As I said in my post below, I just checked mine and the full serial number is included in the device hostname. Since tons of regular PW installs are going to average joe residential sites which will heavily be using crappy outdated ISP provided routers with default passwords and entirely flat unmonitored LANs, possibly with infected machines to boot, it's fair to say that yes in fact the serial number will be able to be read over the internet without any authentication. Anyone who can see hostnames of devices on the LAN can get the whole serial.
Although I also doubt any such network will have any real rate limiting or notice any hammering either, and the serials look utterly trivial to brute force. So I'm not sure the fact that they're all broadcast for everyone even ultimately makes much difference.
* YY is a year, with the first year being 2015. So right now there's only five options.
* L is the revision, of which there is D, E, F, G, H, I- for six options total.
* XYZ is literally the last three digits of the SSID, which means you get that for free.
With all of this information it will take at most 30 attempts to log into the network.
Honeypot free WiFi at a Tesla Super Charger with a legit looking login page: “Free WiFi for Tesla Customers, Login to your Tesla account to access.”
API End points include vehicle unlocking, speed limit settings, etc. Some are not available while the vehicle is motion, so at least there’s that.
(Full disclose: I own a Model 3)
You can only change the password for management portal not the WiFi.
Funny!
https://teslamotorsclub.com/tmc/threads/misbehaving-powerwal...