37C3 - Back in the Driver's Seat: Recovering Critical Data from Tesla Autopilot Using Voltage Glitch
https://media.ccc.de/v/37c3-12144-bac... Tesla's driving assistant has been subject to public scrutiny for good and bad: As accidents with its "full self-driving" (FSD) technology keep making headlines, the code and data behind the onboard Autopilot system are well-protected by the car manufacturer. In this talk, we demonstrate our voltage-glitching attack on Tesla Autopilot, enabling us root privileges on the system. Apart from building electric vehicles, Tesla has gained a reputation for their integrated computer platform comprising a feature-rich infotainment system, remote services through Tesla's Cloud and mobile app, and, most notably, an automated driving assistant. Enabled by a dedicated arm64-based system called Autopilot, Tesla offers different levels of "self-driving". The "full self-driving" (FSD) is provided to specific customers via in-car purchases and has been subject to public discourse. Despite using multiple cameras and Autopilot's machine learning (ML) models, accidents persist and shape FSD reporting. While the platform security of Autopilot's hardware protects the code and ML models from competitors, it also hinders third parties from accessing critical user data, e.g., onboard camera recordings and other sensor data, that could help facilitate crash investigations. This presentation shows how we rooted Tesla Autopilot using voltage glitching. The attack enables us to extract arbitrary code and user data from the system. Among other cryptographic keys, we extract a hardware-unique key used to authenticate Autopilot towards Tesla's "mothership". Overall, our talk will shed light on Autopilot's security architecture and gaps. Before delving into Autopilot, we successfully executed a Tesla Jailbreak of the AMD-based infotainment platform and presented our attack at BlackHat USA 2023. This achievement empowered custom modifications to the root file system and temporarily facilitated the activation of paid car features. Niclas Kühnapfel Christian Werling Hans Niklas Jacob - hnj https://events.ccc.de/congress/2023/h... #37c3 #Security

37C3 - Full AACSess: Exposing and exploiting AACSv2 UHD DRM for your viewing pleasure

37C3 - Apple's iPhone 15: Under the C

Something is jamming GPS over Europe. Here's what we found

37C3 - Finding Vulnerabilities in Internet-Connected Devices

20 Years in the Trenches: Modernizing a Monolith from .NET 2.0 to .NET 10 - .NET Stammtisch Linz

I Hacked Into The World's Worst E-Bike And Fixed It

39C3 - Cracking open what makes Apple's Low-Latency WiFi so fast

I Tried to Make a Better Fan

START YOUR TUESDAY WITH FAITH | TODAY GOD IS GIVING YOU UNEXPECTED OPPORTUNITIES | FATHER FREDDY ...

37C3 - Breaking "DRM" in Polish trains

39C3 - Hacking washing machines

Programable Logic Controller Basics Explained - automation engineering

37C3 - Fuzz Everything, Everywhere, All at Once

"Something Wicked This Way Comes" — Why The AI Bubble Isn't What You Think

DEF CON 31 - Contactless Overflow Code Execution in Payment Terminals & ATMs - Josep Rodriguez

Fall asleep while I play PLANET ZOO

Ukraine's drone war is isolating Crimea

Jailbreaking an Electric Vehicle in 2023 or What It Means to Hotwire Tesla's x86-Based Seat Heater

I Tried Every Major Linux Distro So You Don't Have To (Here's What I Found)

