DEF CON 23 - Marc Rogers and Kevin Mahaffey - How to Hack a Tesla Model S

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 ต.ค. 2024
  • The Tesla Model S is the most connected car in the world. It might surprise you to hear that it is also one of the most secure. In this talk we will walk you through the architecture of a Tesla Model S noting things that Tesla got right as well as identifying those that they got wrong. From this talk you will get an intimate understanding of how the many interconnected systems in a Tesla model S work and most importantly how they can be hacked. You will also get a good understanding of the data that this connected car collects and what Tesla does with this telemetry. We will also be releasing a tool that will enable Tesla Model S owners to view and analyse that telemetry in real time. Finally we will also be releasing several 0day vulnerabilities that will allow you to hack a Tesla Model S yourself - both locally and remotely. Note - only one of the 6 vulnerabilities we will discuss and release has been fixed. Disclaimer: With great access comes great responsibility - In other words we are not responsible for any Tesla Model S bricked by over enthusiastic attendees of this talk :)
    Speaker Bios:
    Marc Rogers aka Cyberjunky has been a prominent member of the hacking scene since the 80’s. Some of his most notable achievements are co-founding the notorious British hacker group, “The Agents of a Hostile Power” and his role in creating and appearing in the award winning BBC TV series “The Real Hustle”. Marc’s professional career spans more than twenty years, including a decade managing security for the UK operator Vodafone. Marc is currently the principal security researcher for web optimization and security company “CloudFlare. As well as his work in the infosec and telecoms industries, Marc has also been a CISO in South Korea and co-founder of a disruptive Bay Area start-up. Some of Marc’s notable recent hacks include Google Glass, Apple TouchID and most recently the Tesla Model S.
    Kevin is an entrepreneur and technologist with a background in mobile and web technology, security, and privacy. He is the CTO of Lookout, a company dedicated making the world a safer place as it becomes more connected, starting with smartphones and tablets. He co-founded Lookout in 2007 and is responsible for driving Lookout’s technology to protect people from current and future threats while keeping the product simple and easy to use. He started building software when he was 8 years old and it has been a love affair ever since. Kevin is a frequent speaker on security, privacy, mobile, and other topics.

ความคิดเห็น • 62

  • @inthefade
    @inthefade 8 ปีที่แล้ว +76

    It's cool to see a Defcon talk about a company using pretty good security practices.

    • @crimpers5543
      @crimpers5543 ปีที่แล้ว

      boring

    • @426F6F
      @426F6F ปีที่แล้ว +1

      not boring! I agree

  • @giygas73
    @giygas73 8 ปีที่แล้ว +56

    the beeping sound trolled me so hard in the beginning lol

  • @ryanharrison1472
    @ryanharrison1472 4 ปีที่แล้ว +3

    i watched this whole video and i have no idea whats happening but this is still so cool

  • @Fnargl99
    @Fnargl99 8 ปีที่แล้ว +91

    ok they explain that sound a minute in

    • @tarky_tark
      @tarky_tark 8 ปีที่แล้ว +2

      haha, was wondering the same thing

    • @AviPars
      @AviPars 8 ปีที่แล้ว

      mrebus what is it

    • @LemonChieff
      @LemonChieff 8 ปีที่แล้ว

      shit I started looking for my phone.

  • @theitalian94
    @theitalian94 8 ปีที่แล้ว +4

    Very interesting I really liked it how they explained everything! Good job! :)

  • @HemanshuNarsana
    @HemanshuNarsana 8 ปีที่แล้ว +9

    LOL for a minute there I thought Tesla hired Captain America (Chris Evans the actor) as their new head of security :D

  • @definesigint2823
    @definesigint2823 5 ปีที่แล้ว +2

    Really impressed by the talk, by what Tesla's done right and got some good laughs out of this too--thanks :)

  • @geraldellis1177
    @geraldellis1177 7 ปีที่แล้ว +1

    brand new defcon nerd here

  • @101m4n
    @101m4n 7 ปีที่แล้ว +6

    Say what you will about elon musk, he's nuts for trying to build a city on mars, he's a terrible speaker etc, but the man really knows how to set up companies that get shit done.

    • @jamescox2894
      @jamescox2894 ปีที่แล้ว

      He does know what a run-on sentence is. Can we get more commas please?

  • @Zextraterrestrial
    @Zextraterrestrial 8 ปีที่แล้ว +12

    ni....hahaha, great easter egg!

  • @olivierlasne2346
    @olivierlasne2346 ปีที่แล้ว

    awesome talk

  • @EsquireR
    @EsquireR 7 ปีที่แล้ว

    amazing talk, wonder what could another team find now

  • @jamescox2894
    @jamescox2894 ปีที่แล้ว

    🤔yawn, I would have been impressed if you would have made mcu1's browser work properly.

  • @anthonygato407
    @anthonygato407 6 ปีที่แล้ว +3

    can that beep be more awsome????

  • @samuelseidel6148
    @samuelseidel6148 7 ปีที่แล้ว +1

    Can we please not encrypt the internals.

