Tesla hackers turn to voltage glitching to unlock paywalled features
- Reference: 1691408711
- News link: https://www.theregister.co.uk/2023/08/07/black_hat_tesla_hackers/
- Source link:
In [1]a talk given today, a trio of Technische Universität Berlin boffins demonstrated how they were able to bypass the $300 purchase requirement to activate heated rear seats in a Tesla Model 3 – or at least in the computer from a Tesla Model 3.
Instead of approaching the problem like Tesla hackers of the past, who've tried to gain control of vehicles or [2]break into them as an outsider, Christian Werling and his fellow researchers wanted to approach the problem like someone who already had physical access to a vehicle and was trying to make their own modifications – like breaking through soft locks on optional, but installed, features.
[3]
The researchers' first attempt was simply to try to modify the firmware in the Tesla's computer, but they were rebuffed by the secure boot process – something that Werling told us was a relatively new development in Tesla's computers.
[4]
[5]
Previous versions of Tesla computers were vulnerable to an off-chip boot loader buffer overflow that was fixed via firmware updates. Another buffer overflow issue affecting the ROM on Tesla computers remained, but was fixed when Tesla later upgraded from AMD Zen 1 APUs to Zen 2s.
The problems were even worse before, Werling pointed out – Tesla computers used to have open X servers, hard-coded passwords, and their code wasn't even signed. Now, in 2023, Tesla computers have a boot chain of trust, firmware and OS signing and a root of trust in their AMD SoCs that left the researchers faced with a hard reality: They couldn't get in.
Have you considered shock therapy?
Cast your mind back to 2021 and you may recall a story about a group of researchers who managed to [6]subvert AMD's Secure Encrypted Virtualization by causing a voltage glitch. One of the authors of the paper which uncovered the AMD voltage glitch, Hans Niklas Jacob, was also part of the group of Tesla hackers talking at Black Hat.
Now recall that Tesla uses AMD processors in its vehicles and you may have an idea where this is going.
[7]
By soldering a couple of wires to the infotainment and connectivity ECU, which contains the gateway chip that stores settings for things like software-locked features, the team were able to get the voltage to drop at just the right time to fool the system into thinking that it was being booted securely when that wasn't necessarily the case, allowing them to gain root access to the device and unlock the heated seats.
As an added bonus, they were able to use their newfound access to exfiltrate information about the car and user data stored in the Tesla computer, like location history, Wi-Fi passwords and session cookies for services like Spotify and Gmail.
Call us back when you achieve persistence
"When we called Tesla to share the exploit with them, the first question they had was whether it was persistent," Werling told The Register . "We told them it wasn't, and they haven't responded to us since."
The only way to achieve persistence would be to solder a mod chip to the board itself, Werling said, something Black Hat attendees will likely be all too eager to try on their own – if they don't mind digging into their Tesla's computer to solder on some wires and void their warranty.
Werling also told us that the team hasn't had a chance to try it in an actual Tesla yet, but said that independent security researcher Oleg Drokin, who worked on the project with them, has tried it in an actual Tesla. "I'm pretty sure it worked," Werling told us.
[8]
As to whether the problem could be duplicated in other vehicles with software-locked features, like [9]BMWs , Werling said the team hasn't tried yet, largely because they haven't been able to find a computer from other vehicles with software-locked features.
[10]Tesla steering problems attract regulator eyes for second time this year
[11]The semiconductor biz is sick, but demand for SiC chips that improve EVs is accelerating
[12]Tesla's Dojo supercomputer is a billion-dollar bet to make AI better at driving than humans
[13]First of Tesla's 'bulletproof' Cybertrucks clunks off production line
"I would be astonished if other manufacturers have the same level of protection for their systems," Werling said. He noted that Tesla has become good at defending against attacks to its software after investing time and money in [14]attracting hackers in the past, something he said it's not clear if other automakers have considered.
Still, Tesla clearly wasn't considering a voltage glitch as a way around its protection – something that looks a lot like a failure of supply chain security given voltage-vulnerable AMD chips are at the heart of its computers.
The team who wrote the 2021 AMD voltage glitching paper noted that, where hardware redesigns aren't practical, software could be modified to detect voltage modulation to prevent faults that could trigger an insecure boot. Perhaps Tesla will release a patch at some point.
