HomeTechnologyResearchers jailbreak a Tesla...

Researchers jailbreak a Tesla to get free in-car feature upgrades | TechCrunch


A group of researchers said they have found a way to hack the hardware underpinning Tesla’s infotainment system, allowing them to get what normally would be paid upgrades — such as heated rear seats — for free.

By doing this, the researchers essentially found a way to jailbreak the car. This may also give owners the ability to enable the self-driving and navigation system in regions where it’s normally not available, the researchers told TechCrunch, though they admitted that they haven’t tested these capabilities yet, as that would require more reverse engineering.

The researchers will present their research next week at the Black Hat cybersecurity conference in Las Vegas.

Christian Werling, one of the three students at Technische Universität Berlin who conducted the research along with another independent researcher, said that their attack requires physical access to the car, but that’s exactly the scenario where their jailbreak would be useful.

“We are not the evil outsider, but we’re actually the insider, we own the car,” Werling told TechCrunch in an interview ahead of the conference. “And we don’t want to pay these $300 bucks for the rear heated seats.”

The technique they used to jailbreak the Tesla is called voltage glitching. Werling explained that what they did was “fiddle around” with the supply voltage of the AMD processor that runs the infotainment system.

“If we do it at the right moment, we can trick the CPU into doing something else. It has a hiccup, skips an instruction, and accepts our manipulated code. That’s basically what we do in a nutshell,” he said.

With the same technique, the researchers said they were also able to extract the encryption key used to authenticate the car to Tesla’s network. In theory, this would open the door for a series of other attacks, but the researchers said they still have to explore the possibilities in this scenario.

The researchers said they were also able to extract personal information from the car such as contacts, recent calendar appointments, call logs, locations the car visited, and Wi-Fi passwords, session tokens from email accounts, among others. This is data that could be attractive to people who don’t own that particular car, but still have physical access to it.

Mitigating the hardware based attack that the researchers achieved is not simple. In fact, the researchers said, Tesla would have to replace the hardware in question.

Tesla did not respond to a request for comment.



Source link

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

NFL Week 4 injury tracker: Will Jones, Watson and Montgomery play Thursday?

ESPN FantasySep 26, 2023, 04:56 PM ET6 Minute ReadESPN's Fantasy...

How the Writers Deal Got Done: Inside the Room

Getty Images; Adobe Stock; THR Illustration On Saturday, Sept. 23, Disney...

Top Apple Executive Defends Favoring Google on iPhones

Apple’s top deal maker on Tuesday defended his company’s favoritism...

Read Now

Judge Finds Trump Inflated Property Values, a Victory for New York A.G.

A New York judge ruled on Tuesday that Donald J. Trump persistently committed fraud by inflating the value of his assets, and stripped the former president of control over some of his signature New York properties.The decision by Justice Arthur F. Engoron is a major victory...

NFL Week 4 injury tracker: Will Jones, Watson and Montgomery play Thursday?

ESPN FantasySep 26, 2023, 04:56 PM ET6 Minute ReadESPN's Fantasy Football Week 4 injury tracker, featuring an aggregation of injury updates for quarterbacks, running backs, wide receivers and tight ends whose teams are scheduled to play this week. Here we'll track practice reports, injury updates and...

How the Writers Deal Got Done: Inside the Room

Getty Images; Adobe Stock; THR Illustration On Saturday, Sept. 23, Disney CEO Bob Iger was in Beverly Hills, seemingly living his best life. He was at dinner with Paul McCartney and Eagles alum Joe Walsh at La Dolce Vita, an Old World Italian restaurant with long white...

Top Apple Executive Defends Favoring Google on iPhones

Apple’s top deal maker on Tuesday defended his company’s favoritism of Google on iPhones, a pivotal collaboration that has shaped the modern tech industry and is at the center of a federal antitrust trial against the search giant.Eddy Cue, Apple’s senior vice president of services, testified...

‘Unprecedented’ Secrecy in Google Trial as Tech Giants Push to Limit Disclosures

In a court filing last month, Google argued that it needed its privacy in an antitrust trial that would spotlight its dominance in online search.“Once commercially sensitive information is disclosed in open court, the resulting harm to the party’s competitive standing cannot be undone,” the internet...

How Jalen Hurts finally got the best of Todd Bowles

His stats weren’t particularly pretty. Two interceptions will do that. Still, there were some very encouraging signs from Jalen Hurts Monday night, and he didn’t hide his happiness – or maybe relief is a better word – for finally leaving Tampa with a win. It was at...

‘PAW Patrol 3’ In The Works From Paramount, Nickelodeon & Spin Master

Paramount Days before Spin Master/Paramount/Nickelodeon’s PAW Patrol: The Mighty Movie opens with a shot at No. 1 and $20M, a third theatrical movie has been announced for 2026. The long-running preschool franchise, which is celebrating its tenth anniversary, saw its first theatrical release under Paramount (and Elevation...

David McCallum, Heartthrob Spy of ‘The Man From U.N.C.L.E.,’ Dies at 90

David McCallum, the Scottish-born actor who became a surprise sensation as the enigmatic Russian spy Illya Kuryakin on “The Man From U.N.C.L.E.” in the 1960s and found television stardom again almost 40 years later on the hit series “N.C.I.S.,” died on Monday in Manhattan. He was...

CMF by Nothing launches earbuds, smartwatch, charger (Update: Availability)

TL;DR CMF by Nothing is a new sub-brand that uses the same in-house design team as mainline Nothing products. The first three devices from this sub-brand are earbuds, a smartwatch, and a GaN charger. The products are incredibly inexpensive and will come to the UK at first. India is...

Warriors newcomer Chris Paul can win the room with 11-word declaration

The wisest and classiest move Chris Paul can make in the coming days is to extinguish the fire that started with his cryptic response in his first meeting with reporters assigned to the Warriors. Sometime before next Monday, when Paul and his new teammates gather for media...

Biden, Trump to woo unions in Michigan as auto strikes grow

DETROIT, Sept 26 (Reuters) - Joe Biden and Donald Trump will speak to striking auto workers in rare back-to-back events in Michigan this week, highlighting the importance of union support in the 2024 presidential election, even though unions represent a tiny fraction of U.S. workers.Biden will...

Veteran suicide prevention brings cabinet member to Bentonville

BENTONVILLE – The secretary for the U.S. Department of Veterans Affairs came to Bentonville on Tuesday to meet with community groups from across the state on veteran suicide prevention."Veterans were trained to put a mission or others ahead of themselves," Secretary Denis McDonough told a crowd...