4 ms·
At the end of the day, a username and password is everything you need to drive off with any app enabled Tesla. You can perform your attack in a number of diffe
by janvidar 10y ago
At the end of the day, a username and password is everything you need to drive off with any app enabled Tesla.
You can perform your attack in a number of different ways to achieve this, but setting up a free wifi hotspot near a Tesla super charger allows you to target and harvest several such usernames and passwords with very little effort.
Disclaimer: I work for Promon. Feel free to ask me about the attack.
- sfifs 10y agoWell a username and password would let anyone into your primary email account possibly letting them steal your identity and money from your bank account which is again potentially more harmful than stealing a connected car Are you performing an MITM attack from the WIFI hotspot?
- janvidar 10y agoYes, in our case we did MITM to display ads for a "free burger" app containing malware. The app was hosted on Google Play. And, you're right. Once we have access to the phone we can probably do a lot worse than just stealing a car. When it comes to banking apps, they often have mitigations which would require a lot more targeted effort.
- jaclaz 10y agoIf I may, I am a bit perplexed by: >Promon engineers recommend that the Tesla app provide two-factor authentication, should avoid storing the OAuth token in cleartext, prevent easy access to its source code, and use a custom keyboard layout when entering passwords to fight against mobile keyloggers. Security by obscurity?
- janvidar 10y agoI'm not sure where this quote came from, but I can say that the Tesla app should avoid storing the OAuth token in cleartext. Disclaimer: I work for Promon. See our blog post: https://promon.co/blog/ https://promon.co/blog/
- jaclaz 10y agoThe quoted text is the last sentence in the article this thread is about: http://www.bleepingcomputer.com/news/security/android-malware-used-to-hack-and-steal-a-tesla-car/ http://www.bleepingcomputer.com/news/security/android-malwar... If the Author of the bleepingcomputer.com article has misunderstood your findings and conclusions and is reporting as yours something you didn't recommend, you should let him know and ask for a correction.
- mjg59 10y ago> I can say that the Tesla app should avoid storing the OAuth token in cleartext. Why? What additional security would encrypting it with a key that's on the same device give you?