13 ms·
Pwn2Own Vancouver 2019: Tesla, VMWare, Microsoft, and more
- rhexs 8y agoNice marketing stunt, but how many security researchers already have a Model 3 or are going to buy one to do this? Guessing just already-successful firms / personalities that want to win Tesla pen-testing contracts in the future? Or has Tesla released binary blobs of their firmware systems online?
- superobserver 8y agoGiven enough time, we may find out. Does Pwn2Own have any stipulations against 'gaming' their events?
- Canada 8y agoExploits are already developed prior to the event. It's not a CTF where one can reasonably be expected to find and develop an exploit during the contest. Players get limited time to tweak what they've got in case it doesn't work, but that's it.
- deleted 8y ago[deleted]
- superobserver 8y agoWell, my understanding is that there's a submission then various teams are apprised and given x hours to complete, where x would obviously be greater than twenty-four, and not necessarily handled in one setting, such that there'd be a 'reveal' disclosing successful contestants. So it looks like I wasn't mistaken there. But that still does not address the matter of rigging and whether Pwn2Own has clear rules against it. I don't know, which is why I asked.
- Canada 8y agoNot really, it works like this: Prior to the "contest" beginning everyone participating has to disclose what they have 0day for. In cases where more than 1 person brings 0day for a particular target then they will attack it in turn. The order they get to go in is random. When it's someone's turn they get like 5 minutes to exploit the target. If they can't do it then it's the next person's turn. Whoever exploits it first wins. So if you have 2 people each with a reliable exploit for the same vuln in the same target then who wins is really decided by the coin toss. But let's not forget what this really is: vulnerability sales. So if there's 2 different vulns in the same target then probably the sponsor is going to want to buy them both anyway. What is it that you mean by rigging? The main point of the event is that sellers feel safe exposing their warez. The rules are clear, they're going to get paid if they have what they say that have. The sponsors get to buy the 0day and know it's real and they're not getting ripped off. And it's all in the open and everyone gets good press.
- wil421 8y agoThis will be interesting. A Jeep Cherokee was hacked a couple years ago. The results are pretty bad. It cost Chrysler a lot of money in recalls to fix the issue.[1] [1]https://www.wired.com/2016/08/jeep-hackers-return-high-speed-steering-acceleration-hacks/ https://www.wired.com/2016/08/jeep-hackers-return-high-speed...
- joezydeco 8y agoSeems like Tesla could fix security holes remotely. Chrysler could not.
- rootusrootus 8y agoThe ability to remotely patch a car seems like a double edged sword. Hasn't Tesla already had at least one example of introducing a bug through OTA updates?
- HeyLaughingBoy 8y agoI consider that an issue with the software quality, not with the update mechanism. The bug would still have been introduced even if it required a trip to the dealer to plug in a programming cable.
- falcolas 8y agoAt least, when it's updated by a dealer and a cable, you know when to expect changed behavior. With OTA, the vehicle's driving behavior could (and has) quite literally change overnight.
- HALtheWise 8y agoI'm pretty sure you still need manual confirmation in the car, and it shows you patch notes when you next get in, so you should have reason to expect changed behavior.
- 8y ago
- bunkydoo 8y agoStep 1. wait until the owner is nearby Step 2. equip ski mask & rubber gloves Step 3. sneak up and pull a knife or gun and demand the car fob Boom, enjoy your 'hacked' model 3
- swarnie_ 8y ago> And the first successful researcher can also drive off in their own brand new Model 3 after the competition ends If you've successfully hacked a car and shared your method would you then get in said car and drive it away? I'd like a patch or at least a factory reset first....
- Canada 8y agoWhoever pwns the Telsa probably doesn't even live in Vancouver, so no, they're not going to drive off in the target vehicle. Telsa would have to arrange to provide one where they live, and yeah, I think it's safe to say that one would already be patched!
- mcv 8y agoWhat prize do you get for pwning it sufficiently to make it drive off on its own? Sounds like that would be the ultimate hacking competition: you get the car if you make it drive to your own home.
- danpalmer 8y agoFrom what I've read about Tesla's software this could be a bold move. Between the infotainment system, onboard Linux computer, autopilot, self-driving hardware, OTA updates, mobile apps, and the amount they phone home, Tesla are probably doing some of the most advanced computing in any consumer car (some deconstructions have suggested they are miles ahead here, pardon the pun). This is great, but it all comes with additional surface area for attacks, and software engineers have spoken out about the fast paced shipping that happens at Tesla and the corners that are cut as a result.
- astrodust 8y agoThere's no doubt someone's getting a free car.
- sametmax 8y agoThat's the goal isn't it ? Finding critical flaws in a super complex system you built for years and sell to the entire world. For just the price of a car. Or, miracle occurs, nobody finds anything and you get some killer PR. That's a very good deal.
- LeifCarrotson 8y agoYou don't think they could ask their own salaried engineers and get a nice long list of secured-by-obscurity vulnerabilities?
- sametmax 8y agoWe are talking about a company that made electrical vehicules economically realistic in a oil-addidcted world. I think it's safe to think they have considered that already :) Would you say it's unlikely they just maxed out what they can do internally and want new eyes to work on it ?
