So much stuff need to happen for two devices to interact securely that there's seems to be no chain of events that could make this possible.
Either the app goes through their servers and back to the car, which would make it impossible to unlock the wrong car, or through BLE, which would make it easy to verify through digital signatures that the other device is who they say.
which would make it easy to verify through digital signatures that the other device is who they say.
The entire tech industry has a long history of security issues, bad practices, mismanagement of security critical resources (openssl,...), horrible hacks with security issues that where widely discussed beforehand (http tunneling), etc. . The only fake story I could see from a mile away would be "Company publishes flawless auth system, hackers forced to retire".
I agree it doesn't feel right. I have a Tesla, and often come out and find other Teslas parked right to mine. Sometimes 4 or 5. At some point, someone would've been able to unlock mine and done something to my car. Or similar settings anywhere else.
I think we'd have heard this story more than once if it was possible.
EDIT: I grant the possibilities outlined by the responders to my post... still, I'll put a little $$ on this getting clarified otherwise in the coming weeks -- but not any more than that, as I've lost a $ in this week's banking crisis.
There's always the first time you hear a particular story. There's a continuously increasing mapping from how likely such an event is to when you should expect to hear about it for the first time.
That seems like a nonsequitor to me. I don't think that being well-off correlates to whether or not someone is willing to violate the law. And I don't think that, in this situation, rummaging through the car to find contact info is actually illegal.
It could be a rare hash collision. It wouldn't happen to you but with millions of Teslas out there it would happen to somebody. I wouldn't be surprised if this were real.
Some race condition that causes a duplicate signature to be generated, or causes the same signature to be sent to two different cars doesn't seem too outlandish to me. I have seen similar bugs before. The only thing that is coincidental is that the duplicates ended up in two vehicles near enough to each other for the mistake to matter.
Both cars unlocked and presumably started at different times for different people, so it would have had to have been simultaneous of two identical race conditions on two different sets of devices at different times. This feels like total bs.
No, I am suggesting one race at the factory that gave the two vehicles the same private key. Therefore Person A can always access Person B's car and vice versa because they use identical keys.
Yeah, now that I "said it out loud" it seems like if that were the case, there would be instances of them using the app while you are driving or near your car. You would know "something" is wrong with your car even if you don't know what exactly.
Yeah when I worked at Amazon we found two computers with NICs with identical MAC addresses (and it was a long time ago when Amazon had an awful lot less servers). Some database process at the manufacturer had a race condition.
Also somehow the other person just happened to have his phone number according to the article? Feels fake as hell, and it is jalopnik...
“After five, 10 minutes I got a text on my phone that said ‘Rajesh are you driving [a] Tesla,’” he explained to the outlet. Randev went on to say the person who messaged him told him he was driving the wrong car.
The article also explains the person didn't just happen to have his phone number if you continue on:
When the two Tesla owners met up, the rightful owner of the car Randev was driving told him he’d found Randev’s phone number on a document inside Randev’s car.
Overall the original article linked by jalopnik is better written though.
Hang on, does that imply the other person had got into Randev's Tesla somehow? Because it seems like the obvious explanation is that they both unlocked their own Teslas at around the same time, but one of them thought the other person's Tesla was theirs because it was in about the right place and unlocked and drove it away...
The story also discusses both of these points. The other guy did get into his Tesla:
That means, if you’re following along, the other guy was able to gain access to Randev’s Tesla as well.
But it wouldn't make sense both Tesla's were just unlocked and started at the same time since he was later able to unlock and start the Tesla a 2nd time:
The two Tesla owners made a plan to switch the cars back — after Randev picked his kids from school. That’s right: Randev was able to get into the Model 3 that wasn’t his, and drive away, for a second time.
(as a side note both of these are worded much better in the original article). It also says he has video evidence of the issue he was trying to deliver to Tesla but neither article includes that video so I'm not sure I buy a simple solution without evidence the entire thing was just fabricated.
