Live data from Hacker News

Tesla Model S Ethernet Network Explored

dragtimes.com

81–90 of 112 posts

Re: Tesla Model S Ethernet Network Explored

#81
post #37

Earlier quoted context omitted.

Sure, I agree, but what system checks the signature? A responsible engineering team would have a dedicated piece of hardware for that. For decent security, it would need to physically sit between the untrusted, internet-connected machine and the embedded hardware. Not to mention that there must be some key floating around Tesla that can be used to completely reprogram any Model S from anywhere. Its not the first time…

> For decent security, it would need to physically sit between the untrusted, internet-connected machine and the embedded hardware. TPM style solutions already exist. Keys burned into the chip + verification at boot should do most of the work. > there must be some key floating around Tesla that can be used to completely reprogram any Model S from anywhere. It could be something more interesting. A set of keys where s…

> Even if there is some master key, they wouldn't keep it on a node connected to the network (one would hope...) Some hardware crypto-box maybe?

I imagine Elon sending the only copy to space on one of the recent SpaceX launches, so that they can deorbit it when needed, but to steal it, you'd actually have to go up there and find it ;).

Re: Tesla Model S Ethernet Network Explored

#82

I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. Automotive systems communicate over a CAN [1] bus, not ethernet. In fact, this bus is usually physically separated between drive-critical bus (which controls things like ABS) and "comfort" bus (such as electric window controls, central door locks, wheel-mounted audio controls). Ethernet has none of…

> I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. I'm still surprised people think like this. We had 60+ years of technology hacking to learn that if it is not airgapped, it can be hacked . And even if it is, it probably still can be (cf. Stuxnet). So while I doubt Tesla is using Ethernet to control critical car systems, I also don't think that…

Agree-

Re: Tesla Model S Ethernet Network Explored

#83
post #5

The cool things: Tesla is running Linux (!) and standard technologies/protocols such as SSH, NFS, X11, HTTP, etc. to do things in the car. That is cool, and probably highly efficient since developer test labs can probably just be basic Ubuntu-like virtual machines. The sketchy things: Jailbreaking a car seems pretty dangerous, especially since as far as I'm aware, the electronic systems control things including the b…

No way is the drive control software is running linux, its almost certainly running on its own embedded system.

Depends what level we're talking about surely? SpaceX have their own real time Linux which they do use on rocket systems - stands to reason they might bring a similar idea over to automotive systems.

Re: Tesla Model S Ethernet Network Explored

#85

I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. Automotive systems communicate over a CAN [1] bus, not ethernet. In fact, this bus is usually physically separated between drive-critical bus (which controls things like ABS) and "comfort" bus (such as electric window controls, central door locks, wheel-mounted audio controls). Ethernet has none of…

Thank you for pointing this out. A few additional notes on the way most modern car electronics work: 1) The entertainment system generally has read-only access to the CAN bus via an intermediary DCU. Even if you were able to "jailbreak" it, you wouldn't be able to modify the CAN. 2) The control unit(s) that actually have the ability to modify things like brakes, maximum speed settings, etc. are ECUs ( http://en.wikip…

There isn't any reason why the entertainment system couldn't reprogram the ECUs, I have never seen a read-only CAN controller so the hardware will be able to write to the CAN bus. The OBD-II diagnostic connector provides full access to the CAN bus anyway so once you are inside the vehicle there isn't much security.

You could even run the service diagnostics on the entertainment system and avoid the need for extra hardware in repair shops.

Re: Tesla Model S Ethernet Network Explored

#86
post #13

Can Tesla detect if settings or the files for one of their cars are modified? I would like an option to contact home base to verify that all files and configurations in my car are exactly like their suppose to be, else either disable the car or download the correct software. Maybe a way to enable a developer mode which can only be used on a non-public road. I just can't imagine modifying an electric vehicles computer…

In Germany you have to get your car checked every two years by the "TÜV", if it passes you get a sticker for the license plate without which you are not allowed to drive the car.

Given how critical the software already is, I would be surprised if there isn't a system already in place, that car companies are required to put in, that can use to verify the software for any car.

Re: Tesla Model S Ethernet Network Explored

#87
post #32

Earlier quoted context omitted.

I think the commenter you replied to was inferring that the whole CAN bus was not accessible via the Ethernet network.

Get ssh access to the box connected to the CAN bus and boom, you have access. There must be at least one of those connected because Tesla is able to remote-unlock your vehicle.

There are usually discrete CAN bus firewalls that sit between controllers that are explicitly programmable, and the bus. They might be ASICs, microcontrollers or FPGAs, but there's no way into the mfrom the network. The only attack vector onto the bus is to stab the car with a sharp knife until you have the PCB in your hands, at which point you have owned the car anyways.

Re: Tesla Model S Ethernet Network Explored

#88

I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. Automotive systems communicate over a CAN [1] bus, not ethernet. In fact, this bus is usually physically separated between drive-critical bus (which controls things like ABS) and "comfort" bus (such as electric window controls, central door locks, wheel-mounted audio controls). Ethernet has none of…

Sadly, the segregation between CAN buses is not nearly as good as you would think. ONSTAR, for example, sits on the drive critical bus (and is exploitable). Of course, this is not on a Tesla, but still. http://www.autosec.org/pubs/cars-usenixsec2011.pdf

A few years back, a joint UW-UCSD team showed that car systems are remotely exploitable. They were able to literally call the car's cell phone number and control the brakes/gas/door locks remotely.

http://youtu.be/bHfOziIwXic

Re: Tesla Model S Ethernet Network Explored

#89

I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. Automotive systems communicate over a CAN [1] bus, not ethernet. In fact, this bus is usually physically separated between drive-critical bus (which controls things like ABS) and "comfort" bus (such as electric window controls, central door locks, wheel-mounted audio controls). Ethernet has none of…

> I am very amused that people in this thread assume that this ethernet port allows tinkering with the automotive systems. I'm still surprised people think like this. We had 60+ years of technology hacking to learn that if it is not airgapped, it can be hacked . And even if it is, it probably still can be (cf. Stuxnet). So while I doubt Tesla is using Ethernet to control critical car systems, I also don't think that…

Some high-end luxury cars are remotely exploitable, to the point where attackers can control the breaks/engine/locks using a cell connection: http://youtu.be/bHfOziIwXic

Re: Tesla Model S Ethernet Network Explored

#90
post #78

Earlier quoted context omitted.

Assassination via car hacking would have seemed like sci-fi a decade or two ago. See Michael Hastings conspiracy theories: http://www.huffingtonpost.com/2013/06/24/michael-hastings-ca...

Assassination via physical-access car hacking (cutting brake lines, etc.) has been around for a long time. Seems like a small jump to electronic.

Has there ever been a successful assassination using this method? If some cut my brake lines I would know about it the moment I started the engine and applied the service brakes while putting the car into drive/releasing the e-brake, or become aware of it while maneuvering out of a parking space at speeds under 5mph.
Post reply on HN