David Colombo made waves recently when he tweeted that he had gained remote control over a number of Tesla vehicles around the world. As part of a responsible disclosure, he recently explained how he did it and what it means for Tesla owners.

Colombo is a 19-year-old cyber security entrepreneur from Germany who has worked with RedBull, the U.S. Department of Defense, and others. Late last year, the company that he founded, Colombo Technology, was working with a software as a service company from Paris whose chief technology officer drove a Tesla.

While poking around, he ended up discovering a webpage called TeslaMate, which gave him all kinds of information about the owner’s car, including how long it had been asleep for, its state of charge, and its mileage.

So, I now have full remote control of over 20 Tesla’s in 10 countries and there seems to be no way to find the owners and report it to them…

— David Colombo (@david_colombo_) January 10, 2022

“I must say, I am a huge Tesla fan myself. So I really wanted to know what exactly this thing was,” Colombo wrote. “TeslaMate is a pretty cool application. A self-hosted data logger for Tesla’s [sic]. And it’s open-source, so you can find everything on GitHub.”

At first, though, it seemed like it could only display information about the car. But he was curious so he dug deeper and discovered that he could actually find the car’s driving data. That meant that he could see where the car had been, where it had charged, where it usually parks, the navigations requests, the history of software updates, and more.

“Me after seeing that: sorry what? 0.o,” he wrote. “This was… not good. And now I definitely knew this is an issue that I should report. I should not be able to know where the CTO of this SaaS company went on vacation last year.”

autos, cars, news, tesla, reports, tech, teen hacker explains how he gained partial control over tesla vehicles

The discovery that TeslaMate could pull data made Colombo curious about whether he could send commands to the Tesla. He read its source code to figure out how authentication worked and found that control over a select set of vehicle actions could be accessed by using the oldest trick in the book.

“Ever heard about this distant cyber security issue called… ‘default passwords’? Yep, TeslaMate Docker’s Grafana installation comes with default credentials,” he wrote. “I took the shot and tried logging in with admin:admin which, kinda unsurprisingly, but still hilariously it worked.”

By doing that, he discovered that he could lock and unlock doors, honk the horn, change heating and cooling settings, and more. It would have even been possible to open some garage doors if they were connected to the more than 25 vehicles in 13 countries that he found he could access.

Although he could not control the steering, accelerator, or braking, Colombo still believes that this is a major safety issue.

“I also think it potentially could result in some dangerous situations on the road,” he wrote. “For example, if someone with remote access starts blasting music on max volume while the driver is on the highway, or randomly and uncontrollable remotely flashing the lights of the Teslas at night.”

Actually, this is partially false. You can use the autosummon feature in a small radius and make the car hit something (potentially but you dont get to steer it) although it'd have to be an upgrade that they own. You could query this though.

— John Jackson 桜の侍 (@johnjhacking) January 11, 2022

Fortunately, Colombo reported his findings to Tesla and the wider world and, as of January 13, the affected users were contacted by the Tesla Security Team. He recommends checking your emails if you’ve ever had TeslaMate deployed.

Although Colombo says he did all of this to highlight securities flaws, he actually doesn’t think Tesla did a bad job or was even being particularly lax in its cybersecurity measures. This is a third-party issue and, although there’s always room for improvement (he makes a few suggestions in his article), he’s actually impressed with Tesla’s security and its response to this issue.

“Tesla is not responsible for owner or third-party issues. Luckily they still helped in remediating this and protecting the affected Tesla owners,” he wrote. “And maybe they’ll even implement some recommendations to give their users an even more secure experience.”

If you’re a Tesla owner who’s a little freaked out by all of this, Colombo has a few recommendations for you. First, you should be very careful who you give your credentials to. You should also enable Pin-to-Drive to prevent someone from stealing your car and you should update TeslaMate, which has been made more secure since he first disclosed this issue. You also should not “put random stuff on the internet.”

Looking forward, Colombo said he will continue researching security related to Tesla in order to keep it as secure as possible.

“Automotive security is a very important topic, especially as other automakers, such as VW, join in digitizing their fleets,” he concluded.

autos, cars, news, tesla, reports, tech, teen hacker explains how he gained partial control over tesla vehicles

Keyword: Teen Hacker Explains How He Gained Partial Control Over Tesla Vehicles

CAR'S NEWS RELATED

Tesla Cybertruck ‘Basecamp’ tent, solar, and beast mode, leak through app

Tesla Cybertruck options and accessories have leaked through a mobile app update revealing a ‘Basecamp’ tent, solar option, and new “Beast mode”. We are just a day away from getting all the details about the Cybertruck direct from Tesla, but a leak is now giving us some details ahead ...

