Connect with us
Tesla hackers find a vulnerability with NFC relay attack Tesla hackers find a vulnerability with NFC relay attack

News

Tesla hackers find a vulnerability with NFC relay attack

Jeremy from Sydney, Australia, CC BY 2.0 , via Wikimedia Commons

Published

on

Tesla hackers have found a vulnerability with an NFC relay hack but there’s a catch. Thieves will have to work in pairs and get close to the NFC chip or smartphone.

According to IOActive, the relay attack needs two attackers. One uses the Proxmark device at the vehicle’s NFC reader. The other uses any NFC-capable device close to a Tesla owner’s NFC card or smartphone. The team is then able to use Bluetooth to communicate between the devices and replicate the key to one of the thieve’s smartphones.

This new demonstration comes a few days after the National Highway Traffic Safety Administration (NHTSA) recently released an update to its 2016 edition of its Cybersecurity Best Practices for the Safety of Modern Vehicles. Dr. Steven Cliff, NHTSA’s Administrator emphasized the need for cybersecurity to be a top priority for every automaker, developer, and operator.

According to the agency, a layered approach to vehicle cybersecurity reduces the probability of a successful attack while mitigating the ramifications of unauthorized vehicle system access. The NHTSA also added that public key cryptography techniques are more secure than symmetric keys valid across multiple vehicles.

Advertisement

In 2018, Tesla began rolling out the PIN to Drive feature and improved cryptography for its key fobs as a response to several Tesla vehicle thefts through relay attacks in Europe.

In 2019, Tesla began releasing over-the-air software updates addressing the findings of Lennert Wouters of Katholieke Universiteit Leuven in Belgium (KU Leuven). Wouters discovered a security flaw that allowed car thieves to clone a key fob in less than two seconds. Tesla’s solution included the PIN to Drive, a software update, and a new fob that made the Tesla Models S and X  almost 90% less likely to get stolen than the average car.

The new demonstration may show a vulnerability if thieves are dedicated enough to work at it, but Tesla is pretty fast at addressing these flaws. However, all car owners, whether they own an EV or not, should always be aware of their surroundings. You can watch IOActive’s demonstration video below.

Advertisement

Note: Johnna is a Tesla shareholder and supports its mission. 

Your feedback is important. If you have any comments, or concerns, or see a typo, you can email me at johnna@teslarati.com. You can also reach me on Twitter at @JohnnaCrider1.

Teslarati is now on TikTok. Follow us for interactive news & more.

Advertisement

Johnna Crider is a Baton Rouge writer covering Tesla, Elon Musk, EVs, and clean energy & supports Tesla's mission. Johnna also interviewed Elon Musk and you can listen here

Advertisement
Comments

News

Tesla Giga Berlin dispute against IG Metall union leads to investigation

As per a report from rbb24, police seized a laptop belonging to an IG Metall member at Tesla Giga Berlin on Tuesday afternoon.

Published

on

Credit: Tesla Manufacturing/X

German authorities have opened an investigation into an IG Metall union representative following allegations that a confidential works council meeting at Tesla’s Gigafactory Berlin was secretly recorded. The probe follows a criminal complaint filed by Tesla management last week.

As per a report from rbb24, police seized a laptop belonging to an IG Metall member at Tesla Giga Berlin on Tuesday afternoon. Prosecutors in Frankfurt (Oder) confirmed that an investigation is underway into a possible unauthorized audio recording of an internal works council meeting.

Under German law, recording a non-public meeting without consent may constitute a criminal offense.

Tesla stated that Gigafactory Berlin employees alerted management after allegedly discovering that an external union representative, who was attending the event as a guest, had recorded the session. Plant manager André Thierig stated in a post on X that the representative was “caught in action,” prompting the company to contact police and file a criminal complaint.

Advertisement

The seized device is now part of the investigation, and authorities will determine whether any unlawful recording had indeed occurred.

IG Metall has denied the accusation. In comments to German media, representatives rejected Tesla’s claim and described the electric vehicle maker’s allegation as an election campaign tactic ahead of upcoming works council elections.