- Someone1234 8y ago
- anonymfus 8y ago> Entries against “Key Fobs or Phone-as-Key” target must achieve code execution, arbitrary vehicle unlock, or arbitrary vehicle start using protocol-related weaknesses. Entries related to Key Fob relay or “rolljam” attacks are not allowed Does that mean that they think that such attacks are too easy? If they use rolling codes, will they classify any attack with jamming as "rolljam"? If they don't, why specify this?
- glitchc 8y agoWas just at RWC 2019. The Tesla Model S keyfob has been successfully hacked. Here are the slides for the same talk (CHES 2018): https://ches.iacr.org/2018/slides/ches2018-rump-talk14-slides.pdf https://ches.iacr.org/2018/slides/ches2018-rump-talk14-slide...
- termie 8y agoThis is from mid 2017. "First notified Tesla on 31/08/2017 .. Tesla vehicles produced from June onwards use a new key fob". Not sure if the new fob is significantly better as the presentation is not clear there.
- opencl 8y agoAnd the "fix" for people who bought the car before then was adding an option to disable the automatic unlock (so you have to press a button) and/or require entering a PIN to actually drive the car.
- tachang 8y agoThis is some seriously good marketing. Tesla is in a unique position to offer their car up as a prize and target. Other manufacturers could do this but because it is hard to update their firmware they don't do it.
- devy 8y agoRegardless, how good/bad Tesla software will fair with the security contest, this is the best possible way to improve product security within a short amount of time, just like the cat-and-mouse game Apple play with the Jailbreaking community.
- anonymfus 8y ago> just like the cat-and-mouse game Apple play with the Jailbreaking community. That cat-and-mouse game discourages people from reporting vulnerabilities. Why you think that it improves security?
- amelius 8y agoDo you get physical access to the inside of the car first? Or does the hacking have to happen from the outside of the car?
- deleted 8y ago[deleted]
- InTheArena 8y agoAs a Tesla owner, I think this is great, because as an Engineer, I fully expect that Tesla was get owned (literally) here. I have no problem with that - I want people trying to break the security, and I want Tesla to pay them, and to improve it. The reality is that a Tesla is mostly really good software, really good engine, and really good battery, surrounded by a reasonable (but not excellent) rest of the car. That's more then worth it to me, and the Tesla Stretch is real, because the car is incredibly compelling. I would argue that the value is just as much a outcome of the software, and it needs to be hardened.
- dsfyu404ed 8y agoUndergrads at various universities regularly pwn vehicle systems and write reports about it for academic credit. The M3 has a lot more surface area than the typical car most people are hacking. My prediction is that the M3 is gonna get chewed up and spit out. This isn't a "will it get pwned" competition it's a "who will pwn it best/fastest" competition.
- virtualmemory 8y agoAnyway they have bitquark for security. Who can find vulnerability in the Tesla products ?
- darkhorn 8y agoIt looks like Tesla doesn't update many parts of its OS; https://www.reddit.com/r/teslamotors/comments/ag6r2f/please_help_our_turkish_tesla_community_reach/ https://www.reddit.com/r/teslamotors/comments/ag6r2f/please_...
- r00fus 8y agoThis is a great contest. The value of winning a Tesla will be more than the value of the Model3 up for grabs. And it's relatively cheap for Tesla to pay out to get these vulnerabilities found and addressed.
- foothrow0987 8y agoI’m sorry, are you for real? “Rofl no. I can literally drive my car from my phone via root access into the CID. Hell, the gateway that communicates to all the car's ECUs has the static password of 1q3e5t7u for all teslas.”
- auiya 8y agoIf my understanding of the pwn2own event is correct, it's not a CTF event and the exploits are typically developed in advance, and then demonstrated during the event? If there are 2 or more exploits which all work reliably, who is determined to be the "winner"?
- anotheryou 8y agoI found the tesla rules: you need to exploit as many systems as possible as hard as possible: https://static1.squarespace.com/static/5894c269e4fcb5e65a1ed623/t/5c36468c1ae6cfc9ce0a7a9f/1547060891346/01-Tesla_Table.png?format=750w https://static1.squarespace.com/static/5894c269e4fcb5e65a1ed... via https://www.zerodayinitiative.com/blog/2019/1/14/pwn2own-vancouver-2019-tesla-vmware-microsoft-and-more https://www.zerodayinitiative.com/blog/2019/1/14/pwn2own-van...
- jaybosamiya 8y agoAs per the full contest rules (https://www.zerodayinitiative.com/Pwn2Own2019Rules.html https://www.zerodayinitiative.com/Pwn2Own2019Rules.html): > If more than one contestant registers for a given category, the order of the contestants will be drawn at random. Based on the contestant order, the first contestant will be given an opportunity to attempt to compromise the selected target. If unsuccessful, the next randomly drawn contestant will be given an opportunity. This will continue until a contestant successfully compromises the target. The first contestant to successfully compromise a selected target will win the prize money for that target in that category. After a target has been compromised, the contest for that category is over and no other contestants will participate in the contest for that category (unless Sponsor has offered an additional winner option, which would be announced at the conference if applicable).
- anotheryou 8y agoI give it 67 seconds edit: there is nothing stopping someone from leasing a tesla, finding an exploit and shooting it within the first 10 seconds, no? In general, how does this work at pwn2own?