93
submitted 1 year ago by _Frog@feddit.ch to c/technology@feddit.ch

A group of hackers have exposed an exploit that can unlock Tesla’s software-locked features worth up to $15,000.

Free heated seats and Full Self-Driving package, anyone?

Software-locked features that need to be activated by the owner paying or subscribing to a service are becoming increasingly popular in the auto industry.

Tesla has been on board that trend very early since it produced virtually all its vehicles with the same hardware and owners can unlock features later through software updates.

This includes features like heated seats, acceleration boost, and even Tesla’s Full Self-Driving package, which costs $15,000.

It creates a market for people trying to get around the software lock.

A group of security researchers (aka hackers) at TU Berlin announced that they managed to exploit a weakness in the onboard computer to unlock these features:

Tesla has been known for their advanced and well-integrated car computers, from serving mundane entertainment purposes to fully autonomous driving capabilities. More recently, Tesla has started using this well-established platform to enable in-car purchases, not only for additional connectivity features but even for analog features like faster acceleration or rear heated seats. As a result, hacking the embedded car computer could allow users to unlock these features without paying.

They plan to unveil the result of their exploit in a presentation called “Jailbreaking an Electric Vehicle in 2023 or What It Means to Hotwire Tesla’s x86-Based Seat Heater” next week.

The hack requires physical access to the car, and it involves a “voltage fault injection attack” on the AMD-based infotainment system:

For this, we are using a known voltage fault injection attack against the AMD Secure Processor (ASP), serving as the root of trust for the system. First, we present how we used low-cost, off-the-self hardware to mount the glitching attack to subvert the ASP’s early boot code. We then show how we reverse-engineered the boot flow to gain a root shell on their recovery and production Linux distribution.

The group of hackers claims that their “Tesla Jailbreak” is “unpatchable” and allows to run “arbitrary software on the infotainment.”

top 5 comments
sorted by: hot top controversial new old
[-] Russianranger@lemmy.world 19 points 1 year ago

I don’t think I’ll ever willingly purchase a vehicle with built in subscription services to features already existing in the car. But if I didn’t have a choice, I’d be sure to start looking up ways to bypass it.

The thing that’s alarming is we have this subscription car crap now, which would have been absurd back before 2010 (still is, but even more so then), is that I feel we’re another 20 years from subscription AC cooling in cars. They’ll bypass it by giving access to AC cooling to 82 degrees, but if you want that good cool you’ll need to fork up some dineros

[-] ChihuahuaOfDoom@lemmy.world 9 points 1 year ago* (last edited 1 year ago)

Good for them. I doubt it's truly unpatchable though.

Edit: thank you for the replies, I clearly made an uneducated guess.

[-] 2pt_perversion@lemmy.world 11 points 1 year ago

Eh, when you're glitching hardware preboot and attacking root-of-trust it's very possibly unpatchable. Just ask Nintendo.

[-] Virkkunen@kbin.social 8 points 1 year ago* (last edited 1 year ago)

The patch probably involves changing the exploitable hardware to a non exploitable one, and you can't do that with software updates

[-] Ret2libsanity@infosec.pub 5 points 1 year ago

It very well could be.

My guess is they are bypassing some integrity check on signed code by glitching logic in the ASP bootrom. If it’s true then it is very possible there are no fuse banks prepped to patch the bootrom. Which I have seen used to make bootroms patchable.

It’s very hard to protect against glitch attacks. And typically that sort of measure needs to be engineered into the design itself.

load more comments
view more: next ›
this post was submitted on 05 Aug 2023
93 points (100.0% liked)

TeCHnology

6 readers
1 users here now

Technology discussion for Switzerland. This community shall discuss various topics of technology in and around Switzerland.

founded 1 year ago
MODERATORS