Image created by AI
In the evolving landscape of automobile technology, where convenience often comes hand-in-hand with connectivity, two security researchers, Talal Haj Bakry and Tommy Mysk of Mysk Inc., have identified a critical vulnerability that potentially puts Tesla owners at risk of having their vehicles stolen. By simulating a Wi-Fi attack at charging stations, the duo demonstrated that Tesla cars could be unlocked and started through a deceptively simple process that calls into question the robustness of the car’s security features.
The demonstration utilized a compromised Wi-Fi setup designed to mimic "Tesla Guest," a common network name at Tesla Supercharger locations. Using a hardware device known as Flipper Zero, the researchers created a captive network that could entice users to connect by assuming the guise of an official Tesla Wi-Fi hotspot. Such hardware is easily accessible; attackers could also deploy similar setups using a Raspberry Pi or an Android phone.
Once Tesla owners connected to this malicious network, they were prompted to input their Tesla login credentials, including their username, password, and the requisite two-factor authentication PIN, into a falsified login screen. These credentials are conventionally used to track the car and sign into the Tesla mobile application.
Capitalizing on these stolen credentials, the attackers could then link a new phone key—a digital method of unlocking and starting Tesla vehicles—without the owners' knowledge. The researchers revealed a concerning lack of proper notification or authentication; no alerts were sent to the owner's phone or displayed on the vehicle's touchscreen during the addition of this new device, making the attack stealthy and silently effective.
This lack of internal security checks is particularly alarming, as Tesla's current protocol only requires a physical key card to remove a phone key but not to add one. Mysk Inc. highlights this inconsistency, suggesting that similar authentication should be mandatory for all alterations to access controls within the vehicle's system.
Despite the severity of the findings, Tesla's response to the report was dismissive. The car manufacturer investigated the claim and concluded the behavior of the car's system was "as intended," citing the owner’s manual which does not specify the need for a key card when adding a new phone key. The company indicated that the issue fell outside the scope of their Bug Bounty Program—a platform designed to reward individuals for reporting potential threats—and thus, implied no immediate intentions to modify the affected features.
This incident brings to light significant concerns surrounding the cyber safety of connected vehicles. As cars become more integrated with technology, the vectors for cyber-attacks widen. It is a reminder of the importance of rigorous cybersecurity measures, and the need for constant vigilance and updates to safeguard against new threats.