Controversy Arises Over Tesla’s Cybersecurity Claims
In a recent Senate hearing, Tesla’s Vice President of Vehicle Engineering, Lars Moravy, asserted that Tesla vehicles have never been remotely commandeered. This assurance, however, is at odds with documented events from the past, raising questions about the integrity of the statement.
During the Senate Commerce Committee meeting focused on autonomous vehicle safety, Moravy emphasized the robustness of Tesla’s security architecture:
“We have many layers of security in our system. Our driving controls are in a core-embedded central layer that cannot be accessed from outside the vehicle.”
Moravy further clarified when queried about any potential breaches:
“To answer your question on if anyone has been able to take over control of our vehicles, the answer is simply no.”
The Unfolding of the 2017 Tesla Hack
Contradicting Moravy’s statements, the 2017 incident involving security researcher Jason Hughes challenges these claims. Known as WK057 within the Tesla circles, Hughes uncovered vulnerabilities granting him access to Tesla’s central server, “Mothership”, which communicates with every Tesla vehicle.
As reported by Electrek, Hughes exploited these vulnerabilities using just a vehicle identification number (VIN), allowing him to interact with any Tesla vehicle remotely, including activating features like the Summon function from a significant distance.
In a demonstration to Tesla’s head of software security, Hughes used a VIN provided to remotely activate a car’s Summon feature, moving a vehicle located in California while he was in North Carolina. The gravity of this discovery led Tesla to award Hughes a $50,000 bug bounty, a figure notably higher than the standard at the time, and prompted immediate efforts to fix the issue.
Recurring Security Breaches
The 2017 breach was not an isolated event. A year earlier, in 2016, experts from Tencent’s Keen Security Lab managed to remotely control a Tesla Model S’s braking system from a distance of 12 miles. This was achieved by exploiting the vehicle’s Controller Area Network (CAN bus), highlighting persistent security challenges. Tesla responded swiftly, resolving the vulnerability within ten days.
Tesla’s Security Evolution
While Moravy’s statements at the Senate hearing may lack complete accuracy, it’s important to note the context. These breaches were exposed by ethical hackers who responsibly disclosed their findings to Tesla, enabling swift resolution. There is no evidence suggesting malicious actors have successfully taken control of Tesla vehicles outside controlled environments.
In response to past incidents, Tesla has significantly enhanced its cybersecurity measures, increasing bug bounty payouts and engaging in hacking competitions like Pwn2Own to bolster its defenses. Moravy’s testimony coincides with ongoing discussions about establishing a federal framework for autonomous vehicles, underscoring the need for transparent and accurate communication about security histories.
For further information on past incidents, visit the original Electrek article.
Original Story at electrek.co