Tesla's charging ports use a standard msg to open on 315MHz and can be replayed
twitter.com
twitter.com
The charging port cover, as far as I know, isn't a security mechanism, and it opening is just a matter of user convenience. Having an easy protocol to open it means that a third-party charger can open it automatically to be inserted more easily, so that seems fine.
Even if they did require some sort of signed message from the charger, since anyone can buy a "wall connector" charger for home the private key would already be out there (unless a visitor had to pair their per-car key before they could use your charger? That sounds like bad ux)
There's already some people in the twitter comments talking about this as a security issue, so I'll respond do that too.
I guess you can sort of say this is a security issue (like I'm sure with enough work you could short the battery or such)... but jamming such a device into a car would be about as obvious as shoving a brick through the window, keying the paint, or any of a number of other physical attacks. This is the same sort of security issue as the security issue of "car's glass windows can be broken by a determined malicious individual". We don't run around with a fear of "cars aren't secure because a malicious person could put a brick through the glass", and a fear of "a malicious person could open the charge port and do something" is way further down the list of any reasonable person's concerns imo.
Where's the drama?
'...some people in the twitter comments talking about this as a security issue...'
For some reason, all minor Tesla recalls become public scandals yet serious safety-related recalls of other automakers are obscure.
Since supercharging is paid and tied to the VIN, that implies that there is some kind of data transfer occurring between the vehicle and the charging station, right? It's not just a dumb terminal connection.
Given that this is the case, could a theoretical exploit use that data connection to gain access to the vehicle and e.g. unlock the doors? Since any common criminal can open the charging port with this exploit, they could also plug in a fake charger to weaponize the exploit and drive away with a free car.
Yeah, I know, sounds pretty ridiculous. But these are expensive cars and it might be reality soon enough similar to how common thieves can buy replay attack devices on the black market now.
I get a strange amount of vitriol from anti-EV folks where I live, I could imagine somebody putting a metaphorical potato in the metaphorical tailpipe. Although that type of person is more likely to use a screwdriver than a replay attack.
Makes sense that they'd ditch this as unnecessary complication.
Doesn't mean that it is a bad design.
And I know what you're hinting at but I don't actually care. Just like a Land Rover is a British car even though it's owned by an Indian corporation.
Then because Ford had absolutely no interest in the brand, they basically invested zero money, the cars stagnated, and yes, by the end of the Ford's ownership, they were absolutely crap and I would not recommend anyone buying one.
Then Ford finally got bored with it, and sold it to Geely, a chinese corporation - but they basically said "we'll leave you alone, here's an unlimited purse of money to design a car that people will want" - and so Volvo designed the new SPA platform, which they used for the XC60 then XC90 then all their other cars, and those were and still are regarded as hugely successful and well designed cars, with good engines. Under the chinese ownership Volvo was allowed to pioneer the plug-in hybrid drivetrains for instance, and they were one of the first ones to offer them.
Nowadays the domination they had in that area is weaning a bit, but Volvo is innovating with immediate launch of SPA2 platform, and hardcore push towards full electrification of all models.
>>I heard they are now Chinese owned, although it seems buyers think they are still Swedish
As far as I can tell, all Geely does is provides budget - the cars are still designed by Swedes. That makes it a Swedish car in my book.
« Analysis of the radio opening of the charging hatch on @Tesla with #URH and #rtl433. Results: frames are the same for all superchargers/cars. A simple 433mhz module and a microcontroller allow you to open the hatch remotely by replaying the sequence! »
And it has been known since 2013 on the tesla forums: https://teslamotorsclub.com/tmc/threads/open-chargeport.2100...
This could be a cool feature! What if the Supercharger stations broadcast that frequency as you pull up to save you a step! ...or... In the "Fully Automated Future!"© The robotic arm that connects your Tesla to the charger emits that signal to access your charging port!
I drive an ICE car that does not have a lock on the fuel port. The gas cap doesn't have a lock either.
This Tesla feature is more secure then my car. And fuel can be siphoned out of my car.
Tesla demoed that in 2015, but didn't make it into a product.[1] Apparently too many people thought it was "creepy".
(That's a good way to do the job. Snake arm robots are quite simple. The tube just contains some pull cables running through disks with holes.[2] All the motors are in the base. So you can build one of these with a protected base and an easily replaced arm tube. The usual problem with snake robots is that the cables wear out. But that's in painting applications, where they're in constant motion all day. A charging robot moves, slowly, for maybe one minute per hour. They're not very repeatable, which is fine in this application. The car won't be in the same place every time anyway. There's a TV camera in the end to find the socket. It's too bad that didn't ship as a product.)
But sometimes these sorts of things have a larger impact than it seems at first. Looking forward to future stories of how teen hacker activists use this security flaw to take down “the man”.
Absolutely, that's why I use a locking gas cap. They aren't perfect but they are a PITA to take off if the key doesn't work. I've had to remove one without the key.
So yeah, it's absolutely possible to just walk up to a random Leaf on the street and extract DC power from it (e.g. to charge another EV or power an AC inverter) but you'd need to build your own cable and controller, and also 500VDC at 100A is extremely lethal so it's a terrible idea....
If it is at all possible to damage the car, then I can image this turns out to be a problem.