Live data from Hacker News

Hackers manage to unlock Tesla software-locked features

electrek.co

491–500 of 773 posts

Re: Hackers manage to unlock Tesla software-locked features

#491
post #321

Earlier quoted context omitted.

Yes. You've already distributed the binary to their machine and are using their resources to store it. In my view, it belongs to them and they should have full access.

By that logic, do you think that after someone has paid for 1 month of netflix, and downloaded their entire catalog to your phone for offline viewing, that all the videos "belongs to them and they should have full access"?

Yes, absolutely, if that were a feature the Netflix app allowed.

Obviously it does not: your downloads expire after a certain amount of time, and if you cancel your subscription, you won't be able to get a key to decrypt the files.

Companies are free to try to put restrictions on that sort of thing, but I think if customers are able to circumvent those restrictions (the DMCA anti-circumvention laws notwithstanding), the company should not get to complain about this.

Re: Hackers manage to unlock Tesla software-locked features

#492

Earlier quoted context omitted.

> The customer didn't pay for a car with heated seats. Well, when you buy a car your payment gives you ownership of the entire car. There may not be a written contract or specification explicitly saying that the valves in the tyres are included in the deal, but they're your property nonetheless (in the absence of obvious errors like the dealer letting you drive the wrong car off the lot) The customer paid for a car w…

> Well, when you buy a car your payment gives you ownership of the entire car. Sure. > If the customer wants to modify their property, that's their business. If you were talking about a vacuum cleaner or something, I'd agree. But modern cars are "fly by wire". It is not, in fact, only the customer's business if they modify their car's software.

I think the problem here is that courts have allowed software vendors to use a legal trick to get around how owning things normally works. Software gets copied into memory to run, and courts have accepted the theory that making such a copy requires a license even though it's not a copy in the traditional sense (it can't be given to a third party so that they can also use it).

A book is copyrighted too, but when I buy one, I can legally write in it, paste in pages of my own, cut out pages, etc.... I can even sell it after I've done that.

I'm 95% certain the law should be changed to restore the first sale concept to software, and even more certain when it comes to embedded software that's necessary to use hardware owned by end-users.

Re: Hackers manage to unlock Tesla software-locked features

#493

Now comes the funny part, were tesla tries to make the platform trusted and locked down, and then people start to flash there own firmware and solder chip-mods, cause there is nothing GNUnder the sun. Wouldn't be surprised if Tesla has a defeat-device buried somewhere that allows for remote permanent deactivation once parked in case of piracy

They can anyways remotely ssh into any parked Tesla nowadays

Re: Hackers manage to unlock Tesla software-locked features

#494
post #311
post #259

Earlier quoted context omitted.

Rent keeps getting paid. It's not a one-time purchase of $25.

What about games with monthly membership fees like world of warcraft?

That's fine, since there's an on-going cost to maintain the cloud infrastructure that the game needs to function. The company is well within its rights to say "if you stop paying us, you stop getting to use our cloud services".

But if there was a single-player or LAN version of the game (I know that's not really possible with something like WoW, but for the sake of the argument...), then players should absolutely not have to pay an on-going subscription fee to play that way.

Re: Hackers manage to unlock Tesla software-locked features

#495
post #450

Earlier quoted context omitted.

Right. Instead of manufacturing a 50, 80, and 100 kWh battery pack, and having to go through the whole process of getting certifications and everything for each size, they just make 100 kWh packs all day long, and then software limit them to 50. Which means, in the case of an emergency, the company can bestow extra range on lower-end vehicles, which they did for Hurricane Irma. https://www.theverge.com/2017/9/10/1628…

Does that imply there is not much of a manufacturing cost difference between 50 kWH and 100 kWH battery pack?

Great reply!

It's either so close that you're overpaying for the 100kWH, or it's not very close in which case you're overpaying for the 50kWH.

Either way: the 50kWH is hit: carrying dead weight on a smaller capacity. A not insignificant weight.

Re: Hackers manage to unlock Tesla software-locked features

#496

Earlier quoted context omitted.

> Seems like a great way to get a bunch of people messing with their cars which could lead to all kinds of catastrophic consequences People have always been able to do this with a wrench since before the invention of cars.

