George Reese, a Senior Distinguished Engineer and Executive Director of Cloud Computing at Dell, says the authentication system in the Tesla Model S car`s API has a vulnerability that hackers could use to remotely control some functions of the car.
Drivers of Tesla electronic car can remotely trigger some actions in their car if they log into https://portal.vn.teslamotors.com/vehicles and register on the portal.
With a dedicated API, Tesla drivers can check from a distance the battery charge, access the climate control or the panoramic sunroof, localize the car, honk the horn or open the charge port.
In his blog post, Reese argues that the authentication system have some flaws:
Logging into that account requires a token that is valid for three months. Anyone that can log in can remotely access some functions of a car. Given the restricted number of actions someone can do via this API, it is clear that no unauthorized person can take complete control over the car or cause an accident.
The damage is rather linked to the economic side. “I can target a site that provides value-added services to Tesla owners and force them to use a lot more electricity than is necessary and shorten their battery lives dramatically. I can also honk their horns, flash their lights, and open and close the sunroof. While none of this is catastrophic, it can certainly be surprising and distracting while someone is driving.”
tags
A blend of product manager and journalist with a pinch of e-threat analysis, Loredana writes mostly about malware and spam. She believes that most errors happen between the keyboard and the chair.
View all postsNovember 14, 2024
September 06, 2024