Security researchers collect awards for Tesla exploits at Pwn2Own Automotive
bleepingcomputer.com
bleepingcomputer.com
It’s their advantage when it comes to coordinated user experience, but might become a problem as the fleet size increases and becomes a more valuable hacking target.
I could see security becoming a bigger part of CarPlay/Android auto’s pitch to OEMs.
Tesla has a (IMO rediculous) high market cap and stock value. A severe hack could affect that, which, combined with a short position, would allow attackers to make a large amount of money.
What I'm saying is: Tesla already is a valuable hacking target.
The good(?) news is that e.g. WannaCry took out large, "boring" companies, like Maersk, or MSD. These companies typically have a low Alpha, low volatility, and people invest in them for long term: decades rather than weeks. Whereas with e.g. Tesla, every fart that Elon makes has an effect on the stocks.
https://news.ycombinator.com/item?id=38932228
According to one of the comments: "The price of BTC initially jumped 3% on the hacked tweet. That's $25bn+ of market cap."
From a purely pragmatic perspective, Tesla's that occasionally and irregularly crash are a way better alternative than terrible human drivers.
It's lifting secret keys that allow criminals to open any Tesla 'till an OTA update, or callback has been rolled out. For days exposing your Tesla+luggage to theft. Or just breaking stuff: imagine the flack of every tesla driver suddenly losing access to navigation or entertainment for weeks. Or camera access: imagine the outrage if hackers can record and publish anything done and said inside and around Teslas in the last months?
While I don't disagree that Tesla is a valuable attack target, the reality is that for market value security does not matter.
There can be a massive attack on Tesla announced tomorrow, the stock will go down 5% for a few days and recover within a month. Nobody cares. It's a depressing reality.
If they try to emulate Tesla without the experience making it secure they could be even worse
traditional OEMs do not make a EV that is just a ICE with Electric Motor and battery, the traditional OEMs BEV platforms are completely redesigned to put in "features" that no one wants, and no one asked for to enable OEM control over every part of the car, enable them to turn features on and off in software and OTA (you know so they can make your pay monthly for your heated seats)
Good joke. Have you seen any of the stolen cars because of CAN Bus security flaws lately?
Nothing is air gapped. The Android entertainment system running 4.0 because of 32MB RAM requirements is fully connected to the CAN bus.
It's a safety nightmare.
https://www.propelex.com/hacking-cars-remotely-with-vin-numb...
How come other cars aren't submitted to Pwn2Own?
way to go since it became common for cars to constantly broadcast wifi and bt beacons from unpatched software stacks
hence the criticism targeting the laziness in building a car with the same components used for mvp webshit
Customers should not buy connected products if there is not a really good reason to have them connected.
I guess that's my point: people choose base on "how much more convenient is it vs how much more expensive?" where security should be part of it. Somehow people seem to think that "security is under control". It is not: even BigTech gets hacked all the time.
It's similar to premature optimization or overengineering stuff at work. There is no need to overdo it.
You mean because you live in a country that has never been (and probably won't ever be) unstable or targeted by someone? Have you ever heard of NotPetya and its global consequences (which could have been much worse, to be honest)?
We are connecting more and more critical stuff to the Internet, pretending that security is not an issue. That is a problem.
> It's similar to premature optimization or overengineering stuff at work. There is no need to overdo it.
Sure, I agree that there is no need to overdo it. Now if we need to talk about the state of the software industry, I feel safe in saying that most work is "underdone" these days. I haven't had an issue of premature optimization in a long time, but I have issues of "very bad code thrown out there without care" on a daily basis.
Similarly, being paranoid and doing nothing because of security concerns is probably not the right way. But not caring about security at all is on the other extreme :-).
I reached the same conclusion time ago. It is frustrating when I have to replace devices, it is a market for Elois waiting with complacency for the harvest. Maybe they rely in the fish shoal mass?
You've been downvoted for your comment, so I guess mine is also going to be Eloized.
Haters gonna hate :-)
Stuff is on the internet. If you're convinced it's safe for your phone[1] you should be able to be convinced it's safe for your car.
[1] And, no, it's not particularly more safe for your phone than for your car. Apple and Google are incrementally better at this than GM is, surely, but everyone has zero days.
No no no no, NO!
Your phone can NOT kill anyone. Because you trust the software running on your phone to show you the weather forecast should not (as in NOT AT ALL, EVER) mean that you should trust any software that would control a rocket sending you to space.
thou, there are other, less dangerous ways to implement that feature
Exactly, we agree here!
> If connectivity gives you huge UX boost and maybe sometimes there might be a security issue, well, you take the connectivity (generally speaking).
Maybe you do, I don't. Especially not for a vehicle that can kill me (or others).