Comments
This has to be fake.
So much stuff need to happen for two devices to interact securely that there's seems to be no chain of events that could make this possible.
Either the app goes through their servers and back to the car, which would make it impossible to unlock the wrong car, or through BLE, which would make it easy to verify through digital signatures that the other device is who they say.
The entire tech industry has a long history of security issues, bad practices, mismanagement of security critical resources (openssl,...), horrible hacks with security issues that where widely discussed beforehand (http tunneling), etc. . The only fake story I could see from a mile away would be "Company publishes flawless auth system, hackers forced to retire".
I agree it doesn't feel right. I have a Tesla, and often come out and find other Teslas parked right to mine. Sometimes 4 or 5. At some point, someone would've been able to unlock mine and done something to my car. Or similar settings anywhere else.
I think we'd have heard this story more than once if it was possible.
EDIT: I grant the possibilities outlined by the responders to my post... still, I'll put a little $$ on this getting clarified otherwise in the coming weeks -- but not any more than that, as I've lost a $ in this week's banking crisis.
There's always the first time you hear a particular story. There's a continuously increasing mapping from how likely such an event is to when you should expect to hear about it for the first time.
People who drive Teslas are usually pretty well off, probably not the type to risk arrest by rummaging around in another person's car.
That seems like a nonsequitor to me. I don't think that being well-off correlates to whether or not someone is willing to violate the law. And I don't think that, in this situation, rummaging through the car to find contact info is actually illegal.
It could be a rare hash collision. It wouldn't happen to you but with millions of Teslas out there it would happen to somebody. I wouldn't be surprised if this were real.
Teslas get OTA updates all the time. Perhaps something was accidentally broken only recently?
Your comment reads like the statement of a very naïve person who hasn't witnessed the past 30 years of computer technology.
Some race condition that causes a duplicate signature to be generated, or causes the same signature to be sent to two different cars doesn't seem too outlandish to me. I have seen similar bugs before. The only thing that is coincidental is that the duplicates ended up in two vehicles near enough to each other for the mistake to matter.
Both cars unlocked and presumably started at different times for different people, so it would have had to have been simultaneous of two identical race conditions on two different sets of devices at different times. This feels like total bs.
No, I am suggesting one race at the factory that gave the two vehicles the same private key. Therefore Person A can always access Person B's car and vice versa because they use identical keys.
Maybe, but that seems unlikely - this would also mean any time one car is unlocked the other is too (presumably if done by app not BLE)
Yeah, now that I "said it out loud" it seems like if that were the case, there would be instances of them using the app while you are driving or near your car. You would know "something" is wrong with your car even if you don't know what exactly.
Yeah when I worked at Amazon we found two computers with NICs with identical MAC addresses (and it was a long time ago when Amazon had an awful lot less servers). Some database process at the manufacturer had a race condition.
As if there's no opportunity for defects anywhere in that mountain of abstractions...
Also somehow the other person just happened to have his phone number according to the article? Feels fake as hell, and it is jalopnik...
The article also explains the person didn't just happen to have his phone number if you continue on:
Overall the original article linked by jalopnik is better written though.
Hang on, does that imply the other person had got into Randev's Tesla somehow? Because it seems like the obvious explanation is that they both unlocked their own Teslas at around the same time, but one of them thought the other person's Tesla was theirs because it was in about the right place and unlocked and drove it away...
The story also discusses both of these points. The other guy did get into his Tesla:
But it wouldn't make sense both Tesla's were just unlocked and started at the same time since he was later able to unlock and start the Tesla a 2nd time:
(as a side note both of these are worded much better in the original article). It also says he has video evidence of the issue he was trying to deliver to Tesla but neither article includes that video so I'm not sure I buy a simple solution without evidence the entire thing was just fabricated.
Yeah, car makers have never designed fundamentally buggy and insecure digital systems before. Definitely stretches credulity!