Web to Wheels: Tesla Password Insecurity Exposes Cars, Drivers
ID: f93b3fe2-cb97-5b0c-8627-66a880819cd8
STIX ID: report--f93b3fe2-cb97-5b0c-8627-66a880819cd8
Feed Name: Security Ledger
Research presented at Black Hat Asia found that Tesla Model S relies on a weak six-character PIN and allows unlimited password retries in its mobile app and website, enabling brute-force compromise; additionally, web vulnerabilities, exposed third-party API credentials, and potential social-engineering of support staff could let attackers track vehicles and control remote functions (lock/unlock), though driving theft is unlikely without the key fob. The researcher recommends stronger authentication (longer passwords or MFA) and sandboxing third-party apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
