Man hacks Tesla firmware, finds new model, has car remotely downgraded
arstechnica.com
arstechnica.com
The guy's own post [1] said it was "pending" (e.g. downloaded and ready for an automatic update), not installed. Given that someone else in the same thread notes that the update when installed on their car didn't actually fix the important charging bug it was supposed to, it's much more likely that it was "somebody in engineering decided to cancel a bad update" than his paranoid claims.
[1]: http://www.teslamotorsclub.com/showthread.php/63905-Tesla-s-...
This is correct. It was an attempted downgrade. He stopped it.
> it's much more likely that it was "somebody in engineering decided to cancel a bad update" than his paranoid claims.
This is unlikely. He wasn't being downgraded to the version prior to the current one. He was being downgraded to a much older version that did not contain any of the secret info. And nobody else was experiencing the downgrade. If there is a critical flaw that requires a rollback, you do it for everyone and it's big news. He also made it clear that he found a ton of other stuff and was not disclosing that (yet).
It looks like somebody at Tesla pushed code to production that shouldn't have been pushed since it isn't relevant to any production vehicles. Once the leak happened, there was a bit of a panic and to stop anymore leaks, they tried to downgrade ... which was silly, because if you know how to root the car, you probably know how to make a backup and stop remote access.
We are living in cyberpunk times.
We need something like Certificate Transparency to log ACL hits for all these "connected, but proprietary" things in our lives.
Do we have any guarantees a rogue tesla employee can't just tell your car to drive off a bridge while you're inside it?
http://nypost.com/2016/01/06/uber-will-no-longer-allow-creep...
Not enough evidence to say for sure, so Occam's razor applies.
Regardless, even under your logic an auto-downgrade without a user's input is completely unwarranted for.
I think this is often true, but definitely not always.
We are living in cyberpunk times.
I remember when cyberpunk was fresh and new, before it was a codified collection of cliches. Mind you, this was also a time when an author could write, "His buyer for the three megabytes of hot RAM in the Hitachi wasn't taking calls," and think this sounded futuristic and criminally lucrative.
"His buyer for the three petabytes of hot RAM..." etc...
In academe anything under ten mangabytes is noise these days tho and I imagine the dark economy is two factors beyond anything we have access to. :/
And suddenly this fast, spiky thing appears, that's all nihilism and dystopia and edge and noir and anti-heroes and technology abuse, and instead of looking ahead a billion years it's looking ahead about 15 minutes, and instead of sounding like an orchestra it sounds like the wind over tensioned steel cables, and it wears sunglasses at night and it thinks technology is power and its just so gosh-darned cool...
Yeah, that's pretty much what it was like. Ok, it's all cliches now, but so's a modern punk band.
You might just roll the whole thing back a release, in the first instance to 'update' the hacker to a 'safe' version. If there were a need to roll everyone back then some type of patched new version would need to be released, or, if speed really mattered, just remote downgrade everyone to something safe. The major version numbers might not be the safe releases, the last release from a previous major version might be safer. Hence back to v.12.x.y for him. No malice be involved, just prudent reaction.
It's not malice, it's panic and it's profoundly stupid.
Only those with root access to the car can access the secret info.
There are a handful of people out there who rooted their cars. They are individuals of extraordinary technical ability.
You think they don't know how to make a backup? Or how to stop remote access?
That's exactly what happened. He blocked them and then deleted the pending downgrade.
Would you agree that this extraordinary technical ability individual should be criminally liable in this case?
No.
Cars have had software for a while. Tesla is the FIRST and ONLY company to do over-the-air updates. I don't think you should be criminally liable for turning a feature off.
Sorry, but once you push to production, the cat is out of the bag. I absolutely HATE this new attitude that it's OK to not thoroughly test code before pushing it to production, because hey, you can always fix it later or roll back, right?
No. There's no mens rea. He should be liable for damages in civil court.
What if you are the owner of a building and you decide you want to "optimize" the fire detection/fighting system because you have some ideas in this area, or maybe you want to run an "open" software on it, with better reporting, and as a result some people die in a fire.
Yes, is totally hypothetical, but you seem to be saying that one is not responsible if he does that, because he was just "hacking", with no mens rea.
It happens every time I put more air in my tires.
https://en.wikipedia.org/wiki/Criminal_negligence
In your case, the person was being reckless. I don't think gaining access to hardware you own can be considered reckless, regardless of the unlikely circumstances that may result. Your death-by-rooting example is entirely hypothetical and has never happened.
Just like drone accidents, each year we get closer and closer to an actual kill as their number increases (https://youtu.be/MvF49R_ZX5E). One day heavier drones will be required to run only certified software if flown over crowds, and rooting those drones will raise the same question.
It has never happened? Who cares, what does that matter?
By your logic, if the manufacturer puts out software that is responsible for a death, would you throw the software developer who wrote in jail? That's silly.
All this stuff is limited to civil liability.
