Live data from Hacker News

Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

synacktiv.com

41–50 of 90 posts

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#41

Repeat after me: An owner voluntarily downgrading firmware to gain control of your hardware IS NOT A HACK. And if an adversary is doing this, then they have already breached yoir physical security.

Eh, that’s a bad generalization. defense in depth is a thing and there are many cases where you’d want to protect against attackers with physical access

This isn't designed to stop attackers with physical access. This is designed to stop casual tinkerers and shade tree mechanics.

You know what isn't vulnerable? A "dumb" offline charger. You know what doesn't make any money or turn the consumer into another product? A "dumb" offline charger.

If it were about physical security, the suggested fix would be to remove the communication from the port entirely.

Companies shouldn't get to make something simple and secure into something inherently insecure and then iterate security into it. Like drive by wire steering, or brakes. Nobody asked for these things and if you ask ANYONE who works on, builds, or actually enjoys cars the consensus is NOBODY wants it.

But there are enough sophomoric, pedestrian car owners out there who gawk at the senseless overdeployment of technology and think "this is so convinient" and don't see it as 1) regulatory barrier building and gatekeeping 2) enabling vendor lock in 3) overcoming right to repair legislation. So the knowledgeable and enthusiastic voices of reason who care about cars get drowned out by the hoard of pedestrian geeks who couldn't imagine operating a car without at least a 16 inch touchscreen.

In security, the best defense is not introducing a vulnerability at all. There is value in having less code. For example, if your PaaS doesn't collect user SSNs... then it can't lose SSNs in a breach.

The question here should not be "why is this not secure." The question should be "why does this even need to be secure in the first place?" We have a very simple task to do and we've complicated it so much we've introduced vulnerability that didn't exist previously.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#42
post #23

Earlier quoted context omitted.

Your comment makes no sense. The tesla wall connector is a home charging port you install in your garage.

I knew this is about wall charger at home but I assumed ‘time of use billing’ was some kind of billing system for the charger that’s implemented.

some people have variable electrical tariffs, so electrical use in the middle of the night is usually much much cheaper than the middle of the day.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#43

Repeat after me: An owner voluntarily downgrading firmware to gain control of your hardware IS NOT A HACK. And if an adversary is doing this, then they have already breached yoir physical security.

It clearly seems people have different meanings to the word, then.

For example, if I am able to gain root access to a WiFi access point I own, even though the vendor has tried to prevent it, then yes, I would call it a hack. To me, it doesn't matter why or who is doing the steps.

In fact, I believe I have never before heard someone combine the meaning of the word to be related to the ownership of the device being hacked.

I suspect the number of people understanding the word in your way is a minority. Redefining terms doesn't help build mutual understanding: here we are taking a word some think has negative connotations and then remove the thing they think should be cool and ok, and then suggest that this is actually the real meaning of the word. Personally I don't think this is how words should be wielded.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#45
post #27
post #5

Earlier quoted context omitted.

I don't think there are any restrictions. I think j1772 might just work with an adapter (adapt from the nacs plug to the j1772 plug) I thought tesla even made a j1772 native wall connector.

There are some restrictions. I had the foolish idea of installing a Tesla charger at home to charge my Bolt. I’ve been unable to ever use it. The wall charger works fine with Teslas. My car and adapter charge fine at Tesla superchargers. But the home Tesla charger refuses to charge my Bolt. (Yes I disabled vehicle restrictions and tried all sorts of combinations of settings for weeks before giving up. Tesla support w…

Really gross. I have a gen 1 charger and it's dumb as bricks. Basically just a giant relay.

I guess I could see why you might want to restrict who can use your charger, but I really prefer the "dumb as bricks" version I currently have.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#46

Why use Tesla wall connector in a first place and not just the standard nema/dryer outlet with the Tesla cord/charger? It seems like people are overpaying for nothing.

I can do 48A @ 240V with my wall connector. It's also very convenient.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#47
post #43

Repeat after me: An owner voluntarily downgrading firmware to gain control of your hardware IS NOT A HACK. And if an adversary is doing this, then they have already breached yoir physical security.

It clearly seems people have different meanings to the word, then. For example, if I am able to gain root access to a WiFi access point I own, even though the vendor has tried to prevent it, then yes, I would call it a hack. To me, it doesn't matter why or who is doing the steps. In fact, I believe I have never before heard someone combine the meaning of the word to be related to the ownership of the device being hac…

> For example, if I am able to gain root access to a WiFi access point I own, even though the vendor has tried to prevent it, then yes, I would call it a hack.

Yep. The owner of the device can sue you.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#48
post #23

Earlier quoted context omitted.

Your comment makes no sense. The tesla wall connector is a home charging port you install in your garage.

I knew this is about wall charger at home but I assumed ‘time of use billing’ was some kind of billing system for the charger that’s implemented.

That's done on the property's electricity smart meter.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#49
post #2

Why would I want to hack the bootloader for a wall charger? Asking for a friend

Publicly accessible piece of equipment that could have a pseudo-trusted connection to an internal network (since they're connected to the Tesla Cloud(tm)).

Picturing someone rolling up to a charger outside of a large office building, 'plugging in', exploiting the charger via the communications, then using the charger to pivot inwards.

Re: Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

#50
One thing I'm really scared of is EV charger software being modified by users, hackers or bugs to pull max power at times that don't suit the grid.

In the UK, for example 10 million EVs all pulling 7kw would overwhelm the roughly 70GW potential of the grid. Even a million EVs charging at an inconvenient time could add a 7GW draw which is enough cause a problem.

Post reply on HN