6 ms·
Getting root access on a Tesla Model S
- jacob019 11y agosure would like to take a look at that script
- geggam 11y agoIt is ubuntu.... #!/bin/bash sudo su
- psiconaut 11y ago"This goes through a secret process that eventually gets me connected to the CID (touchscreen) with root privileges." give me back my 2 mins, please.
- shiftpgdn 11y agoI'm pretty sure that wasn't disclosed as lots of dangerous things could be done in the wrong hands.
- corndoge 11y agoRight, so now we just have to wait until someone else with a Model S figures it out and actually posts code.
- marssaxman 11y agoLike... um.... what, exactly? People could take control of their own vehicles and exercise the privileges that ought to come with ownership? The ability to jailbreak a Tesla is the only thing that might make me interested in owning one.
- nxzero 11y agoWonder given Elon's position on patents if they've even thought about open sourcing the software; guessing they have, but never know.
- celticninja 11y agoHis position on patents is that if you patent something you make it public and the Chinese steal it regardless of the patent. By not patenting something they keep it secret. He is not anti patent he just understands that some people DGAF about a US granted patent and will steal your ideas anyway. As such I can't imagine they have ever thought of open sourcing the software behind their vehicles.
- deleted 11y ago[deleted]
- spullara 11y agoIt seems like the new car that you just created should have to be checked out and approved as street legal. How do you know that the changes you have made still meet safety regulations and the like?
- formerly_ta 11y agoThere are lots of things you can do to make a car not street legal. And people have access to them. And it's their responsibility to make sure they only drive a street legal car on the street.
- marssaxman 11y agoOne could reasonably propose that things ought to work that way, but that is not, in fact, the way things have ever worked, at least not in the USA. People routinely make very substantial alterations to their cars and continue driving them on the street with no legal process involved. "Street legal" is not an exacting standard and no inspections are required for an altered vehicle (so far as I know, anyway) beyond whatever routine process your state requires as part of the registration process. (Here in Washington state, that's just an emissions test.) I used to be part of a 4x4 club; we routinely rebuilt our trucks' suspensions, changed out the gearing, replaced wheels and tires with bigger ones, installed power steering systems adapted from some other type of vehicle, swapped our engines or axles out for bigger, tougher ones, swapped out entire drivetrains - you name the component, somebody in the club probably modified or replaced it. We weren't even doing anything unusual by recreational offroading standards, much less hot-rodding standards. We weren't building tube frames, and most of us didn't modify our frames at all. Nobody had ripped off all the sheet metal on their truck and replaced it all with a molded fiberglass replica; none of us installed superchargers or nitrous injection or anything like that. I'd guess no more than half of us even knew how to weld. Modified cars are on the road all the time; you've seen thousands of them whether you realize it or not. If this were a big safety problem, there would have been a moral panic about it decades ago. Tweaking the software in a Tesla is completely insignificant by comparison. No, it doesn't need to be checked out and approved.
- spullara 11y ago
- shiftpgdn 11y agoTeslas are exposed to the internet via the wlan/gsm connection built into the car. It would be very bad if this were exploited.
- marssaxman 11y agoGiven that it involves physical access to the car, and a fairly intensive degree of it from the looks of the photo series, how exactly would anyone but the car's owner or an authorized mechanic go about using such an exploit?
- Hemera- 11y agoI agree wholeheartedly, just as of now have decided not to release the procedure. I said elsewhere but Tesla knows of this and so far has chose to not change it. If it becomes a trend which every owner could easily do I have no doubt they would quickly change their minds. Barring that, there is enough information out there for a determined individual to accomplish this.
- ZoF 11y agoThis. Complete waste of time.
- Skunkleton 11y agoI want my time back, plus compensation for the tremendous let down.
