Connect with us
Tesla Pwn2Own Tesla Pwn2Own

News

Tesla cybersecurity measures fail, hackers win Model 3 at hacking event

Credit: Zero Day Initiative, Twitter

Published

on

Tesla has been hacked at the Pwn2Own hacking event, and the hacking group has taken home a Tesla Model 3 and $100,000.

As electric vehicles and their significant amount of integrated software have become more common in everyday life, the security around them has become significantly more critical. In the worst-case scenario, a hacker could not only gain access to a car but could leak user data or even take control of the vehicle. Now, at the Pwn2Own hacking competition, a group of hackers successfully hacked a Tesla Model 3 and won the vehicle along with a $100,000 prize.

The successful hack completed by the group Synactiv was initially reported by the Zero Day Initiative Twitter account, revealing that the group had used a TOCTOU exploit to gain access to the vehicle.

Advertisement
-
-

Thanks to the nature of the hacking competition, the details of how the hack was performed have not been made entirely public to avoid a security risk for Tesla owners. Still, the method the hackers used was relatively straightforward.

The TOCTOU (Time-Of-Check Time-Of-Use) exploit involves altering internal files to gain system access. In essence, the hackers are altering the files that a system will check to ensure someone actually should have access. This could, for example, involve changing login credentials to allow yourself access. However, as the name suggests, this is highly time-dependent, as it involves using the discrepancy of time between the system checking the files and a person actually being logged in.

Pwn2Own is one of the most famous hacking events in the world. It involves teams of hackers attempting to gain access to some of the most popular software available on the market. Each group of hackers and security researchers will be given a list of devices and software and a series of objectives to achieve. The first team to navigate through the list gains a cash prize. In this case, for completing this step of the competition quickest, the Synactive team won the Tesla Model 3 that they hacked.

With software becoming ever more interconnected with the vehicles we drive, focusing on keeping that software secure will only become more important as time passes. And with the increasing interconnectedness of these car systems, the consequences of not keeping these systems secure will only become more dire. Hopefully, automakers will take this threat seriously and continue to work to keep their items as safe and secure as possible.

What do you think of the article? Do you have any comments, questions, or concerns? Shoot me an email at william@teslarati.com. You can also reach me on Twitter @WilliamWritin. If you have news tips, email us at tips@teslarati.com!

Will is an auto enthusiast, a gear head, and an EV enthusiast above all. From racing, to industry data, to the most advanced EV tech on earth, he now covers it at Teslarati.

Advertisement
Comments

News

SpaceX just launched a secret payload from California

SpaceX launched a classified Space Force mission from Vandenberg, revealing almost nothing about its payload.

Published

on

By

Space Force officials say the Falcon 9 booster pictured here in SpaceX's rocket factory will have to wait a few months longer for its launch debut. (SpaceX)

SpaceX launched a classified Falcon 9 mission for the U.S. Space Force from Vandenberg Space Force Base on Saturday night, and the government released almost nothing about what was on board. The mission, designated USSF-366, lifted off from Space Launch Complex 4E with a window that opened at 9:52 p.m. ET and ran into the early hours of Sunday, according to SpaceX’s own mission page, which described the payload only as classified. SpaceX confirmed the launch on its X account and pointed viewers to a livestream that began roughly ten minutes before liftoff.


The lack of detail did not stop analysts from filling in the blanks. Independent tracking of the rocket’s stage drop zones matched the pattern SpaceX has used on previous Starlink Group 15 missions, according to reporting from Outer Space Today, which pointed to Starshield as the likely payload rather than a one off government satellite. Starshield is SpaceX’s national security product, a version of the Starlink satellite bus built to Pentagon specifications for earth observation, communications and hosted payloads. Unlike consumer Starlink, government agencies do not have to disclose what Starshield satellites are actually doing once they reach orbit.

USSF-366 is the latest entry in a steady flow of classified and semi classified work between SpaceX and the Space Force. The company picked up a $178.5 million task order in April to launch missile tracking satellites for the Space Development Agency, as Teslarati reported at the time, and followed that in July with a $1.6 billion award covering 18 more Falcon 9 missions from Vandenberg through the end of 2027, also detailed by Teslarati. Add those contracts up and SpaceX’s Pentagon business for 2026 alone tops $8 billion.

