Connect with us

News

Details Behind the Tesla Model S Hack

Two researchers broke into the software of a Tesla recently. But there is good news behind the Tesla Model S hack. A fix was sent to all cars within days.

Published

on

Tesla Model S hack

Tesla Model S infotainment system also serves as the command center to the vehicle.

Last week, Marc Rogers, of content delivery network CloudFlare, and Lookout Mobile Security co-founder Kevin Mahaffey completed a digital break-in of a Tesla. But here’s the good news behind the Tesla Model S hack. Tesla quickly released an over-the-air firmware update, to every Model S ever manufactured, that would resolve the security holes uncovered by Rogers and Mahaffey.

The Tesla Hack

Rogers and Mahaffey had to dismantle the dashboard to gain access to an ethernet port. From there, they were able to connect directly to the CAN bus, the controller area network across which car data is sent and received.

After that, they chained together four separate vulnerabilities, first to gain access to the infotainment systems and then the touchscreen used to control vehicle functions. That let them make the speedometer disappear, alter the suspension, unlock the doors and the trunk, and make the windows go up and down. They were also able to shut down the car’s electric motor below 5 mph.

Above that speed, the dashboard screens would go blank but the car would shift into neutral, giving the driver time to find a safe place to bring the car to a stop. “Ironically, that means it’s the only car that can protect itself against a successful cyber attack,” Rogers noted.

Tesla’s Response

“Tesla has taken a number of different measures to address the effects of all six vulnerabilities reported by Lookout. And, we continue to develop further ways to harden our systems, informed by ongoing discussions with the security research community, as well as our own internal analysis. The update has been made available to all Model S customers through an OTA update. We will deploy this update to all vehicles by Thursday,” a spokesperson said in a statement e-mailed to Forbes.

Advertisement

Other auto manufacturers are following in Tesla’s footsteps by making internet updates available for their upcoming line of vehicles, but are starting years behind Tesla.

Rogers and Mahaffey say they also found two potential browser vulnerabilities that they exposed but did not exploit. Those flaws, resident in the WebKit browser engine, could possibly have enabled remote attacks, but Tesla’s new firmware update has resolved those issues as well.

Tesla CTO Toasts Hackers

While Rogers and Mahaffey were explaining their hacks at Def Con 23 last Friday, Tesla CTO J. B. Straubel made a surprise appearance to offer them a toast and personally thank them for their work. J.B. presented the duo with “Challenge Coins,” which will Tesla will be giving to any researcher who finds a serious security hole in their vehicles.

As cars acquire more digital capability, the opportunities for outside interference either by "white hat" hackers or those bent on doing actual harm will increase. Tesla, though, has the most robust program for identifying and resolving digital security issues of any manufacturer. That commitment should give every Tesla owner and prospective owner a full measure of confidence in the integrity of Tesla automobiles, now and in the future.

"I write about technology and the coming zero emissions revolution."

Advertisement
Comments

News

Tesla VP explains latest updates in trade secret theft case

Tesla reportedly caught Matthews copying the tech into machines that were sold to competitors, claiming they lied about doing so for three years, and continued to ship it. That is when Tesla chose to sue Matthews in July 2024 in Federal court, demanding over $1 billion in damages due to trade secret theft.

Published

on

tesla 4680
Credit: Tesla Inc.

Tesla Vice President Bonne Eggleston explained the latest updates in a trade secret theft case the company has against a former manufacturing equipment supplier, Matthews International.

Back in 2024, Tesla had filed a lawsuit against Matthews International, alleging that the firm stole trade secrets about battery manufacturing and shared those details with some of Tesla’s competitors.

Early last year, a U.S. District Court Judge denied Tesla’s request to block Matthews International from selling its dry battery electrode (DBE) technology across the world. The judge, Edward Davila, said that the patent for the tech was due to Matthews’ “extensive research and development.”

Tesla is suing a former supplier for trade secret theft

Advertisement

The two companies’ relationship began back in 2019, as Tesla hired Matthews to help build the equipment for its 4680 battery cell. Tesla shared confidential software, designs, and know-how under strict secrecy rules.

Fast forward a few years, and Tesla reportedly caught Matthews copying the tech into machines that were sold to competitors, claiming they lied about doing so for three years, and continued to ship it. That is when Tesla chose to sue Matthews in July 2024 in Federal court, demanding over $1 billion in damages due to trade secret theft.

Now, the latest twist, as this month, a Judge issued a permanent injunction—a court order banning Matthews from using certain stolen Tesla parts or designs in their machines. Matthews is also officially “liable” for damages. The exact amount would still to be calculated later.

Bonne Eggleston, a VP for Tesla, said on X today that Matthews is a supplier who “exploited customer IP through theft or deception,” and has no place in Tesla’s ecosystem:

Advertisement

Tesla calls this a big win and warns other companies: “Buyer beware—don’t buy from thieves.”

Advertisement

Matthews hit back with a press release claiming victory. They say an arbitrator ruled they can keep selling their own DBE equipment to anyone and rejected Tesla’s request for a total sales ban. They call Tesla’s claims “nonsense” and insist their 20-year-old tech is independent. Both sides are spinning the same narrow ruling: Matthews can sell their version, but they’re blocked from using Tesla’s specific secrets.

