Live data from Hacker News

Running Tesla Model 3's computer on my desk using parts from crashed cars

bugs.xdavidhu.me

171–180 of 356 posts

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#171
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

Imagine having to hack your device, then having to submit a request to actually own it.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#172

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

You can feel that way, but plenty of car configuration has always been locked away and walled off, and manufacturers make a tidy profit selling software licenses to dealers and mechanics to perform basic diagnostics. Proprietary software is big business what can you do.

That is the recent (and gradually worsening) situation but it is not in and of itself a justification. Effectively you're saying "it's currently this way therefore it's okay for it to be this way".

Manufacturers have increasingly restricted control over products as they've gradually been digitized. Prior to the digital era anyone could do anything to personal property (regulations notwithstanding ofc); more expensive items typically came with circuit diagrams for the purpose of repairing them.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#173
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

The interesting part is this implies that Tesla cars have static certifcates that don't rotate. (Whoops.)

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#174

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

[flagged]

[deleted]

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#175
post #162

Earlier quoted context omitted.

No, one can do that anyway. There is basically no real way to stop folks from modifying their cars. It can be made more difficult, sure. This is about selling tools and access. It's another profit pipeline for car OEMs.

Perhaps it is also about liability. Otherwise, we would have people installing OpenClaw on their Teslas.

Then why wasn't it a problem before? People have always been able to install aftermarket or possibly even hacked together physical parts. If there was liability you'd expect some sort of shield blocking access to, for example, the hydraulic system for the brakes.

As it turns out though blatant irresponsibility is quite rare (depending on your definition anyway) since people have a strong self interest in not endangering their own lives or wallets. It's similar for homeowners - many states explicitly carve out a requirement that insurance companies cover DIY modifications that are within reason and this generally works out since you have a strong vested interest in not destroying your own house regardless of any insurance policy.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#176

Earlier quoted context omitted.

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

Four 9/11s worth of people die every year from drunk driving. If we can't even get that under control, I don't see why being able to modify your own car is a big deal.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#177

Earlier quoted context omitted.

As much as I tend to agree philosophically, could it not result in people making changes that endanger other road users?

I don’t think that’s the reason, seeing as a car is already endangering everyone around it by existing. More likely about keeping the tooling to diagnose issues proprietary and expensive.

Obviously, they are both very good reasons. Just because you don't like one of them, doesn't mean the other one doesn't suddenly exist anymore.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#178
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

The interesting part is this implies that Tesla cars have static certifcates that don't rotate. (Whoops.)

Why can't they rotate ? having root ssh keys on the device doesn't imply the certs don't rotate.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#179
post #99

From the article > Tesla offers a “Root access program” on their bug bounty program. Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car, allowing them to log in as root and continue their research further. Pretty interesting. Sounds like Apple's Security Research Device Program[0], where you're loaned a rooted iPhone, but with a clear qualificati…

> Researchers who find at least one valid “rooting” vulnerability will receive a permanent SSH certificate for their own car It feels like this is something you should get by being owner of the car, and not have to do free speculative research for the manufacturer to get it.

Normies get scammed on Discord into pasting commands into their browser console.

As a pedestrian I prefer for most people to not have root access to their multi-ton fast-moving killing machine.

Re: Running Tesla Model 3's computer on my desk using parts from crashed cars

#180
post #161

Earlier quoted context omitted.

That's super cool, I'm currently struggling with scan tools for a 1999 Mercedes E300 Turbodiesel. I had one that worked OK for about a decade (Autel something or other) with a 38pin connector, but it recently bricked itself with a message like "connect via USB to Updata" which I assume means its firmware somehow erased itself. Cannot figure out how to "updata" it, doesn't seem to connect via USB, the Autel software r…

> All that is to say, this space is ripe for some open hardware/software love. There's just so many computers and what-not in modern cars that this is a very tall ask. You'd need a project on-par with HomeAssistant to get anywhere.

Yeah, it seems like more modern technology has settled on standard protocols (maybe a naive impression--someone will shout at me if that's the case) but there's probably a very long tail of bizarre false starts if you want full coverage of models back to the early 90s when computers became more commonplace.
Post reply on HN