Tesla hacked again, 24 more zero-days exploited at Pwn2Own Tokyo

return2ozma@lemmy.world to Technology@lemmy.world – 342 points –
bleepingcomputer.com
12

I love that one of the prizes for hacking a Tesla is a Tesla. Like here’s one of the privacy nightmares on wheels that you’ve just demonstrated is full of holes. Enjoy!

Free testing device to find more holes to get more testing devices … Profit

I mean, I'd take a free Tesla I'd loot it for parts but I'd take it

Just to be very clear: Tesla is not as special. A lot of modern cars are incredibly susceptible to being pwned because "car companies" repeatedly demonstrate that they are car companies and not tech companies because they keep making rookie errors when it comes to security.

Car companies out source to 3rd parties for their car apps. And these 3rd parties just pump things out on aggressive deadlines. A couple former coworkers work(ed?) at one.

Edit - although, given the amount of in house tech at tesla, I'd expect them to mostly do their own software

If people could see how absolutely shit pretty much every car manufacturers’ software and APIs are they would understand it’s foolish to trust them

I work with pretty much all of them and they’re all trash

It's funny to me that every 100 dollar tablet is better than any in car display i have ever seen.

Shit on Tesla all you want, but the new ones come with a Ryzen processor. Beats any 100 dollar, and any 300 dollar tablet.

repeatedly demonstrate that they are car companies and not tech companies because they keep making rookie errors when it comes to security.

Not that "real" tech companies have a better record when speaking about IT security, tbh...

Throughout the second day, competitors demoed 24 unique bugs and earned $382,500, totaling 48 zero-days and $1,101,500 since the start of the competition.

really having a field day

Alternative title: Tesla will now be patched against several vulnerabilities unlike other brands that don't take part in such bug bounties.