Live data from Hacker News

Hackers manage to unlock Tesla software-locked features

electrek.co

701–710 of 773 posts

Re: Hackers manage to unlock Tesla software-locked features

#701

Earlier quoted context omitted.

Fucking hell, here we go again: "Dash cams are much more tightly regulated in some parts of the EU than elsewhere." It depends on the eu country of which there are several...including an ex-eu country. How it comes accross: One of the things i hate about America is that in new york all the californian building restrictions and zoning are killing free speech.

With respect, the GDPR is a Regulation and this applies uniformly across the bloc. Enforcement varies, obviously. TBH your comment comes off as very condescending and ill-informed.

GDPR is to be implemented independently in each country. There is room for interpretation, it's not a granitic ruleset from above

Re: Hackers manage to unlock Tesla software-locked features

#702

Pretty sophisticated attack vector: low voltage attack on AMD secure execution environment during boot. I wonder how many tries you need to get whatever bits you need in the right place. Also, I imagine you only need to cut 12V wires to do this, but I admire the willingness to get in there direct on these systems. I'd be a little nervous to make those cuts personally. Buried in the article is the claim that this will…

This is the same attack (and same people who developed) faulTPM[1] that was previously discussed[2]. This article is the same people demonstrating that attack against Tesla vehicles. The paper[1] and previous discussion[2] address the underlying problems with AMD's Secure Processor (AMD-SP) that is embedded in their CPU SoCs and previously and more commonly known as Platform Security Processor (AMD-PSP).

Unlike a web browser where W3C AntiFraudCG folk propose that websites would blacklist all impacted AMD-SP hardware and create massive amounts of e-waste[3], Tesla likely can't do much about this attack because Tesla (not users) would be responsible for a very expensive change of vehicle hardware.

If it's not an easy-to-execute attack like faulTPM, there are more complex (but becoming more mainstream and cheaper) IC reverse engineering methods like polishing the die down to take photos of each metal layer and regenerating VHDL, FIB editing an operational IC to bypass tamper detection methods, etc[4].

A security architect of the Xbox One presented a talk[5] a few years ago which provides some good background too. Largely the Xbox One has managed to avoid piracy because they made it economically not worth anyone's time to attack due to competitive pricing models versus high cost of attack. Similar to use of Denuvo for a month or two after release of a PC game, attackers aren't going to bother if their work amounts to nothing a month later.

Hacking a Tesla to enable additional features is worth a lot of money, so the economics are quite different. It's also different economics for printer cartridges, "pay to enable more features or performance" network equipment, etc. The cost of IC reverse engineering / FIB editing attacks (or other future attack methods) will keep reducing. IC tamper detection features will get more complex. Perhaps attackers will even get an advantage once they can readily reverse engineer 3nm ICs and defenders can't do much other than implementing ever more complex and obfuscated IC tamper detection features and VHDL logic (kind of like a Denuvo situation in hardware).

[1] https://arxiv.org/abs/2304.14717

[2] https://news.ycombinator.com/item?id=35787195

[3] https://github.com/antifraudcg/proposals/issues/19

[4] https://www.youtube.com/watch?v=6390Zqca3Mg

[5] https://www.youtube.com/watch?v=U7VwtOrwceo

Re: Hackers manage to unlock Tesla software-locked features

#703

Earlier quoted context omitted.

You better be ok with building your own car then, because every major player is adding subscriptions for various features. Remote start and remote lock/unlock are the most common, along with satellite radio.

The way I see it is that you're supposed to own the car and every feature you paid for it.

Which would you rather have:

Option A: A vehicle that lacks the hardware for heated seats, heated steering wheel, and driver assist that costs $25,000 to produce and that you pay $25,000 for. If you want these items next year, you have to buy a new vehicle.

Option B: A vehicle that includes the hardware for heated seats, heated steering wheel, and driver assist that costs $27,000 to produce. You can pay $25,000 now and those features aren’t enabled. But next year you can enable them for a nominal fee. Or you can pay $30,000 now and there are enabled for life. Or $27,000 now and a $500/year subscription fee that you can later cancel.

If not having two separate designs and production lines means less cost to make that a reality, that seems like a reasonable trade off to me.

Re: Hackers manage to unlock Tesla software-locked features

#704

Earlier quoted context omitted.