> Yeah, I'm exaggerating but so are many screaming against anything connected.
I work with embedded systems, I can tell you that the state of security in my field is pretty alarming. I personally would not use the products my company sells for anything important.
I will jump on that bandwagon the day there is a remote, no physical access needed exploit that can intervene on brakes, steer or accelerator in a connected car. Until that happens, I will keep my opinion that advantages are bigger than disadvantages.
Don't Teslas get firmware updates for the self-driving over the internet? Or are you saying that "you don't see a problem because you don't choose the cars that are vulnerable to that"? Because the main topic here is security issues with Tesla cars...
But this starts looking like the famous XKCD comic [1], why not just throw some bombs to achieve the same goal?
You are literally comparing a few bombs to Hiroshima. Except nuclear weapons cost billions to develop, billions to produce and deploy, are complex and difficult to successfully use against targets, and are almost impossible to use stealthily.
Turns out handing out nuclear weapons for less than the cost of a tank, or you know starting a new McDonald’s franchise, is a serious cause for concern.
It is estimated that a few hundred thousand have died in the Russo-Ukrainian War and that has cost billions and required open warfare. It literally costs 1,000x as much to cause such casualties using traditional techniques. Conflating them makes about as much sense as claiming that Usain Bolt is neck-and-neck with a Atlas V rocket or that Earth is basically the same size as Jupiter.
The question, really, is "how likely is it to be vulnerable, what are the consequences if it is, and why would I accept that risk?". In your case, you are saying that you are ready to accept the risks coming from a security breach in a self-driving car if in return it gives you the comfort of not sitting in a cold car.
That's fine, you are allowed to not care about security. But I don't think it's reasonable to say "there are no security issues and there will never be any".
(I'm not including in the equation theft, because any kind of car can be stolen anyway.)
Sure, but that's completely ignoring the consequences of everybody doing that, too. Just like for privacy. "If I share MY data, it's okay" -> sure, but when everyone does, it becomes a different matter. If all the vehicles are connected, and someday all the vehicles stop working (maybe due to a collateral effect like NotPetya, maybe due to some voluntary attack), then that is a problem.
My point, in the beginning, was that we should not connect everything. Not because everybody is individually the target of a serious threat actor, but because connecting everything in mass with bad security is dangerous. We should stop putting mics and cameras and Internet access into everything just for some marketing benefit. That's all I was saying.
I don't get that. So you want to prevent regular companies from abusing your data, but you don't mind so much about bad actors abusing it? Presumably bad actors have an incentive to hurt you, whereas regular companies have an incentive to make more profit (and hurting you is a collateral damage).
I mean, if we can't agree on the fact that having any group (governmental or not) out there have access to some IA trained on all the data of everybody is a national security risk for pretty much everybody, I don't think we can go any further in this discussion. We'll just have to agree to disagree :-).
What about if I can remotely hack into your car, crank up the heater and leave that running overnight so that when you head out to your car in the morning it's sitting at 0 battery, that's certainly super annoying. Could I potentially exploit the battery management system and run your battery to 'actually 0' damaging or potentially destroying your very expensive battery?
https://www.theverge.com/2015/7/21/9009213/chrysler-uconnect...
I wonder how the conversation would change if it were a plane and not a car. Seems like both Tesla and Boeing are having similar quality control issues.
"I personally would not use the products my company sells for anything important."
I feel like most products today are not meant to be important. Most seem to be about convenience with the design thought of "if it breaks they can just do it manually", even if that's not always applicable. Or people forget how to do it on thier own like without blind spot detectors or backup cameras.
Imagine a hack that randomly disables blind spot detectors or freezes/replays backup cam footage? A whole generation would have severe issues because they trust it.
I really don't get how people are not becoming paranoid about planes. I used to say "it's much safer than taking your car, don't worry". Now, given the problems Boeing has had in the last few years (which was not "bad luck" but rather "poor engineering"), I don't feel like telling people who are scared to fly that planes are particularly safe.
Still nobody around me seems to even wonder what plane they will use for their next flight. In many ways the covid vaccines were much more thoroughly tested and therefore safer than (at least Boeing) planes, but still a ton of people were afraid of the vaccines and nobody of the planes :-).
Simple: it's not the same threat model. Tiffany's protects something extremely valuable that they keep behind those windows. If you had the same stuff behind your windows, you would be advised to get the same security.
As if driving a 1200kg at 80km/h was not "dangerous" enough for people around.
- Imagine relying on a closed source app to drive a car - Imagine relying on some blinking lights on the dashboard to drive a car - Imagine relying on your hands and feet to drive a car
It all boils down to driving being dangerous in general. You have to put your trust somewhere - and also trust that other people's trust and self-awareness align with yours.
(Note: Earnings are set to be released after hours today)