Live data from Hacker News

The Big Tesla Hack: A hacker gained control over the entire fleet

electrek.co

91–100 of 195 posts

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#91
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

Those two types in particular are examples of actors that are willing to break the law in this way. Competitors aren't going to contract a hack - like the parent comment said, every 3 letter agency would be after you and suddenly your executives are going to prison.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#92
This is another reason why I think it's incredibly foolish to own a vehicle with an internet connection. Even if the vehicle doesn't support remote control like Tesla there may be a chain of bugs that could be used to do just that or cause other problems.

That's not even considering the major privacy issues that come with such vehicles.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#93
post #83
post #77

Earlier quoted context omitted.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

Surely there’s more than 2 types. Another off the top of my head - competitors.

> Another off the top of my head - competitors.

Car manufacturers do plenty of shady things, but this would be ridiculously over the top. I don't think that would be a serious concern at all.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#94
post #47

Earlier quoted context omitted.

People still want regular map updates, live updating traffic information, and play back stuff from their phone on the in-car entertainment system. All this exposes cars to data communication outside of the car repair shop. Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.

There is some level of communication, but there really shouldn't be.

The problem is that total separation is difficult to achieve with the requirements being placed on these vehicles. Sure, whatever is playing your favourite music tracks over the speakers probably doesn't need to know anything about steering and acceleration. However, your self-driving software is going to have a tough time getting your car to a location it doesn't know exists because its onboard navigation maps predate the existence of that building, or planning a route that avoids an accident it doesn't know about because it has no real-time information about road closures.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#96
post #77

The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.

> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Ne…

>Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No.

Yeah, they do. It's a self declared measure of how seriously they take their security. They valued avoiding the takeover of their fleet at 0.0000125% of their market cap.

The reason I left lastpass was because the bug bounty for a bug that could expose all of everybody's passwords just by visiting a website was, like, about $1k. The company became dead to me in a split second and I wanted out immediately.

....and it's not doing too well these days, from what I can tell.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#97

Earlier quoted context omitted.

I wonder if at some level of bounty payment, you run into the problem of encouraging people to introduce bugs to get a bounty. Probably no one with commit access in a major tech company would risk their career for a few months salary. But for ten years' salary...

It just needs to be a subtle bug designed by someone much smarter than the comitter, that's plausibly deniable. They certainly don't need to understand how it works, or how it's going to be used months or years later. And I understand that this sort of thing happens with governments, and TLAs, and the people leave after a few years to start their own gig with VC funding and subsequent acquisitions and no-one's the wi…

> They certainly don't need to understand how it works

They must need to know something about it in order to verify that it does the malicious thing correctly. It's hard enough to get code right when there's a whole team of people who know exactly what it's supposed to do.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#98
post #88
post #83

Earlier quoted context omitted.

Surely there’s more than 2 types. Another off the top of my head - competitors.

Agreed. Another could be solo blackhats who just want to make money, who have no state sponsorship. Tangental, but I also hesitate to create such a massive bucket for "mental instability" like that. It's easy to find when someone who does something difficult to understand, or against what we would do ourselves, and then just say "well they're mentally unstable." Definitely the case for some, but it seems like a lazy…

I was using "maliciously exploit" here to describe what would basically be the worst case scenario of such a bug (instructing every Tesla to deliberately crash at high speed). I don't think it's in any way a stretch to characterise someone who would do that as mentally unstable.

Of course there's many other ways you could exploit such a bug, but in the context of a "multi-billion dollar" event, it's really only The Big One that's in frame here.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#99
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

Maybe it's maturity in the sense of relationships.

An immature relationship might be based on selfish interests, compounded with power struggles, boundary issues, jealousy, spying, and a little rage and stockholm syndrome thrown in for fun.

A mature relationship is based on trust and mutual respect. It does not concern itself with knowing every detail or trepidation regarding other suitors. The relationship is there because it is valued and there are willing participants.

Now... internet connected devices.

Re: The Big Tesla Hack: A hacker gained control over the entire fleet

#100
post #82
post #46

This is what holds me back from 'smart' devices that have the potential to cause real harm... We've been making motors (electric or combustion) for over a hundred years, and gotten pretty damn good at making them safe and reliable. Same thing with stoves, HVAC equipment, small appliances, etc. These are all mature technologies that we can practically trust our lives with. Internet-connected smart vehicles aren't a ma…

"Internet-connected smart vehicles aren't a mature technology. Not in the sense of this being the win2k era of that tech, but that our assumptions about how to build these systems might be fundamentally wrong. I don't know if it will ever be safe enough to trust human lives to it." I often hear this kind of thing and am really surprised by it. Specifically for the tech in vehicles example, it seems like a real double…

Hopefully in 50 years the whole idea of single-occupancy vehicles will be considered a quaint relic of a much more decadent time, especially vehicles which were allowed such extravagant externalities in terms of pollution and endangerment to vulnerable road users.
Post reply on HN