>1. This scenario makes the car cheaper for the poorer customers, so they benefit from it. Pardon my ignorance, but if the cost of the hardware is already baked into the cost of the cheapest options, which means they are paying for all of the hardware they have in their cars, including the hardware they can't use, how do they benefit? Cost, in that situation, is determined simply by the need to assemble efficiently.…

> Pardon my ignorance, but if the cost of the hardware is already baked into the cost of the cheapest options, which means they are paying for all of the hardware they have in their cars, including the hardware they can't use, how do they benefit? The idea is that the “cheaper” models are getting the hardware at a discount. Very simply: are getting $30,000 of hardware for $25,000 because features aren’t active. Other…

It may actually be even better than that.

If the manufacturer hadn't done this, they would have to produce at least 2 versions of the car: one without any extra hardware, and one with all the extra hardware.

It may turn out that doing separate versions of the car could cost $5,000 more per car over its entire lifetime, including production (extra design, assembly lines, etc) and support, rather than simply making one version of the car.

So if the car company hadn't done this, the car might have cost $30,000 anyway without the extra features, and $35,000 with the extra features, so the poorer customers would lose while the rich customers would pay the same.

This works more or less the same if these costs are comparable or higher than the costs of the extra hardware. And I suspect they are higher, as it seems highly likely that the price for these premium features in cars are a lot higher than the actual costs of the hardware itself.

Sure, the company could still engage in the same wealth redistribution / subsidization / price differentiation in the 2-car scenario (and they likely already do), but everyone could still lose anyway because the total costs of all the cars could still be higher in total.

Re: Hackers manage to unlock Tesla software-locked features

#705
post #585
post #538

Earlier quoted context omitted.

Gait detection renders any of this obsolute sadly.

If you're willing to go to the lengths of adversarial fashion, you're probably also willing to walk around with a stone in your shoe, or in high heels.

Pfft. Stilts, 10 footers, that's the key.

Re: Hackers manage to unlock Tesla software-locked features

#706
post #538

Earlier quoted context omitted.

Gait detection renders any of this obsolute sadly.

Luckily my gait is not in an adtech company's database and sold to the government, like my face probably is.

How do you know?

ID phone Bluetooth on passing, or even facial rec, then it gets tied to gait, and it's forever tied.

Re: Hackers manage to unlock Tesla software-locked features

#707
post #435

Earlier quoted context omitted.

That's why I also rotate license plates and repaint my car twice a year.

you're joking, but there's a whole genre of "adversarial fashion"[0][1] dedicated to making clothing that spams these sort of public data recognition services. Hoodies with license plates, face masks with weird facial features, etc. Often optimized against actual neural networks too [0] https://adversarialfashion.com/ [1] https://www.capable.design/

This is really cool. Though the Capable Design site with its animations is a bit adversarial to me browsing it.

Re: Hackers manage to unlock Tesla software-locked features

#708

Earlier quoted context omitted.

That's why I wear an rpi connected to four lcd's on my face that display randomly chosen beard tiles. It's also why I started Our Lady of the Anonymity Pool where we gather for music and fellowship, and to recharge and distribute beard screens to our congregants and visitors.

Phillip K Dick imagined a "scramble suit" that did just that in a Scanner Darkly, continuously randomizing the users facial features.

The film has a good representation of it: https://www.youtube.com/watch?v=2aS4xhTaIPc

Re: Hackers manage to unlock Tesla software-locked features

#709

Earlier quoted context omitted.

The way I see it is that you're supposed to own the car and every feature you paid for it.

Which would you rather have: Option A: A vehicle that lacks the hardware for heated seats, heated steering wheel, and driver assist that costs $25,000 to produce and that you pay $25,000 for. If you want these items next year, you have to buy a new vehicle. Option B: A vehicle that includes the hardware for heated seats, heated steering wheel, and driver assist that costs $27,000 to produce. You can pay $25,000 now a…

But you know how this will end up with you paying 30,000 upfront AND the yearly 500.

Re: Hackers manage to unlock Tesla software-locked features

#710

Earlier quoted context omitted.

Okay, but in that PlayStation example you DIDN'T pay for the games, but still decided to 'do what you want'. How is that legitimate but attempting to prevent it not?

Because you also prevent legitimate uses of such "feature", such as playing games you purchased legitimately from other regions, as that "feature" also allows to defeat region-locking. As for why not just buy those same game versions released in your region, some games were just never released in some regions. Another common use is running legitimate homebrew software. So logically, it isn't modding/unlocking the con…

This, or you want to have a backup of your disk because your younger brother isn't especially gentle, or you want to have a second copy of your game so that you can have one at Dad's home and one at Mom's.

And these use-cases aren't only legitimate, in France they are even legal and in exchange we pay a tax whenever we buy a media storage device (Taxe sur la copie privée).

Post reply on HN