View more: Tesla Cybertruck ‘Basecamp’ tent, solar, and beast mode, leak through app

Taiwanese Tesla supplier Hota retools supply chain with first US factory

Companies Hota Industrial Mfg. Co Ltd Ford Motor Co General Motors Co TAICHUNG, Taiwan, Nov 29 (Reuters) – For years, Hota Industrial Mfg. Co has made gears, shafts and other auto parts in Taiwan and shipped them to large foreign carmakers such as Tesla (TSLA.O), Ford Motor (F.N) and ...

View more: Taiwanese Tesla supplier Hota retools supply chain with first US factory

Tesla Cybertruck’s ‘Beast Mode’, Trim Details Uncovered By Software Developer

A developer who deconstructed the Tesla app also revealed that the pickup will come in two trim levels.

View more: Tesla Cybertruck’s ‘Beast Mode’, Trim Details Uncovered By Software Developer

Mazda CEO Says Electric Vehicles (Other Than Teslas) are “Not Taking Off”

Mazda’s Chief Operating Officer, Masahiro Moro, has expressed some frustrations that the company’s battery-electric lineup is struggling to gain traction, stating that any EV, other than a Tesla, simply isn’t popular with buyers. In a surprisingly candid interview with Fortune, Moro said that “EV is an absolutely important technology, and ...

View more: Mazda CEO Says Electric Vehicles (Other Than Teslas) are “Not Taking Off”

Closer look at Tesla Cybertruck – should we be concerned?

We get a closer look at the Tesla Cybertruck with one of the units the automaker is now displaying in its showrooms. Should we be concerned about the build quality? Much has been said about the Cybertruck build quality even before the truck has made it to market. We ...

View more: Closer look at Tesla Cybertruck – should we be concerned?

Tired Of Waiting For Your Cybertruck? You Can Now Lease A Rivian R1T

Photo: Rivian Rivian finally started offering leases for its electric R1T pickup in 14 states on Monday, and these leases are eligible for the full $7500 federal EV lease credit – in contrast to the $3750 credit that Rivian buyers are eligible for. The lucky residents of Arizona, California, ...

View more: Tired Of Waiting For Your Cybertruck? You Can Now Lease A Rivian R1T

Even A Tesla Cybertruck Prototype Can't Mess With San Francisco Parking Enforcement

Screenshot: Tesla East Bay Fremont on Twitter There have been a lot of Tesla Cybertruck ‘release candidates’ on the back of tow trucks lately, but they’ve all been related to breakdowns. This time a Cybertruck driver parked in the wrong place and the city of San Francisco brought down ...

View more: Even A Tesla Cybertruck Prototype Can't Mess With San Francisco Parking Enforcement

Tesla Raises Insurance Rates For Drivers Who Use 'Track Mode' On The Track

Take "Track Mode" literally, and you get punished by Tesla's insurance algorithm.

View more: Tesla Raises Insurance Rates For Drivers Who Use 'Track Mode' On The Track

Tesla Confirms A New Model 3 Performance Is On The Way

Tesla increases Cybertruck pre-order deposit, but reverts right away

Slow Cybertruck Production Will Cost Tesla 'Blood, Sweat and Tears'

