Connect with us
Tesla hackers find a vulnerability with NFC relay attack Tesla hackers find a vulnerability with NFC relay attack

News

Tesla hackers find a vulnerability with NFC relay attack

Jeremy from Sydney, Australia, CC BY 2.0 , via Wikimedia Commons

Published

on

Tesla hackers have found a vulnerability with an NFC relay hack but there’s a catch. Thieves will have to work in pairs and get close to the NFC chip or smartphone.

According to IOActive, the relay attack needs two attackers. One uses the Proxmark device at the vehicle’s NFC reader. The other uses any NFC-capable device close to a Tesla owner’s NFC card or smartphone. The team is then able to use Bluetooth to communicate between the devices and replicate the key to one of the thieve’s smartphones.

This new demonstration comes a few days after the National Highway Traffic Safety Administration (NHTSA) recently released an update to its 2016 edition of its Cybersecurity Best Practices for the Safety of Modern Vehicles. Dr. Steven Cliff, NHTSA’s Administrator emphasized the need for cybersecurity to be a top priority for every automaker, developer, and operator.

According to the agency, a layered approach to vehicle cybersecurity reduces the probability of a successful attack while mitigating the ramifications of unauthorized vehicle system access. The NHTSA also added that public key cryptography techniques are more secure than symmetric keys valid across multiple vehicles.

In 2018, Tesla began rolling out the PIN to Drive feature and improved cryptography for its key fobs as a response to several Tesla vehicle thefts through relay attacks in Europe.

In 2019, Tesla began releasing over-the-air software updates addressing the findings of Lennert Wouters of Katholieke Universiteit Leuven in Belgium (KU Leuven). Wouters discovered a security flaw that allowed car thieves to clone a key fob in less than two seconds. Tesla’s solution included the PIN to Drive, a software update, and a new fob that made the Tesla Models S and X  almost 90% less likely to get stolen than the average car.

The new demonstration may show a vulnerability if thieves are dedicated enough to work at it, but Tesla is pretty fast at addressing these flaws. However, all car owners, whether they own an EV or not, should always be aware of their surroundings. You can watch IOActive’s demonstration video below.

Advertisement
-
-

Note: Johnna is a Tesla shareholder and supports its mission. 

Your feedback is important. If you have any comments, or concerns, or see a typo, you can email me at johnna@teslarati.com. You can also reach me on Twitter at @JohnnaCrider1.

Teslarati is now on TikTok. Follow us for interactive news & more.

Johnna Crider is a Baton Rouge writer covering Tesla, Elon Musk, EVs, and clean energy & supports Tesla's mission. Johnna also interviewed Elon Musk and you can listen here

Advertisement
Comments

News

SpaceX just launched a secret payload from California

SpaceX launched a classified Space Force mission from Vandenberg, revealing almost nothing about its payload.

Published

on

By

Space Force officials say the Falcon 9 booster pictured here in SpaceX's rocket factory will have to wait a few months longer for its launch debut. (SpaceX)

SpaceX launched a classified Falcon 9 mission for the U.S. Space Force from Vandenberg Space Force Base on Saturday night, and the government released almost nothing about what was on board. The mission, designated USSF-366, lifted off from Space Launch Complex 4E with a window that opened at 9:52 p.m. ET and ran into the early hours of Sunday, according to SpaceX’s own mission page, which described the payload only as classified. SpaceX confirmed the launch on its X account and pointed viewers to a livestream that began roughly ten minutes before liftoff.


The lack of detail did not stop analysts from filling in the blanks. Independent tracking of the rocket’s stage drop zones matched the pattern SpaceX has used on previous Starlink Group 15 missions, according to reporting from Outer Space Today, which pointed to Starshield as the likely payload rather than a one off government satellite. Starshield is SpaceX’s national security product, a version of the Starlink satellite bus built to Pentagon specifications for earth observation, communications and hosted payloads. Unlike consumer Starlink, government agencies do not have to disclose what Starshield satellites are actually doing once they reach orbit.

USSF-366 is the latest entry in a steady flow of classified and semi classified work between SpaceX and the Space Force. The company picked up a $178.5 million task order in April to launch missile tracking satellites for the Space Development Agency, as Teslarati reported at the time, and followed that in July with a $1.6 billion award covering 18 more Falcon 9 missions from Vandenberg through the end of 2027, also detailed by Teslarati. Add those contracts up and SpaceX’s Pentagon business for 2026 alone tops $8 billion.

