4 ms·
If you read the Wired article I linked earlier you'll see that this is indeed a concern since the updates aren't signed. Tesla is relying on the two way verifi
by breser 11y ago
If you read the Wired article I linked earlier you'll see that this is indeed a concern since the updates aren't signed. Tesla is relying on the two way verification of their VPN that is used to communicate between the car and Tesla to validate the software.
- snuxoll 11y agoThis at least prevents a MITM or a malicious actor from hijacking DNS, etc - since the car effectively ensures it's at least talking WITH Tesla. This doesn't prevent a malicious employee from gaining access to the update server and pushing out an update, but you're going to have to worry about that regardless.
- Silhouette 11y agoThis doesn't prevent a malicious employee from gaining access to the update server and pushing out an update, but you're going to have to worry about that regardless. I'm pretty sure that if your car isn't connected in the first place, so that its essential control systems can't be updated remotely by a single malicious actor like that, then this isn't a significant concern.