If I root my phone and accidentally brick it, nobody here would say, "Gosh, that's terrible, it's all Motorola's fault!" They would say, correctly, that if blame is to be assigned, it'd all be mine.
I think it's even clearer with something where even small errors could be fatal. Anybody rooting a car is betting both their life and those of the people they encounter on their technical skill. It might be an excellent bet, but they should be entirely aware that they're betting.
Yes?
So is every guy who pops his trunk and starts working on the car? And people have been doing that since the very beginning. This isn't anything new.
There are three new things here.
One is that automotive mechanical systems are relatively well understood. If you are a mechanic working on a car, it was literally designed for that. The manufacturer makes manuals explaining how to do it well, and they sell extra parts that are meant to be swapped in. There is a century or so of evolved practice an understanding here. This is not true with drive-by-wire software, which is certainly novel, and is frequently terrible.
The second is that mechanical stuff is generally linear and easy to understand. If I change a lightbulb, I have a pretty good understanding of what that will affect and what it won't. Software is highly non-linear. A novice working on, e.g., a device driver, can have effects they will find extremely surprising.
The third is that in software we have a long culture of consequence-free tinkering. We're used to being able to power-cycle something, to restore from backup, to just re-install the OS. Any software person is going to have a lot of habits and biases that become extremely dangerous when working with life-critical systems.
But in the case of drunk driving, you were negligent at the point of taking the first drink for not making safe transportation (or lodging) arrangements while sober.
Unfortunately from this thread it seems clear that we'll just have some blowhard Tesla manager swearing that "our code is perfect and any change to our code would automatically cause vehicular Armageddon, never mind the fact that we change it on a regular basis!" They won't want me on the jury...
I would love if Tesla's were open for hacking but a previous article [0] pointed out that there appears to be a strong stance [1] against this.
Disclosure:I am a huge fan of the Tesla brand, just cautiously optimistic.
[0] https://news.ycombinator.com/item?id=11233898 [1] https://news.ycombinator.com/item?id=11234465
On the other hand, if some guy found a major security flaw and posted it all over the internet I bet the car would be remotely driven into a brick wall at 100mph+ with the driver inside.
http://www.huffingtonpost.com/2013/06/24/michael-hastings-ca...
That's a bit much. They'd probably just revoke his license to use their software, leaving him with an expensive brick.
That sounds like something the government would do to your car if they suspected you were a terrorist.
Or at the very least, Elon Musk is the voice of Tesla, but there are many other people who work there. You judge a company by their actions, not their words. I'm a huge fan of what they're doing, but not necessarily how they're doing it.
The cars are absolutely awesome.
Unfortunately, they only provide service manuals in Massachusetts (where they are required to by law) and charge $100 per day to view them. Do not sell parts to the public. Ports in the car (obd/ethernet/etc.) are disabled by default. API is undocumented/proprietary. No access to OS. No access to diagnostic information.
Very similar to how Apple does things.
He is the CEO, he is responsible for the actions of his employees that are work related. Under the same guise, he shouldn't receive praises for anything everyone else under him does either.
$ echo -n 'P100D' | sha256sum
5fc38436ec295b0049f186651ebba5fd55e8d7b81eb61cbd00d3f1bf18dd9c81I imagine it was just guessed, though. Any Tesla fan thinking of "cool new upgrade to the car, currently secret" would put a P100D model near the top of the list of things to try.
https://md5hashing.net/hash/sha256/5fc38436ec295b0049f186651...
> (a reverse lookup of the hash posted above yields this)
5 days ago, http://www.teslamotorsclub.com/showthread.php/58951-Let-the-...
If you put 5fc38436ec295b0049f186651ebba5fd55e8d7b81eb61cbd00d3f1bf18dd9c81 into the google, the second link (because first is article about it) will tell you what it is[1].
[1] https://md5hashing.net/hash/sha256/5fc38436ec295b0049f186651...
I haven't read the 48-page forum discussion linked in the article, so there may be more info there, but at the very least the article writer hasn't adequately backed up his claims.
Again, maybe there's something in that 48-page thread that proves me wrong. I'm fine with that. But it makes no sense to swallow the article's simplified interpretation without first doing the homework.
I can't believe you wealthy boys are putting up with this.
Do you guys really want to be sitting on the side of a road clueless over your toy? I don't expect you boys to pull out the DVOM, and Snap-on tools, but a little knowledge of why it broke down?
Isn't it kinda the American way to at least know what the underlying problem is? Or, have we been conditioned into being good obedient victims?
Personally, I feel emasculated if I need to ring a ding ding AAA? Especially, if the problem is minor. Will never know if we aren't able to read up on the toy?
Audi: https://erwin.audiusa.com/erwin/showOrderFlatrate.do ($250/m)
Tesla: https://service.teslamotors.com/ ($350/m)
BMW: https://www.bmwtechinfo.com/ ($250/m)
However, I cannot access the service manuals for Tesla. Because I don't live in Massachusetts. Does that seem right to you?
They even make sure to verify your address by mail to make sure you really do live in Massachusetts before they grant access.