Hacking my Tesla Model S
su-tesla.space
su-tesla.space
- It is a blog with only 1 entry.
- The Whois entry is "WhoisGuard Protected" in Panama: http://who.is/whois/www.su-tesla.space . Very bad timing with the #panamapapers. The non-technical depth and the naive writing let me imagine that a junior social media employee could have done it. And I'm disappointed if Tesla hired such people / let an intern write a PR article.
- There is no mention about the previous testimonial of the guy who tried to hack his Tesla, received a disabling upgrade and a phone call from Tesla. https://news.ycombinator.com/item?id=11255160
- He pretends to have done "2 months of research". What could be researched? There is no public documentation and the hackerspace is still empty. At the very least he would have mentioned that he managed to overcome the item above.
In the best case this is an organized leak from Tesla: Let's hope they'll use this channel to unofficially explain how to hack the Tesla.
Because
* when I ask CloudFlare to stop resolving phishing domains with their nameservers they don't care.
* when I ask amazon to remove the content from their networks that's clearly against their TOS, they don't care.
* when I try to get in touch with PrivacyGuard about this domain, they don't care either.
* I ask aweber.com to cut off this customer who they are providing mailinglistservice for, they don't care.
These are all at least semi-reputable companies, who through inaction continue to allow criminals to abuse their infrastructure, and do not allow me to directly contact this offending customer.
So there is no way for me to find out which entity is responsible for actually creating this phishing operation. Granted, they'd probably fake whois data anyhow, but it's my last straw :-)
Now, I'm actually all for anonymity, I'm just frustrated with trying to remove this phishing site that's been up for months now.
[0] https://news.ycombinator.com/item?id=11440612 [1] https://news.ycombinator.com/item?id=11441113
- Namecheap's WhoisGuard. Do you really think I'd not try and protect myself? I was debating for a week whether I should post anything at all. Tesla sure as hell knows someone new is doing something somewhere. I'm trying REALLY hard to make it so absolutely nothing can be easily linked back to me. The "dramatic reenactment" had to be done. I have pictures of me actually rooting but the PS1 on the car is tesla@cid-<VIN>$ Can't really show that if I'm trying to be anonymous. Funny anecdote: I had posted it Tuesday night before bed, but I didn't show anyone. In the morning I was driving to work and looked down at my IC. So, you can name your cars, and the name I gave my car was on the IC. Sure enough, the factory mode IC picture had that name. It was a fairly unique name, and I had to hurry up and censor that one too.
- Sorry my blog doesn't pass your technical writing course. Thank God it's just a blog and I can write it however I want.
- There's no reason to mention the previous hacks from other people. Are they me? No. You can read that stuff somewhere else.
- Ahh, you caught me on the "2 months of research". That's the term I use when I'm actually saying "2 months of slacking." I was distracted by new coloring books for a while. Also I really didn't want to have to make the cable. I was trying to get a salvaged one for a while. Eventually I had to suck it up.
So, sooooorry to disappoint you that it's not an organized leak from Tesla and that it's not the "best case". I knew the post would be somewhat popular, but nowhere near this popular. I thought it'd be the later posts where I'm actually showing stuff instead of me just ripping my car apart that people would love. It's actually funny when a friend of mine told me about this thread. Here I am terrified out of my mind that Tesla was going to figure out who I was, and then everyone is saying I AM Tesla.
Recent events such as Nest from Google, a company can decide to shutdown your device. Cellphones that don't come with root are the trend. Recent games require player to stay online for completely nothing other than DRM purpose. And by the way, how can someone in Tesla just downgrade people's car because he got root?
This is just the beginning of kill switch. Big companies just field testing how tolerate customers are nowadays. Once the new become the norm, you don't know what comes next.
I can see that ubuntu server has proven itself in a lot of real-world environments, but wouldn't they have to run their own fork of Ubuntu at some point? Or is the distro management toolchain in the Ubuntu world more advanced than for example some bsd or centos?
Edit: I am talking about the output on this screenshot: https://4.bp.blogspot.com/-e08E6tXwQvc/VwSTUbXgFDI/AAAAAAAAA...
This is speculation, but I believe NVidias reference image, Linux4Tegra, is based on ubuntu.
As per the license... the license to use it is revoked, not until they distribute the code, but until all licensors grant a new one.
It would really be funny "if" this were an organized leak.
Waiting for the EFF lawsuit that you should be able to root your car without voiding the warranty (and then lobbyists paying congress to prevent that, then in 10 years the supreme court deciding).
b) Previously on HN [1]: 12 and 16 [2] hours ago, the first one has some (mostly: 'The article is light on details') discussions.
Can we ask for an investigation here? I'd like to know:
- Do the IPs of the 3 people who posted the articles match an IP of Tesla Motors?
- How did the 3 people discover the articles?
- How come they posted different urls, with different titles, to the same article?
If my intuition is correct, you might flag the accounts; but even more interesting is you might happen to uncover an deceiving behaviour from Tesla. Passionating!
Tesla's ASN is 394161 and I only see one block of IP's allocated to them 209.133.79.0/24. So that's obviously not enough IPs for the entire company.
Hopefully somebody smart enough will uncover another way to correlate this information back to Tesla.
I looked and found no evidence, not even a tinge, of the things you're asking about. Seems most likely that a bunch of people ran across the story on the internet and thought HN would like it. Tesla is one of a few strains of high-grade local catnip, so they weren't wrong.
Btw other users posted the article too but hit the dupe detector. The ones who varied the URL made it past the dupe detector, which is how it's designed to work.
As for the actual HN posts, I only posted the first one, then moved on with my life. Others told me that the second one was then posted, so I went in there to clear up any misconceptions. I woke up this morning being told by a friend that this one had been posted.