Tesla: Security Vulnerabilities
cvedetails.com
cvedetails.com
Obtaining code execution, persistence, or privilege escalation on a Tesla is a formidable challenge. Pwn2own went many years without there being any compromise of the vehicle, and last year's compromise was done by a firm that dedicated a lab and team of people for more than 6 months.
That said, neither CVSS scores, security researchers, nor security teams are perfect. Some reports will be marked as won't fix, some teams won't publish vulnerabilities as CVEs, and some CVEs will be wildly inaccurate. But yes; they're going to pay attention to them.
Cars have government-mandated safety features, and manufacturers are forbidden from adding kill switches. Selling a car with (manufacturer-sanctioned) root access would be legally the same as including a kill switch letting the owner disable safety features.
If an owner cuts their brake light wires to flee the cops, it's 100% on them. If a manufacturer included a switch for it, they'd be in massive trouble.
I know the vehicle data recorder, and I've heard that LTE radios have to report occupancy, though I can't find a requirement that cars need an LTE radio.
There's rumors cars will be mandated to support remote deactivation, but the story is unclear: https://www.usatoday.com/story/news/factcheck/2023/01/19/fac...
relevant: https://consumerwatchdog.org/sites/default/files/2019-07/KIL...
Unless it's mandated by law that there must be anti-circumvention features (components checking system integrity, DRM-like), which root access would actually contradict. But that'd be completely different from prohibition to introduce a kill switch. That'd be a legal requirement that a vehicle or some of its parts mustn't be user-serviceable.
Root access is not a way to break stuff, even though it can be (ab)used as such - it's most certainly not its primary use case. It's a maintenance feature, enabling rightful owner to be able to diagnose, maintain and enhance their own vehicle's software without resorting to hacks. I'm sure that most people would use that to tweak their multimedia console (like adding CarPlay support) or get more diagnostic info about some failure they're facing, not hack their engine control module in some illegal way.
NHTSA forced Tesla to do a recall because the in-car computer allowed the owner to play custom audio on top of ("obscuring") the pedestrian warning tone.[0] If the in-car computer allowed them root access, NHTSA would have an aneurysm.
> as long as manufacturer doesn't provide a script or otherwise encourages you to `kill -9 safetyprocess` or something.
Doesn't matter.Scripts will be circulating online within days. If Tesla doesn't stop it, now they're knowingly complicit. Headlines will feature sympathetic low-knowledge users who followed directions, reasoning that it's safe because "why would Tesla let me do it otherwise??" Fin.
--
A rooted car is a nice dream, but it's just a dream. We'll never be allowed to sell a (fully) rooted car, just like we can't sell a fully-rooted (w baseband) phone. The Wild West is over folks! Last round's on me... :)
If we're very lucky, some manufacturer might give root access to a (heavily firewalled / air-gapped) media computer.
[0] https://static.nhtsa.gov/odi/rcl/2022/RCONL-22V235-2686.pdf
However it goes without saying if users could play a tone of their choice in addition to the required noise, no one could have objected to it.
The vehicle effectively became non compliant to one[1] of the fmvss rules
[1]https://www.regulations.gov/document/NHTSA-2016-0125-0001
Is this a tactic that people use to evade police? I can't really think of how this would be advantageous.
...although I expect that to actually be a law once self driving is figured out and widespread
If they would, they wouldn't have to pay Tesla for the SW extras, and just sideload them for free later.
On top of that, root won't give you _a lot of access_ to the car AFAIK. Some specific features are gated under some specific operations that require a sequence to unlock the gateway. If you also add to the mix the secure boot, it might be hard to do persistent harm other than what the infotainment usually does - you can't flash the autopilot system nor you can interfere with the basic driving functions (?). I'd be happy to be proven wrong though.
> * DISPUTED * Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended.
HackerOne says there have been hundreds reported and most car vendors can't OTA patch.
Those who don't have any haters have to pay for that valuable information, and still end up left wondering if the feedback is too soft.
If you're not repulsed by Musk, you haven't been paying attention. He is an abhorrent human being, antisemite, conspiracy theorist, anti-human rights, philandering, anti-free speech, billionaire troll. Every one of those claims has citations based in reality. Sorry to burst your bubble.
> they'll work feverishly to find and yell about any and all of your flaws and weakness, for free.
This is a very questionable assumption. I don't see why a black hat who manages to pwn Tesla is going to then turn around and responsibly report the vuln they're using instead of doing maximum damage to the brand, potentially endangering lives of drivers, or selling their 0-day to some other malicious actor.
I wouldn't rely on it as an armored vehicle. If I want extra protection, then I would spend money on uparmoring it.
https://www.quora.com/How-thick-of-a-hardened-steel-plate-do...
Toyota should do same marketing tricks with new Prius.
Starting with the handgun, the two most popular calibers are 9 mm and .45, and if you shoot hollow point rounds, they can even be stopped by a few inches of drywall (hollow points are designed to expand on contact), and lead bullets may also be stopped by the truck if they are shot at an angle, but I wouldn't be sure about high-penetration rounds like full metal jacket. The Tommy gun is also handgun-caliber (assuming they shelled outout a small fortune to rent a real one, .45).
Shotguns have an even wider variety of available projectiles. A shotgun shooting buckshot has far lower kinetic energy behind each projectile than a handgun, and their velocity falls off very quickly with increased range. A slug (a solid chunk of metal) designed for armor penetration, on the other hand, will penetrate 3 mm of steel easily, with similar caveats about range.
If anyone in Arizona gets a Cybertruck and is interested in more testing, I own a (legal) machine gun and I would be honored to test your vehicle’s bulletproofing. I’ll even supply the ammo.
Al Capone hates this one weird trick.
Where do you live that you actually worry about someone shooting your vehicle while you're out driving?
Wherever it is, you need to leave if that is a valid concern.
AK47 - accelerate
So we should expect the exploit market to include buyers for assassinations (of occupant or person on the street), extortion ("every hour that the Bitcoin aren't transferred, we will take over one of your customer's vehicles in an extremely tragic way, and later we will tell the news media that you declined to prevent it"), economic sabotage, market moving, terrorism, and warfare.
I would bet that there are multiple unfriendly nation states who have intelligence groups persistently looking for ways to penetrate vital networks and secrets, like Tesla's, just to have the option of causing pandemonium if they wish to.
and the ability for Tesla to update the firmware remotely means they don't have to do a recall in order to fix an issue.
Source: I'm a paid hater. :)
https://arstechnica.com/tech-policy/2023/11/elon-musk-and-te...
But I think that has nothing to do with this. Tesla has, for better or worse, one of the most "connected" vehicle systems. There are things I don't miss in my car, but I certainly like other things.
That just makes it a bigger target. Attack surface and all that, more opportunities.
It doesn't have to be about "the haters".