for an inspection.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#169
post #158
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

For a vulnerability of that scope, I assume selling it to a short-seller to publish in bad faith would be more valuable than selling on the actual black market anyway. Hell, the impression I get is that unless you're fairly well connected already, selling large $ value hacks on the black market isn't exactly easy (see Twitter hack). I don't know if this is strictly legal either, but definitely more plausible deniabil…

> I don't know if this is strictly legal either, but definitely more plausible deniability.

Presumably you're into the system by the time you've discovered the exploit, so you're on the wrong side of the CFAA in the US and IMO the law would come down on you _hard_ if you acted in bad faith like that.

Even failing to report it might ruffle enough feathers for the company to use their political connections to have you prosecuted. I suspect that's also part of the reason the bounties are so low.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#170
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

> Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? The article says the max bug bounty was increased to $15k eventually, so it was even less than that at the time even though they gave him $50k. Kudos to whoever at Tesla stepped up and gave him extra. I'd seriously consider not reporting something like that for $15k unless I was worried…

It's pretty silly to suggest that a state-level adversary needs the help of the person who stumbled across the baked-in credentials in an obfuscated Python binary to accomplish a CNE task. If a state wants to target Tesla, someone will submit a petty cash request to contract someone else to develop Tesla vulnerabilities.

If you're able to sell a Tesla vulnerability to the supply chain of a state-level actor, it's probably because they're already actively exploiting Tesla vulnerabilities. By the time random discoveries like this are part of the supply chain, the supply chain is already chugging along.

I think a good rule of thumb is that no serious actor --- not a state, not a crime ring, not a competitor --- does speculative engineering to accept and operationalize a third-party vulnerability. If they're buying, it's because they already have an operational infrastructure to drop the bug into. When you're figuring out the dollar value a vulnerability has, start by telling yourself the story about the entity that already has a bug just like it, is exploiting it for some articulable purpose, and wants a replacement or 10 in the hopper for later. (I don't think this is a perfectly reliable heuristic, but it's where most of this kind of thinking should start).

Post reply on HN