While unlocking vehicles with smartphone apps rather than physical keys offers significant convenience benefits, it also significantly expands the attack surface. Security researchers have discovered a method that uses a $169 Flipper Zero device to deceive Tesla owners into relinquishing control of their cars to a malicious third party, enabling the vehicle to be unlocked and even driven away. Also: 7 hacking tools that look harmless but can do real damage Researchers Tommy Mysk and Talal Haj Bakry of Mysk Inc have devised a method for fooling a Tesla owner into handing over their vehicle's login credentials: An attacker would use the Flipper Zero and a Wi-Fi development board to broadcast a fake Tesla guest Wi-Fi network login page -- "Tesla Guest" is the name given to Wi-Fi networks at service centers -- and then use those credentials to log into the owner's account and create new virtual "keys" to the car. Everything that the owner enters into the fake login page -- username, password, and two-factor authentication code -- is captured and displayed on the Flipper Zero. Here's a walkthrough of the process. This attack also bypasses the two-factor authentication because the fake Tesla guest Wi-Fi network login page requests the two-factor authentication code that the attacker then uses to access the account. This does mean that the hacker has to work fast, and be able to request and then subsequently use that code rapidly to be able to access the account. Will the physical k...
Teslas vulnerable to Flipper Zero hack - here's how to protect yourself
ZDNet
·Adrian Kingsley-Hughes
·Published Mar 8, 2024
·Updated
Affected Software
1 affected component
Tesla Tesla Mobile App
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in Tesla vehicles that can be exploited using the Flipper Zero hacking device.
2
What security implications are discussed in relation to Tesla vehicles?
The security implications include the risk of unauthorized access to Tesla vehicles via smartphone apps due to expanded attack surfaces.
3
What products or software are affected by this vulnerability?
The affected product is the Tesla Mobile App, which facilitates remote vehicle access.
4
What is the Flipper Zero, and how is it used in the attack?
The Flipper Zero is a $169 hacking device that can manipulate wireless signals to gain unauthorized access to Tesla vehicles.
5
How can Tesla owners protect themselves from this vulnerability?
Tesla owners are advised to implement additional security measures, such as enabling two-factor authentication and regularly updating their app and vehicle software.