We'd love to know, but the Musk-owned automaker hasn't answered our questions. ®
Get our [15]Tech Resources
[1] https://www.blackhat.com/us-23/briefings/schedule/#jailbreaking-an-electric-vehicle-in-2023-or-what-it-means-to-hotwire-tesla39s-x86-based-seat-heater-33049'
[2] https://www.theregister.com/2018/09/12/tesla_hack/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/blackhatanddefcon&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNEVKBJCarbLiPg-uksDPQAAAgM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/blackhatanddefcon&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNEVKBJCarbLiPg-uksDPQAAAgM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/blackhatanddefcon&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNEVKBJCarbLiPg-uksDPQAAAgM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/13/amd_secure_encrypted_virtualization/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/blackhatanddefcon&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNEVKBJCarbLiPg-uksDPQAAAgM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/blackhatanddefcon&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNEVKBJCarbLiPg-uksDPQAAAgM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/07/12/bmw_locks_korean_car_owners/
[10] https://www.theregister.com/2023/08/02/tesla_steering_problems/
[11] https://www.theregister.com/2023/08/01/onsemi_silicon_caribide_demand/
[12] https://www.theregister.com/2023/07/21/tesla_dojo_spending/
[13] https://www.theregister.com/2023/07/17/first_tesla_cybertrunk/
[14] https://www.theregister.com/2023/03/27/in_brief_security/
[15] https://whitepapers.theregister.com/
Re: Musk asnwering questions?
They'll just brick the car.
Turn the car on and all that appears on the dash screen is a poo emoji.
Re: Musk asnwering questions?
Or maybe a large scarlet X?
soft locks on optional, but installed, features
Good on them, because this is shit and shouldn't be allowed. If it's installed, it's installed, end of.
Re: soft locks on optional, but installed, features
Soft locks are a high tech equivalent of things that have been going on for decades.
You want cruise control in that Vauxhall? Find one in the scrapyard with it and swap the indicator stalk.
Can't remember the make, but two rear fog lamps will cost serious extra cash - or you can always just fit the missing bulb yourself.
Re: soft locks on optional, but installed, features
Soft locks are a high tech equivalent of things that have been going on for decades.
There's a well known range of oscilloscopes that can be updated to a higher spec by hacking the firmware.
Re: soft locks on optional, but installed, features
I've done that "upgrade" myself, and I can confirm that it works.
It's not even really serious "hacking". All you have to do is open a serial connection, and type a command to tell the scope it's the better model.
Re: soft locks on optional, but installed, features
" and type a command to tell the scope it's the better model "
Shame I can't do that to myself. "You're not a middle aged fart with a bumper and crappy eyesight...".
Re: soft locks on optional, but installed, features
" Soft locks are a high tech equivalent of things that have been going on for decades. "
Oh, I know. I once had a cheap (but modern at the time) video recorder. Opening it up, a massive mostly bare circuit board. The masses of crap inside my old Betamax had, in this device, been shrunk to two or three chips.
There was a rather conspicuous row of holes next to another row of holes. One was linked with a piece of wire. I unsoldered it and fitted a bank of DIP switches.
And fiddled.
And discovered Long Play mode, HiFi audio, a much better pause (used a memory buffer so the picture didn't wobble), and something else (I forget what). All features that would have cost plenty of extra cash... just for a different arrangement of link's inside.
I know it happens. A lot. Doesn't make it any less shit. If they can afford to pack all the features into the cheap model and turn them off, then having them turned on is just fleecing the customer.
Re: soft locks on optional, but installed, features
The only difference between a Garmin GPS-95 (aviation use, could display speeds (100kt) and the GPS-45 (everything else, blanked the display over 100kt) was a single wire link on the circuit board. Oh yes, and the 95 cost five times as much as the 45.
Not persistent, so not a problem
I guess Tesla is right. If the owner has to go through the shenanigans of hacking his own computer every time he wants to start the car, it's quickly going to get old.
The article isn't quite clear on whether other things can be unlocked as well.
Still, spending some time every time you need to leave just to ensure that you have whatever features you didn't pay for but still want is going to quickly run up against the hassle of the wires, the laptop and the time it takes to dally around instead of actually getting where you need to go.
And good on Tesla for hardening their computing platform. "They couldn't get in" is about as good a reward as you can expect in this domain.
Now, if only they could get the autopilot working . . .
Re: Not persistent, so not a problem
Well, it's not a problem for Tesla, but the user is paying $3000 just to be allowed access to a switch. From an environmental point of view, this is totally bonkers. Raw materials and energy go into hardware features that will never be used if the owner of the vehicle doesn't pay for them. What a complete waste....
Re: Not persistent, so not a problem
Additional battery capacity is a software switch too, isn't it? So if you don't pay for that switch, then you have a bunch of battery cells sitting there unused -- adding weight to the vehicle and wasting the (somewhat scarce) resources that were used to manufacture the unused batteries.
Re: Not persistent, so not a problem
" Additional battery capacity is a software switch too, isn't it? "
Hmm, doesn't La Grosse Pomme (*) have all the patents on messing with battery capacity?
* - Hard day at work and I'm all Frenched out and running on autopilot, so I'm just guessing "pomme" is feminine.
Musk asnwering questions?
Nah... They'll just brick the car. That's how they keep their cult in line with the new Messiah.