- anaolykarpov 11y agoTotally worth to read the comments before reading the article. Thank you! (no irony)
- sarthakk 11y agoAdditionally, > "This allowed me to make a special REST call to the CID to enable factory mode." > "So, I plugged in my laptop and ran a script I had pre-written: obtain_root". Then, an image of the a script that spouts gibberish to the console. Props to the author for the significant effort they put in the hack. But it does seem like the author is intentionally glossing over some parts of the hack (actually spelling these things out would have been a lot easier). Everyone (including Tesla) would like to know what you did in the script, not what you called it or what newfangled quotes it is printing out.
- Hemera- 11y agoTesla already knows of the procedure.
- electriclover 11y agoCan u email me srschere it is an arizona state University email address (.edu)... thanks!
- Hemera- 11y agoIt can be patched by Tesla. They have so far said they won't fix it, but if it becomes a trend I have no doubt they'll disable it. I know it sucks but it's a decision that I have made.
- ascorbic 11y agoClick on the image showing the terminal. https://4.bp.blogspot.com/-e08E6tXwQvc/VwSTUbXgFDI/AAAAAAAAABo/gCyFvXtCAr0niW71AjTY86_ZQ2iEIxVvg/s1600/hacked.png https://4.bp.blogspot.com/-e08E6tXwQvc/VwSTUbXgFDI/AAAAAAAAA...
- molecule 11y agoURL should probably point to article itself, and not blog's homepage. http://www.su-tesla.space/2016/04/hack-s.html http://www.su-tesla.space/2016/04/hack-s.html
- elyrly 11y agobugcrowd.com/tesla
- klapinat0r 11y agoWould love to hear how the IC-connected network was setup. > disconnect the cable from the IC and plug my earlier cable in to it. This allowed me to make a special REST call to the CID So the cable from the side panel connects to the above network via VPN? Interesting approach :)
- schlowmo 11y agoHm, now wait for what could happen next: https://news.ycombinator.com/item?id=11255160 https://news.ycombinator.com/item?id=11255160
- Overtonwindow 11y agoThere was something about this recently where someone connected in to their Tesla. Then their phone rang and it was Tesla engineers telling them to stop. Did you get a phone call?
- eclipxe 11y agoI'm not sure that actually happened. Recently Jason Hughes (wk057) released some info he found in firmware (P100D) and Tesla engineers rolled back his firmware remotely, but no one called him AFAIK.
- celticninja 11y agoAnd Tesla said they didn't do it or it was not done in retaliation but rather to resolve an issue with the firmware version wk057 was running. I think it eventually got reverted but can't be sure of that.
- Hemera- 11y agoNo, so far I have not seen anything to suggest Tesla knows.
- castratikron 11y agoIf he's talking about getting root on that big screen in the middle, it's been done before: https://teslamotorsclub.com/tmc/threads/let-the-hacking-begin-model-s-parts-on-the-bench.58951/ https://teslamotorsclub.com/tmc/threads/let-the-hacking-begi... However, the guy who did it before told everyone exactly how he did it, without any "secret script sorry :^)".
- Hemera- 11y agowk57 got direct access to the CID by unsoldering the ROM from a salvaged screen. I honestly wouldn't have the guts to do that.
- electriclover 11y agoThis is an easy way to go if you are good at soldering under a microscope to put it back together. I've considered doing it this way but I'd prefer to figure out the software route...
- RubyPinch 11y agosince I was (for some reason) wanting more details, https://blog.lookout.com/blog/2015/08/07/hacking-a-tesla/ https://blog.lookout.com/blog/2015/08/07/hacking-a-tesla/ is something I came across
- settsu 11y agoAs a tech and automotive geek, I find this interesting and would be interested in a deeper investigation into the legal implications between the manufacturer and hacker (software licensing, etc.) as well as how, if any, existing motor vehicle laws apply. For context, I drive an old Jeep that has various modifications (AKA lifted, with various accommodations due to that fact) and I've given little thought to any legal ramifications. That said, I do live in state (Colorado) that, legally, has little to nothing to say regarding such modifications, or only addresses them broadly. In contrast, Utah has a number of very specific regulations on such modifications.