The Tesla Cybertruck Isn't Even On Sale Yet But Somehow One Got Impounded

Tesla sues Sweden’s transport agency, and gets a small win

Tesla on two wheels? India's Ola Electric feels the strains of success

I Saw The Tesla Cybertruck Up Close. My Jaw's Still On The Floor

Tesla beats US claim that it fired factory workers amid union campaign

Tesla spotted building a fleet of over 25 Cybertrucks ahead of the launch

Tesla Wins Suit Against Sweden Over Union Solidarity

Volkswagen is ‘no longer competitive,’ job cuts intensify to keep up with Tesla

Tesla Cybertruck Delivery Event Will Start Nov. 30 Around 2 P.M. EST

OTHER CAR NEWS

; Top List in the World https://www.pinterest.com/newstopcar/pins/
Top Best Sushi Restaurants in SeoulTop Best Caribbean HoneymoonsTop Most Beautiful Islands in PeruTop Best Outdoor Grill BrandsTop Best Global Seafood RestaurantsTop Foods to Boost Your Immune SystemTop Best Foods to Fight HemorrhoidsTop Foods That Pack More Potassium Than a BananaTop Best Healthy Foods to Gain Weight FastTop Best Cosmetic Brands in the U.STop Best Destinations for Food Lovers in EuropeTop Best Foods High in Vitamin ATop Best Foods to Lower Your Blood SugarTop Best Things to Do in LouisianaTop Best Cities to Visit in New YorkTop Best Makeup Addresses In PennsylvaniaTop Reasons to Visit NorwayTop Most Beautiful Islands In The WorldTop Best Law Universities in the WorldTop Richest Sportsmen In The WorldTop Biggest Aquariums In The WorldTop Best Peruvian Restaurants In MiamiTop Best Road Trips From MiamiTop Best Places to Visit in MarylandTop Best Places to Visit in North CarolinaTop Best Electric Cars For KidsTop Best Swedish Brands in The USTop Best Skincare Brands in AmericaTop Best American Lipstick BrandsTop Michelin-starred Restaurants in MiamiTop Best Secluded Getaways From MiamiTop Best Things To Do On A Rainy Day In MiamiTop Most Instagrammable Places In MiamiTop Interesting Facts about FlorenceTop Facts About The First Roman Emperor - AugustusTop Best Japanese FoodsTop Most Beautiful Historical Sites in IsraelTop Best Places To Visit In Holy SeeTop Best Hawaiian IslandsTop Reasons to Visit PortugalTop Best Hotels In L.A. With Free Wi-FiTop Best Scenic Drives in MiamiTop Best Vegan Restaurants in BerlinTop Most Interesting Attractions In WalesTop Health Benefits of a Vegan DietTop Best Thai Restaurant in Las VegasTop Most Beautiful Forests in SwitzerlandTop Best Global Universities in GermanyTop Most Beautiful Lakes in GuyanaTop Best Things To Do in IdahoTop Things to Know Before Traveling to North MacedoniaTop Best German Sunglasses BrandsTop Highest Mountains In FranceTop Biggest Hydroelectric Plants in AmericaTop Best Spa Hotels in NYCTop The World's Scariest BridgeTop Largest Hotels In AmericaTop Most Famous Festivals in JordanTop Best European Restaurants in MunichTop Best Japanese Hiking Boot BrandsTop Best Universities in PolandTop Best Tips for Surfing the Web Safely and AnonymouslyTop Most Valuable Football Clubs in EuropeTop Highest Mountains In ColombiaTop Real-Life Characters of Texas RisingTop Best Beaches in GuatelamaTop Things About DR Congo You Should KnowTop Best Korean Reality & Variety ShowsTop Best RockstarsTop Most Beautiful Waterfalls in GermanyTop Best Fountain Pen Ink BrandsTop Best European Restaurants in ChicagoTop Best Fighter Jets in the WorldTop Best Three-Wheel MotorcyclesTop Most Beautiful Lakes in ManitobaTop Best Dive Sites in VenezuelaTop Best Websites For Art StudentsTop Best Japanese Instant Noodle BrandsTop Best Comedy Manhwa (Webtoons)Top Best Japanese Sunglasses BrandsTop Most Expensive Air Jordan SneakersTop Health Benefits of CucumberTop Famous Universities in SwedenTop Most Popular Films Starring Jo Jung-sukTop Interesting Facts about CougarsTop Best Hospitals for Hip Replacement in the USATop Most Expensive DefendersTop Health Benefits of GooseberriesTop Health Benefits of ParsnipsTop Best Foods and Drinks in LondonTop Health Benefits of Rosehip TeaTop Best Air Fryers for Low-fat CookingTop Most Asked Teacher Interview Questions with AnswersTop Best Shopping Malls in ZurichTop The Most Beautiful Botanical Gardens In L.A.Top Best Mexican Restaurants in Miami for Carb-loading rightTop Best Energy Companies in GermanyTop Best Garage HeatersTop Largest Banks in IrelandTop Leading Provider - Audit and Assurance In The USTop Best Jewelry Brands in IndiaTop Prettiest Streets in the UKTop Best Lakes to Visit in TunisiaTop Highest Mountains in Israel