4 ms·
Tesla cars can be stolen by hacking the app
- andreasley 10y agoThis was done by installing malware on a Tesla owner's Android smartphone. Tesla's response to electrek [1]: The report and video do not demonstrate any Tesla-specific vulnerabilities. This demonstration shows what most people intuitively know – if a phone is hacked, the applications on that phone may no longer be secure. That is, of course, true. However, is a login and password [2] really sufficient to secure access to a car? Why isn't there some kind of paring between the smartphone and the car? Some argue that stealing a physical key is even easier. Of course it is, but that doesn't mean we can't do better. [1] https://electrek.co/2016/11/23/tesla-hacker-steal-car/ https://electrek.co/2016/11/23/tesla-hacker-steal-car/ [2] https://www.youtube.com/watch?v=vlVFhT-DjnI https://www.youtube.com/watch?v=vlVFhT-DjnI
- janvidar 10y agoThe OAuth token is also stored in plain text on the device. This is by itself enough to locate, track and unlock the car. The app prompts the user for the username/password in order to start the car. Mandatory disclaimer: I'm affiliated with Promon.