Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

81–90 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#81
post #4

Someday, all cars from a particular brand will be made to crash during rush hour. The carnage will be immense. Emergency services will have to go off-road to bypass the snarl. There won't be enough helicopters to meet the demand. The brand that could cause the most damage is probably Bosch, a major automotive component manufacturer.

The thing that worries me is that it doesn't take self-driving tech to make this an issue. Existing safety systems on most cars can control brakes, steering, throttle, airbags, etc.

The threshold issue is remote updates of car software. And Tesla had made that more mainstream and attractive to other manufacturers.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it."

I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double standard. Around 37,000 people in the US die in car accidents every year[1]. That's 100 people a DAY. There is a huge cost to not adopting new safety measures, even if it depends on immature tech, and that needs to be factored against the potential new unknown risks.

Driving to work is almost certainly the riskiest thing you do most days. I find it plausible that people 50 years from now will think that the cars we drove before 2010 were unconscionable death traps.

[1] https://en.wikipedia.org/wiki/Motor_vehicle_fatality_rate_in...

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#83
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#84
post #31

https://medium.com/@mpesce/the-great-hack-part-one-attack-70... "The first thing that happens is nothing. Your smartphone stays black while you swipe at it and press the various buttons. Has the battery gone flat? You could have sworn you left the house with a full charge. Now you start to wonder how you’ll get your car out of the parking structure without a working mobile. That thought hadn’t occurred to you before.…

This reminds me strongly of Daniel Suarez' book Daemon, https://amzn.com/0451228731

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#85

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

I wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day.

It would also align hackers interest with the businesses they are helping secure.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#86
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

OP meant two types that are indifferent to consequences.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#87
post #47

Earlier quoted context omitted.

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible…

People still want regular map updates, live updating traffic information, and play back stuff from their phone on the in-car entertainment system. All this exposes cars to data communication outside of the car repair shop. Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.

There is some level of communication, but there really shouldn't be.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#88
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

Agreed. Another could be solo blackhats who just want to make money, who have no state sponsorship. Tangental, but I also hesitate to create such a massive bucket for "mental instability" like that. It's easy to find when someone who does something difficult to understand, or against what we would do ourselves, and then just say "well they're mentally unstable." Definitely the case for some, but it seems like a lazy dismissal with no attempt or interest at understanding.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#89
post #8

Can y'all add "in 2017" to the title here?

This article is from three days ago (August 27th, 2020). I suspect the underlying issue was under a 3 year NDA/agreement. It would be misleading to label an article from three days ago from "2017," particularly as this is the first reporting about this ever.

I'm not saying add "(2017)" I'm saying clarify that the hacker gained the control 3 years ago, not just now.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#90
post #47

Earlier quoted context omitted.

The difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible…

People still want regular map updates, live updating traffic information, and play back stuff from their phone on the in-car entertainment system. All this exposes cars to data communication outside of the car repair shop. Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.

Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.

I think you've just identified the root cause of at least one set of problems. The essential control systems in a vehicle should ideally be separated from other vehicle functions to prevent interference, whether accidental or deliberate, from compromising vehicle safety. The approach now being taken by manufacturers with their always-online, increasingly automated cars may be undermining that separation, without necessarily having adequate safeguards in place to ensure safety and reliability are maintained.

Post reply on HN