discovering 49 zero-day bugs in EV systems
Holy shit that’s a lot of zero days homies
More holes than Emmental cheese lol
Holier than the Vatican
More holes than even Stanley Yelnats could dig.
Surely, that’s the intention behind the Swiss cheese model?
Btw did you know Swiss cheese has copy protection? I know the thought is pretty random, but I thought I’d share anyway.
90 days till release of Zero-Days 😉 don’t update your tesla 😂 so you can gain root and really own that car
Just flash a custom os 😂
brb flashing TempleOS to let god be my driver /s
I hope it gets called something like edOSon and is filled with subtle insults to its namesake.
I’d fear it would drive into an elephant.
Pretty sure the elephant would win, after all at least one beat a steam locomotive.
Hannah Montana OS for the Tesla!
What a time to be alive!
Scribbles
Another reason not to buy proprietary garbage. Where are the Open Source EVs at?
Open-source EVs are a bit like Gentoo, you have to build it yourself.
There actually are a lot of really cool EV conversion builds on YouTube using fairly open parts. So I’d say this is perfectly accurate.
Wait so was the hacking live?
Yes, pwn2own is a live competition
Anti-libre software licenses can never defend us from Tesla.
Do they directly show(sell maybe) the exploits to the companies?
White hats can be prosecuted via the CFAA. they usually aren’t (most of us are guilty of CFAA penalties) but some companies got sour to fixing their web security and instead would sue and push to prosecute.
So in the early 2010s the white hat community went gray to survive. And companies that don’t pay their bounties oe cause trouble don’t get pen tested by white hats (at least not when wearing a white hat).
Thank you! I appreciate the insight.
How do you know if a company is going to pay to fix?
Do you just have to take a chance and notify them?
Either I make a bunch of money, or they say fuck off, or they send me to jail? It seems too iffy
Thats what white hats would do and what these contests are usually for
But its more like a bughunt with an open Bounty then selling afaik
So, all these exploits seemingly still require physical access to the car/product electronics? If so, that seems to make it somewhat less of an issue (but still an issue of course) than if they could gain e.g. root access without physical access to the car or even proximity at all.
I’m not that worried about my laptop in regards to physical access because I don’t usually leave it in public unattended for long.
My car? Sometimes that thing sits in a parking spot or paid garage for weeks when traveling. I also leave it unattended in public most times I go brick and mortar shopping.
Hell yeah brother.
Wow. Imagine paying $1.4mil to find 49 zero days instead of hiring an actual security team.
The people who did this are fucking idiots.
$1.4 million vs the ability to steal as many Teslas as you want?
I’ll take the money…
bro that’s fucking cheap.
.
White hat shit like this is lame as fuck lol
Hack a 1%s car and run it off a cliff (ransomware breaks, hello?)
That’s some sociopath shit right there. But tbh white hat is better – the people that did this are guaranteed steady paychecks for the rest of their lives, with a lot lower stress than getting one big payday and having to look over your shoulder your whole life
Look over your shoulder? Lol 🤣
Hack a 1%s car
A Tesla costs about the same as a Ford F-150 pickup. You want all those F150 drivers killed too?
(the car could be any of the hundreds of digitalized luxury cars, or a Tesla, sure)