SpaceX scores another massive Pentagon deal to support military satellites

The Falcon 9 that flew Saturday landed back near the launch site, producing the sonic booms that have become routine for residents near Vandenberg. What is less routine is how little the public will likely ever learn about what the rocket carried. SpaceX and the Space Force have not confirmed the Starshield connection, and government satellite programs built on commercial buses rarely get identified beyond a mission number and a general orbit. For a company that live streams almost everything else it does, from Starship test flights to Optimus robot demos, USSF-366 is a reminder that some of SpaceX’s busiest work now happens entirely out of public view.

Advertisement
-
-
Continue Reading

News

Tesla V2L adapter for Model Y stirs up a new complaint among owners

Published

on

Credit: Tesla

On Friday, Tesla launched the Outlet Adapter that enabled Vehicle-to-Load (V2L) energy transfer, meaning owners could essentially utilize their cars as a power source for things like laptops, electric grills, or string lights.

However, even owners of some of the newest builds of the Model Y are finding out that their cars are not compatible with the new $80 accessory, stirring up a new complaint among members of the community.

Tesla launches V2L Outlet Adapter for Premium Model Y in the U.S.

Upon the release of the Outlet Adapter on Friday, I signed into my Tesla account to order the accessory. However, I was met with the dreaded “This product is not compatible with your 2026 Model Y” message at the bottom of the screen.

Some said their accounts also displayed the same message, but they ordered anyway. However, they might be surprised to find that this is no mistake; some of the newest Model Ys do not have the appropriate Power Conversion System (PCS). Mine, which was ordered on this day last year and delivered on August 31, has the old 48A, single-phase PCS.

Vehicles with the new, two-piece PCS are able to utilize V2L features on their cars:

Obviously, it’s disappointing. Many owners have taken delivery this year and still can not utilize the Outlet Adapter because their cars feature the old PCS:

It looks like if you have one of these older PCS units, you can upgrade, but the parts alone are $1,750, and that’s before Tesla adds labor for installing. It is honestly more logical to get some kind of portable power supply or power station at that point.

Advertisement
-
-

It is great that Tesla has enabled V2L for Model Y vehicles, but it is also unfortunate that vehicles that are less than one year old are not able to take advantage of this awesome new feature.

With that being said, it truly is a first-world problem; can you really complain when Full Self-Driving is available, maintenance is incredibly inexpensive, and the car has been so good through a year of ownership?

Continue Reading

News

Tesla launches V2L Outlet Adapter for Premium Model Y in the U.S.

Published

on

Credit: Tesla

Tesla has launched a new Vehicle-to-Load (V2L) Outlet Adapter for Premium Model Y vehicles in the United States, meaning you can now power devices like laptops or light strings with your vehicle’s battery.

It appears the capability will be available for any Model Y Premium trim, including those that were purchased prior to the Adapter being launched. It will also only impact Juniper Model Y vehicles, so the first-gen owners will unfortunately not have access to this capability.

If your Model Y was purchased before Tesla renamed the trim levels to “Premium” and “Standard,” it does not seem to be compatible. My Model Y is technically a Premium build, as it is the Long Range All-Wheel-Drive. However, Tesla says it is not compatible with my vehicle.

For $80, you can now utilize your car as a portable charger for small appliances or devices. This is perfect for things like tailgates, concerts, or camping, as you can now plug in devices that you might use. Those string lights for camping? That laptop for the other games that are on at the tailgate?

Advertisement
-
-

They’ll both utilize energy from your Tesla’s battery to be powered. This is the first time Tesla has expanded the capability to vehicles outside of the Model Y Performance and Cybertruck. However, this feature has been highly requested by owners for an extended period of time.

Tesla launched the Outlet Adapter in China last year:

Tesla China rolls out Model Y L V2L adapter, and it’s free for early owners

You will need the Mobile Connector to operate the Outlet Adapter: the Outlet Adapter will plug into the main housing of the Mobile Connector, where the appropriate adapter to charge your vehicle will plug in.

It is rated for 120 volts and 20 amps, and has a max power rating of 2.4kW.

You can buy it here from Tesla for $80.

Advertisement
-
-
Continue Reading