What are Tesla’s Current Legal Options

The case isn’t over—it’s moving to the damages phase. Tesla can:

  • Push forward in court or arbitration to calculate and collect huge financial penalties (potentially $1 billion+ if willful theft is proven).
  • Enforce the permanent injunction with contempt charges, fines, or even jail time if Matthews violates it.
  • Challenge Matthews’ new patents that allegedly copy Tesla’s work, asking courts to invalidate them or add Tesla as co-inventor.
  • Seek extra damages, lawyer fees, and possibly punitive awards under the federal Defend Trade Secrets Act and California law.

Tesla could also refer evidence to federal prosecutors for possible criminal trade-secret charges (rare but serious). Settlement is always possible, but Tesla’s fiery public response suggests they want full accountability.

This isn’t just corporate drama. It shows why trade secrets matter even when Tesla open-sources some patents, confidential know-how shared in trust must stay protected. For the EV industry, it’s a reminder: steal from your biggest customer, and you risk losing everything.

Advertisement
Continue Reading

News

Tesla Cybercab includes this small but significant feature

The Cybercab is Tesla’s big plan to introduce fully autonomous ride-sharing in a seamless fashion. In fact, the Full Self-Driving suite was geared toward alleviating the need to manually drive vehicles.

Published

on

Credit: Tesla

Tesla Cybercab manufacturing is strikingly close, as the company is still aiming for an April start date. But small and significant features are still being identified for the first time as production units appear all over the country for testing and for regulatory events, like one yesterday in Washington, D.C.

The Cybercab is Tesla’s big plan to introduce fully autonomous ride-sharing in a seamless fashion. In fact, the Full Self-Driving suite was geared toward alleviating the need to manually drive vehicles.

This was for everyone, including the disabled, who are widely reliant on ride-sharing platforms, family members, and medical shuttles for transportation of any kind. Cybercab aims to change that, and Tesla evidently put a focus on those riders while developing the vehicle, evident in a small but significant feature revealed during its appearance in the Nation’s Capital.

Tesla Cybercab display highlights interior wizardry in the small two-seater

Advertisement

Tesla has implemented Braille within the Cybercab to make it easier for blind passengers to utilize the vehicle. On both the ‘Stop/Hazard Lights’ button and the Door Releases, Tesla has placed Braille so that blind passengers can navigate their way through the vehicle:

This is a great addition to the Cybercab, especially as Full Self-Driving has been partially pointed at as a solution for those with disabilities that would keep them from driving themselves from place to place.

It truly is a great addition and just another way that Tesla is showing they are making this massive product inclusive for everyone out there, including those who have not been able to drive due to not having vision.

The Cybercab is set to enter mass production sometime in April, and it will be responsible for launching Tesla’s massive plans for an autonomous ride-sharing program.

Advertisement
Continue Reading

Elon Musk

Tesla and xAI team up on massive new project

It is the latest move by a Musk company to automate, streamline, and reduce the manual, monotonous, and tedious work currently performed by humans through AI and robotics development. Digital Optimus will be capable of processing and actioning the past five seconds of a real-time computer screen video and keyboard and mouse actions.

Published

on

Credit: Grok

Elon Musk teased a massive new project, to be developed jointly by Tesla and xAI, called “Digital Optimus” or “Macrohard,” the first development under Tesla’s investment agreement with xAI.

Musk announced on X that Digital Optimus will “be capable of emulating the function of entire companies.”

It is the latest move by a Musk company to automate, streamline, and reduce the manual, monotonous, and tedious work currently performed by humans through AI and robotics development. Digital Optimus will be capable of processing and actioning the past five seconds of a real-time computer screen video and keyboard and mouse actions.

Essentially, it will be an AI version of a desk worker in many capacities, including accounting, HR tasks, and others.

Musk said:

Advertisement

“Grok is the master conductor/navigator with deep understanding of the world to direct digital Optimus, which is processing and actioning the past 5 secs of real-time computer screen video and keyboard/mouse actions. Grok is like a much more advanced and sophisticated version of turn-by-turn navigation software. You can think of it as Digital Optimus AI being System 1 (instinctive part of the mind) and Grok being System 2. (thinking part of the mind).”

Its key applications would be used for enterprise automation, simulating entire companies, high-volume repetitive tasks, and potentially, future hybrid use with the Optimus robot, which would handle physical tasks, while Digital Optimus would handle the clerical work.

Tesla announces massive investment into xAI

The creation of a digital AI suite like Digital Optimus would help companies save time and money, as well as become more efficient in their operations through massive scalability. However, there will undoubtedly be concerns from people who are skeptical of a fully-integrated AI workhorse like this one.

Advertisement

From an energy consumption perspective and just a general concern for the human workforce, these types of AI projects are polarizing in nature.

However, Digital Optimus would be a great digital counterpart to Tesla’s physical Optimus robot, as it would be a hyper-efficient addition to any company that is looking for more production for less cost.

Musk maintains that there is no other company on Earth that will be able to do this.

Advertisement
Continue Reading