Home Technology Tesla: AMD’s infotainment systems in Tesla cars can be used to bypass paid services: Report

Tesla: AMD’s infotainment systems in Tesla cars can be used to bypass paid services: Report

Tesla has recently implemented AMD-based infotainment systems in all of its latest car models. According to researchers from the Technical University of Berlin, they have successfully developed a method to hack these infotainment systems, allowing them to run any desired software. Additionally, this hack enables the extraction of the unique hardware-bound RSA key used for authentication in Tesla’s service network. Moreover, the researchers were also able to utilize this key to activate software-locked features such as seat heating and ‘Acceleration Boost’ without the need for payment.

The researchers were able to exploit the vulnerabilities of the vulnerable AMD Zen 1 CPU-based infotainment APU used in Tesla cars by using fault injection attack techniques. By using low-cost and readily available hardware, the researchers were able to successfully manipulate the early boot code and gain root access to the system. This provided them with the ability to make permanent changes and decrypt sensitive information stored in the car, including personal data like phonebooks, calendar entries, call logs, Spotify and Gmail session cookies, WiFi passwords, and visited locations.
Implications of this vulnerability for users
The jailbreak performed by the researchers allows attackers to extract the TPM-protected attestation key used by Tesla for car authentication and platform integrity verification. In addition to car ID impersonation and potential unauthorized usage, this vulnerability also poses a risk for unsupported region usage, as well as independent repairs and modding.
One of the researchers, Christian Werling, has outlined the tools required for this infotainment jailbreak, suggesting that a soldering iron and other electronics worth $100 are sufficient for the hack.

 

Reference

Denial of responsibility! TechCodex is an automatic aggregator of the all world’s media. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, and all materials to their authors. For any complaint, please reach us at – [email protected]. We will take necessary action within 24 hours.
Denial of responsibility! TechCodex is an automatic aggregator of Global media. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, and all materials to their authors. For any complaint, please reach us at – [email protected]. We will take necessary action within 24 hours.
DMCA compliant image

Leave a Comment