Hackers from TU Berlin managed to jailbreak #Tesla cars, unlocking software-locked features worth up to $15,000 🪓🪓🪓

They used a known (unpatchable) voltage fault injection attack against the AMD Secure Processor to glitch the boot process, got root, and retrieved the car's RSA private key 👌

https://electrek.co/2023/08/03/hackers-manage-unlock-tesla-software-locked-features/

Hackers manage to unlock Tesla software-locked features worth up to $15,000

A group of hackers have exposed an exploit that can unlock Tesla’s software-locked features worth up to $15,000. Free heated...

Electrek

@jomo An unpatchable fault in the Secure Processor.

Oh, the irony 😄

@ChampersBE @jomo Also X86 type CPU and secure from physical attacks choose one.
@jomo i wonder if this would have qualified for pwn2own this year 🤔 But I guess for a key glitching was out-of-scope

@jomo

Mit Root-Rechten und dem RSA-Schlüssel sind natürlich auch andere Dinge möglich. Etwa das Betriebssystem durch Linux ersetzen oder das Auto fernzusteuern.

Mein Favorit: 8 weisse Tesla Y und 8 schwarze Tesla Y (die Bauern) und 8 helle Tesla S, 3 und X und 8 dunkle Tesla S, 3 und X (König, Dame, Springer, Läufer und Turm) in die Quadratestadt Mannheim schicken und eine Partie Strassenschach spielen. Mir fehlt nur ein Gegner der genauso schlecht Schach spielt wie ich (also nicht Ron Weasley).

@HonkHase
@privacyDE
@SheDrivesMobility
@BlumeEvolution

@Life_is @jomo @HonkHase @privacyDE @SheDrivesMobility @BlumeEvolution in Mannheim-Friedrichsfeld ist auch ein Servicecenter. Also die Anzahl Fahrzeuge wäre evtl schon bereit ;)
Eher die Frage wo man in den gar nicht so quadratischen Quadraten ein gescheites 8x8 Feld definieren kann 🤔
@jomo
Cool. Can I run my Tesla with Linux then?? 🐧
@jomo "Voltage fault injection attack" sounds like something that should involve jumper cables...
@jomo fuck thoses computers on wheels, well done guys you did the right thing, hardware enabled by software should not be legal.

@jomo

My first thought was to wonder how many more steps it would take from unlocking FSD to pwning the vehicle remotely. If not this, then it's just a matter of time before someone figures that one out.

@Mikal I see northing morally wrong here just customers getting what they paid for.
@Luna
What's morally wrong is companies being able to deny you what you already paid for. But my bigger worry about these things is the ability of threat actors to take control of these cars for malicious purposes.
@jomo If paying for it doesn't mean ownership, then stealing it isn't theft.
@jomo Great. I hated the idea of buying a car and having to pay more to unlock features anyway.
Injury Reserve - Jailbreak the Tesla (Feat. Aminé)

YouTube
@joelhanlon @jomo @billt interesting story for the notpod

@jomo This looks like a clickbait, the article contradicts the headline:

This includes features like heated seats, acceleration boost, and even Tesla’s Full Self-Driving package, which costs $15,000

Ultimately, the hackers believe that they can unlock virtually all software-locked features inside Tesla vehicles even Full Self-Driving – though they believe that it would require some more reverse-engineering

Doesn’t seem like they actually unlocked it, they just think that it’s technically possible.

@jomo using voltage-based hacks to jailbreak something called a tesla is especially great
Injury Reserve - Jailbreak the Tesla (Feat. Aminé)

INJURY RESERVE OUT NOW: https://found.ee/InjuryReserve Stream: https://found.ee/IR_JailbreakTheTesla directed by Parker Corey produced by Will Hasty cinematography by Chris Ripley 1st AC by Kyle Frank rigging grip by Joanne Nguyen gaffer by Gregory Loebell grip by Mathias Peralta ronin operator by Andrew Brinkhaus bts filming by Leo Lovely “Jailbreak The Tesla (Feat. Aminé)” a product of Seneca Village/Loma Vista Music video by Injury Reserve performing Jailbreak The Tesla. © 2019 Loma Vista Recordings., Distributed by Concord Music Group, Inc. http://vevo.ly/1FEk6P

InjuryReserveVEVO | Invidious
@jomo Paywalling car features is just wrong.
https://www.youtube.com/watch?v=4quXTwAiMVA
Beetle Good Good

YouTube
@jomo that's worth logging into the fowl site to re-x their x-cellent x-ample

@jomo

Ooop I guess Elon is gonna buy a university now...

@jomo
Well, lets ignore "run arbitrary software on the infotainment” for a moment, most car brands have such creepy features, like GM and BMW for example. To drive around with hardware built into the car, that you just can't use because of a missing software licence is not very economical.
This is just another proof of those so called cars of the future being the childhood dream of a 1980s teenager: a game console with wheels.
Too bad they catch fire more often than your good old Gameboy.
@jomo hell yea! fuck paywalls.

@jomo

😂 😂
👍 👍

@jomo my hope is a jail brake community pops up over this, I'm sure there is a lot of out of warranty teslas on the rd that would love to do this.
@jomo the jail brake was completely just a derp by me but the pun works well!