Security Risks Exposed after Berlin Researchers Uncover 'Elon Mode' in Teslas During Live Stream

Glitch Revealed in Live Stream Not a Tesla App
Glitch Revealed in Live Stream
Kevin Armstrong

In a recent live stream event, a group of cybersecurity researchers from Technische Universität Berlin, under their doctoral program, demonstrated a successful hack into Tesla's Autopilot system, revealing security vulnerabilities in the vehicles. This hack, which closely mirrors their previous exploit in 2023, not only granted them access to the car's internal hardware but also confirmed that "Elon mode" is still available in recent firmware updates.

All About the Hack

Utilizing equipment costing roughly $600, the researchers induced a brief but critical 2-second voltage drop of 560 millivolts on Tesla’s ARM64-based Autopilot circuit board. This strategic interference allowed them to gain root access, extract cryptographic keys, and access vital system components. They recovered previously deleted data, including a video with GPS coordinates. This same technique also unlocked the elusive "Elon mode,” we’ve heard about before.

“Elon mode," first discovered by @greentheonly in June 2023, enables Tesla vehicles to operate in full self-driving mode without driver input or monitoring. The TU Berlin team suggests that exploiting this mode could also allow users to enable some premium features free of charge and disabling certain safety features.

Feasibility and Limitations

Acknowledging that such a hack requires physical access to the circuit board, the researchers emphasize its impracticality outside a lab setting. However, the fact that it is achievable, even with intricate steps like soldering and careful handling, underscores a looming threat to Tesla's intellectual property.

The revelation of "Elon mode" and the possibility of enabling premium features without cost raises important ethical questions about vulnerability disclosure. The researchers' decision to publicly share their findings, especially without a response from Tesla, opens up a debate on the responsibilities and ethics of cybersecurity research.

Tesla sponsors the Pwn2Own event, offering cash prizes and cars to white-hat hackers who could uncover vehicle security vulnerabilities. The company uses the information to improve its systems, however it appears Tesla has not talked to the hackers that exposed this vulnerability.

Previous Security Glitches

This incident isn't Tesla's first encounter with security vulnerabilities. Earlier reports have cited instances like an insider leak compromising employee credentials and a Bluetooth relay attack on Tesla Model 3 & Y, exposing in-car purchasable features. These incidents highlight ongoing challenges in Tesla's cybersecurity framework.

While the practicality of replicating this hack outside a controlled environment, such as manipulating a parked Tesla, is low, the discovery has significant implications. It exposes gaps in the Autopilot system and raises some safety concerns.

Tesla, informed of these findings and yet to respond publicly, must address these vulnerabilities. The TU Berlin team aims to illuminate the safety architecture of Tesla and the potential gaps in its system, with their presentation highlighting the persistent risk of accidents despite advanced cameras and machine learning models.