Hacker News new | ask | show | jobs
by createdapril24 926 days ago
Tesla not only looks at these, they coordinate their fixes and disclosure. Tesla runs a bug bounty program https://bugcrowd.com/tesla, contracts with security research companies to audit its vehicles, has a security researcher program where they share more access & documentation for researchers who have helped improve vehicle security, and put up both vehicles and cash in pwn2own.

Obtaining code execution, persistence, or privilege escalation on a Tesla is a formidable challenge. Pwn2own went many years without there being any compromise of the vehicle, and last year's compromise was done by a firm that dedicated a lab and team of people for more than 6 months.

1 comments

The (ahem) road to this state is probably littered with lessons learned. I'm hopeful that Tesla will share that history, allows its people to write about it, and let the wider community generalize and learn. There's a lot more than cars out there.