logoalt Hacker News

mystralineyesterday at 11:41 PM10 repliesview on HN

Repeat after me:

An owner voluntarily downgrading firmware to gain control of your hardware IS NOT A HACK.

And if an adversary is doing this, then they have already breached yoir physical security.


Replies

_fluxtoday at 6:29 AM

It clearly seems people have different meanings to the word, then.

For example, if I am able to gain root access to a WiFi access point I own, even though the vendor has tried to prevent it, then yes, I would call it a hack. To me, it doesn't matter why or who is doing the steps.

In fact, I believe I have never before heard someone combine the meaning of the word to be related to the ownership of the device being hacked.

I suspect the number of people understanding the word in your way is a minority. Redefining terms doesn't help build mutual understanding: here we are taking a word some think has negative connotations and then remove the thing they think should be cool and ok, and then suggest that this is actually the real meaning of the word. Personally I don't think this is how words should be wielded.

show 1 reply
wolrahtoday at 5:03 AM

This exploit is delivered through the charging cable to the wall box. These wall boxes are sometimes intentionally located in public spaces with the intent of allowing public charging, and Tesla has features specifically for that use case, so that cable is absolutely expected to be plugged in to untrusted vehicles.

abofhtoday at 2:54 AM

It's a car the charging port is a viable physical perimeter, letting people inject code at the pump is a risk of design, not user error.

zelon88today at 4:44 AM

I thought the same thing. How white hat do you have to be to consider ineffective DRM a vulnerability?

kube-systemtoday at 12:11 AM

Eh, that’s a bad generalization. defense in depth is a thing and there are many cases where you’d want to protect against attackers with physical access

show 1 reply
pramtoday at 2:00 AM

They shouldn’t be able to do it through the charging cable though lol

taneqtoday at 12:14 AM

Arguably it’s a crack. A good one, though.

aussieguy1234today at 3:02 AM

I mean its still technically hacking, but not all hacking is bad/illegal.