Sunday, September 01, 2013

Tesla Model S REST API

Tesla Model S REST API Authentication Flaws - Programming - O'Reilly Media

"For the most part, people use the Tesla REST API via the iPhone and Android mobile apps. The apps enable you to do any of the following:

  • Check on the state of battery charge
  • Muck with the climate control
  • Muck with the panoramic sunroof
  • Identify where the hell your car is and what it’s doing
  • Honk the horn
  • Open the charge port
  • Change a variety of car configuration settings
  • More stuff of a similar nature"

The authentication protocol in the Tesla REST API is flawed...There’s no immediate danger from this architectural flaw that compromises the safety of the Model S...

No comments: