Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

171–180 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#171
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

>Someday, all cars from a particular brand will be made to crash during rush hour. This is also why it's always very, very wrong to compare potential faults of automated cars to humans as in "the automated car is X percent safer!", becuase it ignores the fact that mistakes in automated systems, at least as they are built now, are highly correlated. If there is one bug in an ML system that is rolled out to an entire f…

I can tell it has started raining by the number of ambulances leaving the station down the road.

Human driver errors not correlated my arse!

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#172
post #57

Earlier quoted context omitted.

I think the key here, and unfortunately most companies don't give a sh*t, is to allow the user to gain control over his device and/or take it offline if it pleases him. For example, a Tesla car should come with an option to disable any remote control features, or a way to control it over short distance only when it's offline (I don't know if its already the case, I don't have a tesla).

I think the key here...is to allow the user to gain control over his device and/or take it offline if it pleases him. I wonder how long it will be before we start to see legal or regulatory interventions in this area. Mandatory self-updating and phone-home functionality is rapidly infecting technologies we rely on every day, from our cars to our home computers to our TV sets. This always-connected, always-updated app…

> I wonder how long it will be before we start to see legal or regulatory interventions in this area.

Not long IMO. It'll be sold as a safety measure, but the real purpose will be to limit competition. I think it's similar to "warranty void if removed" stickers, but I'm worried we're not going to get the same pragmatic legislation that makes those ignorable.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#173
post #45

Earlier quoted context omitted.

An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.

Infosec is a worse gov regulation than drug prohibition. It will do little than make naive people feel better.

I disagree. I think in an ideal world this is true but the reality is that the bar for security is exceptionally low for industries that aren't traditionally software industries (not that software is excluded). When the stakes are just accounts and transactions that can be reversed the situation is different, when the stakes are life and death, in the real way, I don't think it's unwise to exercise caution. Let someone else take the risk of cyber terrorism and if they go a decade without any hiccups then leapfrog them. There's no reason to expose consumers to these sorts of risks just because it gets the futurists hard.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#174
post #35

Isn't a "fleet-wide hack of autonomous vehicles" an oxymoron? They clearly aren't autonomous if they are controlled by an outside force that can be hacked. Maybe it depends on perspective, with the manufacturer seeing owners as outside forces, from which their vehicles are autonomous? Rolled up with the liability question is the question of who does control the vehicles and who they are autonomous from.

"Autonomous" in this instance means "able to maneuver without a driver", not "able to make independent decisions without the help of an external system".

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#175
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

I agree to an extent. I think security obligations are good but they should be practical. I know the privacy activists will hate this, because it's something that works, but if we tracked users irl and if banks already have the ability to reverse transactions then the stakes are much lower (because they would be able to identify theft) than something like remotely updated cars or medical devices which can be patched but not before a lot of people have died. Software is advancing rapidly in a way that's valuable, the goal should be to preserve that except when it kills people in the real way.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#176
post #80

Earlier quoted context omitted.

Whoever did this would likely select some combination of valuable/soft/flammable targets. Control over a sizable fraction of all vehicles in a country would enable them to create utter pandemonium in tunnels, bridges and underpasses during rush-hour - even larger highways. Aside from fire, I'd imagine that the "disable vehicle on sensing a crash" functionality would end up being hackable as well. Cars on the whole ha…

>disable vehicle on sensing a crash Most vehicles won’t let you reprogram the firmware without power cycling the car. Disable sensing of a crash is definitely its own ECM that is on a high priority bus. I am assuming your common <$40k car. When you head into bmw, merc Benz land this statement changes slightly.

I'd definitely like to think that all of that stuff would be air-gapped, hard-wired and baked into the silicon (and E2E-encrypted, with a Trusted Computing model and auditable supply-chains), but I do worry that people are going to cut corners, fudge things when they're approaching deadlines, and not take into account an appropriate threat model when they're designing this mass-market consumer automotive stuff. The Chrysler hack in 2015 managed to get some fairly low-level remote access to things like the braking system. I'm also considering the possibility that governments might backdoor their own manufacturers with their knowledge in order to gain exploits to systems overseas or to carry out the odd covert assassination.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#177
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

> Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? […] people who just like to cause chaos, and state-sponsored actors […]. Makes me think of the recent Twitter account take-overs. The amateur attackers acquired access which could have caused enormous damage, and used it to scam ~$100,000. The difference between $50k and $1m in bounty c…

Yeah, I'm not sure the old $5 wrench approach to "hacking" is likely to get you any rewards from megacorps.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#178
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

> Until then, I'll only want to buy cars made before 2010.

Most modern cars don't connect to the internet.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#179

Earlier quoted context omitted.

If you look at adversarial machine learning you'll see it is shaping up as a bit of an evolutionary battle. It is quite likely that a years-offline Telsa (or similar) could be deceived into a fatal collision. We need safe updates with transparent documentation as to all the changes, with hardware enforced feature switches. Forcing them to go through an approval process doesn't sound bad until you've met regulators li…

You have to weigh the risks of manipulating cars one at a time because they don't have the latest updates with the risk of manipulating all cars at once because they can be remote controlled. A more expensive alternative to over the air updates is requiring regular updates done by a mechanic, e.g. when the vehicle is due for an inspection.

I don't really think OTA updates is the problem, so much as the automatic application of the updates without owner awareness (or consent to possibly significant feature changes). Preventing OTA is not the same as preventing remote control -- vehicles WILL be networked, if only for collision avoidance. OTA could be very useful if a bad exploit becomes widely available -- like a protocol bug in the V2X network that lets you crash the V2X module. Many bugs are discovered after being in production for years.

If you allow users to approve and roll back updates then there is some ability to recover after bad updates. Of course, you don't want theives to be able to roll back to a vulnerable release, but you can require the master owner key & code for rollback.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#180
post #96

Earlier quoted context omitted.

>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap. The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, ab…

What was the half-life on that vulnerability? From the moment Lastpass wrote whatever the fix was to the point at which attackers can no longer exploit it afresh, how much time elapses? If it's a serverside fix, so that the number is something like "a day or so while it's deployed", that's your answer about why nobody is outbidding Lastpass for this bug.

I rather thought it was honesty that kept it from being bid on by bad guys. Even if they wouldn't bid more it's a big risk to pay so low.

It's kind of a treasure trove to be able to read all passwords from a user of lastpass simply by showing them a website.

It made me think that the next zero day on lastpass would probably be sold to someone else.

Post reply on HN