I don't think anyone's taking a soldering iron to their on-board computer in a standard ICE vehicle. The fact that tesla has vehicle control code running on it (beyond your typical lane assist) makes this infinitely worse. Or am I missing something? I get that people disagree with these features being locked down and I agree. My point is this isn't like changing a cold air intake in your ICE car. This can have you go…

The part they're messing with it's "just" the infotainment system. The autopilot system and a lot of other things are "protected" by a gateway.

You'd still need Tesla's signing key to rewrite the Autopilot software or mess up some more important components.

Now, the CID is still coordinating some parts of it - but AFAIK the car works also without that, to the point that you can simply reboot the infotainment system without losing control of the vehicle / Autopilot

Re: Hackers manage to unlock Tesla software-locked features

#497
post #216

Earlier quoted context omitted.

> you could anonymize your location on Tesla's servers I already anonymise my location on Tesla's servers by simply not owning a Tesla

Your car is filmed and recognized by other teslas.

That's why I only hang out in the metaverse and don't leave my home anymore. Umm, ...

Re: Hackers manage to unlock Tesla software-locked features

#498

Earlier quoted context omitted.

I'm somewhat torn too. IBM and I'm sure others have shipped enterprise hardware for years that was partially locked. You might get a machine with 16 cpus but you only paid for 8, for example, but you could license the rest as you grew. It seems a little similar and it was in no way underhanded, everyone knew what the deal was. However I'll echo what another poster said. I say Tesla should be free to sell whatever the…

I don’t mind hardware shipping locked and being an optional fee to unlock. I have paid for the rear heated seats in my model 3. What I’m vehemently opposed to is ongoing fees for things that don’t have ongoing costs. BMW wants to charge monthly for seat heaters or carplay, but those things are not a service and don’t have ongoing costs for BMW to provide. If anything creating an ongoing software lock creates an avail…

I usually lean towards consumer rights on this type of thing, and the idea of paying a subscription for something like heated seats is annoying to me.

That said I am trying to play devil's advocate here. Other people have mentioned the analogy of locking out some CPUs on a die for a cheaper version of hardware, and I think that kind of applies here, at least for a one time payment.

If I'm willing to accept that, is it so unreasonable that they could rent this feature to me, even if it's only a software switch? After all, the idea of renting physical property isn't very controversial.

Again, I don't like the idea and would never want to rent the heated seats software switch, but I'm having a hard time justifying why it shouldn't be allowed.

Re: Hackers manage to unlock Tesla software-locked features

#499
post #483

Earlier quoted context omitted.

As other have pointed out, the rules on photography vary from country to country within the bloc. However, the rules governing data protection and the processing of personal data (including photos) come from the GDPR, and very basically say that any processing of personal data requires a valid legal basis. There is an exception for personal use - the household exemption - but as soon as you cross the line into commer…

Why is A[LN]PR unlawful for private citizens to perform on their own footage? (e.g. using https://www.openalpr.com )

It's unlawful as it means you lose the household exemption, and so need a legal basis for the processing. You also need to inform others of the data collection in advance, the purpose for which the data is collected, and the contact details of the data controller.

Private ANPR-equipped vehicles are rare (and outright illegal in some EU states), but when you see them they'll have large decals with the above information on all sides.

Facial recognition is considered biometric data, which is special category data under the GDPR and forbidden to process except in very strict circumstances. Apart from law enforcement/government, it is more or less impossible to lawfully process biometric data with informed consent from the data subject. The household exemption does not apply.

Re: Hackers manage to unlock Tesla software-locked features

#500
post #435

Earlier quoted context omitted.

That's why I also rotate license plates and repaint my car twice a year.

you're joking, but there's a whole genre of "adversarial fashion"[0][1] dedicated to making clothing that spams these sort of public data recognition services. Hoodies with license plates, face masks with weird facial features, etc. Often optimized against actual neural networks too [0] https://adversarialfashion.com/ [1] https://www.capable.design/

That’s really cool, I wonder effective these designs really are! This reminds me of a font that came out 10 years ago ZXX [1] that was presumably designed to hide from OCRs.

[1] https://www.businessinsider.com/zxx-fonts-that-google-cant-r...

Post reply on HN