The election at Tesla’s Grünheide plant is scheduled for March 2–4, 2026, with about 11,000 employees being eligible to vote. Regular works council elections in Germany are held every four years between March and May.

The incident comes amid tensions between Tesla and organized labor in Germany. While works councils operate independently from unions, IG Metall has been active at the plant and has previously criticized Tesla’s labor practices. Authorities, for their part, have not yet announced whether charges will be filed, though the investigation remains ongoing.

Advertisement
Continue Reading

News

Tesla rolls out xAI’s Grok to vehicles across Europe

The initial rollout includes the United Kingdom, Ireland, Germany, Switzerland, Austria, Italy, France, Portugal, and Spain.

Published

on

Tesla is rolling out Grok to vehicles in Europe. The feature will initially launch in nine European territories.

In a post on X, the official Tesla Europe, Middle East & Africa account confirmed that Grok is coming to Teslas in Europe. The initial rollout includes the United Kingdom, Ireland, Germany, Switzerland, Austria, Italy, France, Portugal, and Spain, and additional markets are expected to be added later.

Grok allows drivers to ask questions using real-time information and interact hands-free while driving. According to Tesla’s support documentation, Grok can also initiate navigation commands, enabling users to search for destinations, discover points of interest, and adjust routes without touching the touchscreen, as per the feature’s official webpage.

The system offers selectable personalities, ranging from “Storyteller” to “Unhinged,” and is activated either through the App Launcher or by pressing and holding the steering wheel’s microphone button.

Advertisement

Grok is currently available only on Model S, Model 3, Model X, Model Y, and Cybertruck vehicles equipped with an AMD infotainment processor. Vehicles must be running software version 2025.26 or later, with navigation command support requiring version 2025.44.25 or newer.

Drivers must also have Premium Connectivity or a stable Wi-Fi connection to use the feature. Tesla notes that Grok does not currently replace standard voice commands for vehicle controls such as climate or media adjustments.

The company has stated that Grok interactions are processed securely by xAI and are not linked to individual drivers or vehicles. Users do not need a Grok account or subscription to enable the feature at this time as well.

Continue Reading

News

Tesla ends Full Self-Driving purchase option in the U.S.

In January, Musk announced that Tesla would remove the ability to purchase the suite outright for $8,000. This would give the vehicle Full Self-Driving for its entire lifespan, but Tesla intended to move away from it, for several reasons, one being that a tranche in the CEO’s pay package requires 10 million active subscriptions of FSD.

Published

on

Credit: Tesla

Tesla has officially ended the option to purchase the Full Self-Driving suite outright, a move that was announced for the United States market in January by CEO Elon Musk.

The driver assistance suite is now exclusively available in the U.S. as a subscription, which is currently priced at $99 per month.

Tesla moved away from the outright purchase option in an effort to move more people to the subscription program, but there are concerns over its current price and the potential for it to rise.

In January, Musk announced that Tesla would remove the ability to purchase the suite outright for $8,000. This would give the vehicle Full Self-Driving for its entire lifespan, but Tesla intended to move away from it, for several reasons, one being that a tranche in the CEO’s pay package requires 10 million active subscriptions of FSD.

Although Tesla moved back the deadline in other countries, it has now taken effect in the U.S. on Sunday morning. Tesla updated its website to reflect this:

There are still some concerns regarding its price, as $99 per month is not where many consumers are hoping to see the subscription price stay.

Musk has said that as capabilities improve, the price will go up, but it seems unlikely that 10 million drivers will want to pay an extra $100 every month for the capability, even if it is extremely useful.

Instead, many owners and fans of the company are calling for Tesla to offer a different type of pricing platform. This includes a tiered-system that would let owners pick and choose the features they would want for varying prices, or even a daily, weekly, monthly, and annual pricing option, which would incentivize longer-term purchasing.

Although Musk and other Tesla are aware of FSD’s capabilities and state is is worth much more than its current price, there could be some merit in the idea of offering a price for Supervised FSD and another price for Unsupervised FSD when it becomes available.

Continue Reading