3 ms·
The interesting part is this implies that Tesla cars have static certifcates that don't rotate. (Whoops.)
by otabdeveloper4 6mo ago
The interesting part is this implies that Tesla cars have static certifcates that don't rotate. (Whoops.)
- worthless-trash 6mo agoWhy can't they rotate ? having root ssh keys on the device doesn't imply the certs don't rotate.
- bdavbdav 6mo agoNot necessarily. All they have to do is roll a pub key into the update package. Same as any OTA update.
- dotancohen 6mo agoDo Tesla vehicles get VIN-specific updates?
- bdavbdav 6mo agoNot sure - if I was designing it, feels like it would be a good way of getting the right build to the right car so that all the HW versions of each module are in line.
- dotancohen 6mo agoI'd imagine that the update includes all the possible hardware, and the update script actually decides which components to use. Like apt on Debian or yum on RHEL.
- bdavbdav 6mo agoInteresting - just found this: https://www.pentestpartners.com/security-blog/reverse-engineering-the-tesla-firmware-update-process/ https://www.pentestpartners.com/security-blog/reverse-engine... Not had a chance to read it properly but definitely will be!
- dotancohen 6mo agoThat was an amazing read, thank you! It appears that the Tesla is running a full Ubuntu Linux distro. And here's a small quip to entice passers-by to read more: > With names ranging from “INDIFFERENT” to “SUICIDE_BOMBER”, there is a list of escalation strategies in the updater binary, which appear to be strategies for retries of downloads and user prompts on the UI.
- jon-wood 6mo agoMy read of the output in the post when they tried to SSH to the device was that Tesla are actually doing the right thing here and using an SSH certificate authority, which allows issuing certificates signed with a private key authorising access to a subset of devices (optionally for a defined period of time). https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Certificate-based_Authentication https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Certificate-b... has more information, but in summary unless the private signing key is compromised in some way this is entirely legit. I'd hope that they also have some mechanism for distributing a new public key if the signing key does get compromised but who knows.
- everfrustrated 6mo agoI understand there are also certs involved with tesla vehicles communicating with a supercharger as well.