  • @oscara8746
    @oscara8746 5 ปีที่แล้ว +1

    Captain America was hired for tesla lol

  • @tomassavenas1266
    @tomassavenas1266 5 ปีที่แล้ว

    Marc Rogers holds a mic like Carlos Matos from Bitcoinnect :)

  • @Groaznic
    @Groaznic 8 ปีที่แล้ว +46

    Plain text "tesla1" password? Somebody is going to look for a job at Apple now ;)

    • @griffd2004
      @griffd2004 8 ปีที่แล้ว +20

      +Groaznic To be clear, the password is not tesla1. That's the account name. But maybe you knew that.

  • @JanBabiuchHall
    @JanBabiuchHall 7 ปีที่แล้ว +3

    27:36

  • @p5eudo883
    @p5eudo883 7 ปีที่แล้ว

    I'm interested in writing a tool which scans for files of these types. Any chance someone has a more extensive list of filetypes which contain remote tracking data like those in the video?

  • @DantalionNl
    @DantalionNl 8 ปีที่แล้ว +6

    This car is a security tank on wheels.

  • @franciscorubincapalbo3794
    @franciscorubincapalbo3794 7 ปีที่แล้ว

    Anybody knows what's the website he shows at minute 14:44?

  • @notonclase6750
    @notonclase6750 3 ปีที่แล้ว

    Does this remind anyone of....Watch Dogs?

  • @enciassangrantes3684
    @enciassangrantes3684 5 ปีที่แล้ว

    What's the game in the minute 3:49?

    • @gbrandt
      @gbrandt 5 ปีที่แล้ว

      lemmings

    • @StevesMagic
      @StevesMagic ปีที่แล้ว

      Lemmings, the guy literally says it

  • @applepro7677
    @applepro7677 8 ปีที่แล้ว +4

    Why hackers use OS X not Windows? Enlighten me.

    • @Gigahawk515
      @Gigahawk515 8 ปีที่แล้ว +16

      +Apple Pro presumably because OS X is based on Unix?
      Edit: I'm pretty sure theyre usin some version of linux (probably just a terminal emulator on android)

    • @andkahn9507
      @andkahn9507 8 ปีที่แล้ว +7

      +Apple Pro they use ubuntu or something similar if im not mistaken

    • @badatcad
      @badatcad 8 ปีที่แล้ว +3

      +christian stevens they use kali linux look it up :D

    • @andkahn9507
      @andkahn9507 8 ปีที่แล้ว +2

      Oskar Martin they don't only use kali for this kind of stuff and ubuntu and kali are not that different at all they are both based on debian

    • @batuhangenc2021
      @batuhangenc2021 8 ปีที่แล้ว +3

      +Apple Pro You can install almost any os on mac, but you can't install osx on windows at least easily

  • @fylgdahermetics4763
    @fylgdahermetics4763 5 ปีที่แล้ว

    They will give you a model 3 if you hack it!

  • @FdtTmOJHKPXQFMMkhIE
    @FdtTmOJHKPXQFMMkhIE 8 ปีที่แล้ว

    I hate it when stuff has to patch every other day. I hope that doesn't happen with cars.

    • @flamingcat5135
      @flamingcat5135 7 ปีที่แล้ว +2

      FdtTm4OJH3KPXQF 047M7629Mk41hIE The Tesla's only get patches when connected to wifi, and typically do it at night

    • @davidthacher1397
      @davidthacher1397 4 ปีที่แล้ว

      Tesla is really premature in many ways. Tesla conceptually has stretched beyond the market carrying capacity. Now way in the future will they all be EV. The grid cannot handle this, and they were supposed to ease into something else like Hydrogen which is more sustainable. Smart grid and auto updates create massive at scale issues with the newer versions of that story. Once very early on this could have worked but where we are now this will not work. Certain groups live to ruin plans and ideas.
      I hear Tesla's drive system is decent along with build quality. Built mostly in CAD and has advanced robotic assembly. Which is good, however most of that has been trashed by the all EV model. The going to Mars is now a fricking joke. Along with many other things.
      I do not expect Tesla to survive. I expect them to be taken to pieces for batteries, manufacturing, and drive system designs. I expect their software, automation, etc. to be tossed completely.

  • @your_boy_lamine
    @your_boy_lamine 5 ปีที่แล้ว

    46:16

  • @ravon1982
    @ravon1982 4 ปีที่แล้ว

    so elon isn't as smart as we all thought then.

    • @jamescox2894
      @jamescox2894 ปีที่แล้ว

      We all know from your comment he's got you beat.

  • @FennecTECH
    @FennecTECH 7 ปีที่แล้ว

    dir works in linux

  • @christophermccann1218
    @christophermccann1218 2 ปีที่แล้ว

    "GIF" is pronounced "jif".

  • @SeverityOne
    @SeverityOne 7 ปีที่แล้ว +1

    "Um" is not a very good way to start a sentence - let alone, *every* sentence. Still, interesting presentation.