SpaceX scores another massive Pentagon deal to support military satellites

The Falcon 9 that flew Saturday landed back near the launch site, producing the sonic booms that have become routine for residents near Vandenberg. What is less routine is how little the public will likely ever learn about what the rocket carried. SpaceX and the Space Force have not confirmed the Starshield connection, and government satellite programs built on commercial buses rarely get identified beyond a mission number and a general orbit. For a company that live streams almost everything else it does, from Starship test flights to Optimus robot demos, USSF-366 is a reminder that some of SpaceX’s busiest work now happens entirely out of public view.

Advertisement
-
-
Continue Reading

News

Tesla V2L adapter for Model Y stirs up a new complaint among owners

Published

on

Credit: Tesla

On Friday, Tesla launched the Outlet Adapter that enabled Vehicle-to-Load (V2L) energy transfer, meaning owners could essentially utilize their cars as a power source for things like laptops, electric grills, or string lights.

However, even owners of some of the newest builds of the Model Y are finding out that their cars are not compatible with the new $80 accessory, stirring up a new complaint among members of the community.

Tesla launches V2L Outlet Adapter for Premium Model Y in the U.S.

Upon the release of the Outlet Adapter on Friday, I signed into my Tesla account to order the accessory. However, I was met with the dreaded “This product is not compatible with your 2026 Model Y” message at the bottom of the screen.

Some said their accounts also displayed the same message, but they ordered anyway. However, they might be surprised to find that this is no mistake; some of the newest Model Ys do not have the appropriate Power Conversion System (PCS). Mine, which was ordered on this day last year and delivered on August 31, has the old 48A, single-phase PCS.

Vehicles with the new, two-piece PCS are able to utilize V2L features on their cars:

Obviously, it’s disappointing. Many owners have taken delivery this year and still can not utilize the Outlet Adapter because their cars feature the old PCS:

It looks like if you have one of these older PCS units, you can upgrade, but the parts alone are $1,750, and that’s before Tesla adds labor for installing. It is honestly more logical to get some kind of portable power supply or power station at that point.

Advertisement
-
-

It is great that Tesla has enabled V2L for Model Y vehicles, but it is also unfortunate that vehicles that are less than one year old are not able to take advantage of this awesome new feature.

With that being said, it truly is a first-world problem; can you really complain when Full Self-Driving is available, maintenance is incredibly inexpensive, and the car has been so good through a year of ownership?

Continue Reading

News

Tesla launches V2L Outlet Adapter for Premium Model Y in the U.S.

Published

on

Credit: Tesla

Tesla has launched a new Vehicle-to-Load (V2L) Outlet Adapter for Premium Model Y vehicles in the United States, meaning you can now power devices like laptops or light strings with your vehicle’s battery.

It appears the capability will be available for any Model Y Premium trim, including those that were purchased prior to the Adapter being launched. It will also only impact Juniper Model Y vehicles, so the first-gen owners will unfortunately not have access to this capability.

If your Model Y was purchased before Tesla renamed the trim levels to “Premium” and “Standard,” it does not seem to be compatible. My Model Y is technically a Premium build, as it is the Long Range All-Wheel-Drive. However, Tesla says it is not compatible with my vehicle.

For $80, you can now utilize your car as a portable charger for small appliances or devices. This is perfect for things like tailgates, concerts, or camping, as you can now plug in devices that you might use. Those string lights for camping? That laptop for the other games that are on at the tailgate?

Advertisement
-
-

They’ll both utilize energy from your Tesla’s battery to be powered. This is the first time Tesla has expanded the capability to vehicles outside of the Model Y Performance and Cybertruck. However, this feature has been highly requested by owners for an extended period of time.

Tesla launched the Outlet Adapter in China last year:

Tesla China rolls out Model Y L V2L adapter, and it’s free for early owners

You will need the Mobile Connector to operate the Outlet Adapter: the Outlet Adapter will plug into the main housing of the Mobile Connector, where the appropriate adapter to charge your vehicle will plug in.

It is rated for 120 volts and 20 amps, and has a max power rating of 2.4kW.

You can buy it here from Tesla for $80.

Advertisement
-
-
Continue Reading