{"id":14032,"date":"2022-01-27T12:01:37","date_gmt":"2022-01-27T17:01:37","guid":{"rendered":"https:\/\/autosector.com\/?p=14032"},"modified":"2022-01-27T12:01:37","modified_gmt":"2022-01-27T17:01:37","slug":"tesla-hacker-finds-owners-emails","status":"publish","type":"post","link":"http:\/\/autosector.com\/?p=14032","title":{"rendered":"Tesla Hacker Is Back, Says He Can Find Owners\u2019 Emails"},"content":{"rendered":"<p>You may remember that last week we covered a story about a young cybersecurity researcher and hacker who announced that he had <a href=\"https:\/\/insideevs.com\/news\/560350\/hacker-full-control-25-teslas\/\" data-inline-widget=\"internal-links\" data-type-id=\"0\" data-params=\"%7B%22article_edition_id%22%3A%22560350%22%2C%22section%22%3A%221%22%2C%22alias%22%3A%22hacker-full-control-25-teslas%22%7D\">gained control of two dozen Tesla vehicles<\/a>. He was able to do it by using APIs (application programming interfaces, which is basically software that allows applications to communicate) and now he says he can learn owners\u2019 emails by using the same technique.<\/p>\n<p>With the first vulnerability that he uncovered, David Colombo waited to be contacted by <a href=\"https:\/\/insideevs.com\/tesla\/\" data-inline-widget=\"internal-links\" data-type-id=\"2\" data-params=\"%7B%22alias%22%3A%22tesla%22%7D\">Tesla<\/a> after posting his findings on Twitter. He eventually was contacted by the manufacturer, although we don\u2019t know if he had already found a way to see the emails when talking to Tesla.<\/p>\n<p>According to <em>Automotive News<\/em>,<\/p>\n<blockquote readability=\"11\">\n<p>Colombo said the defect was in a Tesla application programming interface, or API. After he publicized his first discovery, a Twitter user suggested contact details for the affected owners could be found in the code that allows two pieces of software to communicate with each other, also known as an API endpoint.<\/p>\n<\/blockquote>\n<p>The hacker, who is 19 years-old and lives in the small historic German town of Dinkelsb\u00fchl, told <em>Bloomberg<\/em> that<\/p>\n<blockquote readability=\"11\">\n<p>Once I was able to figure out the endpoint, I was indeed able to carry the email address associated with the Tesla API key, the digital car key.<\/p>\n<p>You shouldn&#8217;t be able to carry sensitive information like an email address using an access that is already expired or revoked.<\/p>\n<\/blockquote>\n<p>Now he says he is waiting to receive \u2018a big bounty\u2019 from Tesla for notifying the manufacturer about these vulnerabilities, although the source says this has not been agreed upon yet. Back in 2020, Tesla announced it was offering $1-million and a free car to security researches who found bugs in its systems, which is surely what got David Colombo interested in the first place.<\/p>\n<section class=\"relatedContent-new\" contenteditable=\"false\" draggable=\"true\" data-widget=\"related-content\" data-widget-size=\"content\" data-params=\"%7B%22type_id%22%3A0%2C%22title_id%22%3A%22%22%2C%22items%22%3A%5B%7B%22article_edition_id%22%3A%22563576%22%2C%22title%22%3A%22Joe%20Rogan%20Reportedly%20Takes%20Tesla%20Cybertruck%20For%20A%20Quick%20Drive%22%2C%22alias%22%3A%22joe-rogan-drives-tesla-cybertruck%22%2C%22section%22%3A%221%22%2C%22is_video%22%3A%220%22%2C%22images%22%3A%7B%22s5%22%3A%22https%3A%2F%2Fcdn.motor1.com%2Fimages%2Fmgl%2Foj1ZK0%2Fs5%2Ftesla-cybertruck-joe-rogan.jpg%22%7D%7D%2C%7B%22article_edition_id%22%3A%22563578%22%2C%22title%22%3A%22Tesla%20Model%20Y%20UK%20Deliveries%20Will%20Reportedly%20Start%20In%20February%22%2C%22alias%22%3A%22tesla-modely-uk-deliveries-february%22%2C%22section%22%3A%221%22%2C%22is_video%22%3A%220%22%2C%22images%22%3A%7B%22s5%22%3A%22https%3A%2F%2Fcdn.motor1.com%2Fimages%2Fmgl%2FQeWXzN%2Fs5%2Ftesla-model-y-performance-mic-in-china---november-2021.jpg%22%7D%7D%5D%7D\">   <\/section>\n<section contenteditable=\"false\" draggable=\"true\" data-widget=\"video_mstv\"><img decoding=\"async\" class=\"sizer\" draggable=\"false\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAJCAYAAAA7KqwyAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAABpJREFUeNpi\/P\/\/PwMlgImBQjBqwLAwACDAAOVfAw9\/ZDvcAAAAAElFTkSuQmCC\" alt=\"\"\/>  <\/section>\n","protected":false},"excerpt":{"rendered":"<p>You may remember that last week we covered a story about a young cybersecurity researcher and hacker who announced that he had gained control of two dozen Tesla vehicles. He was able to do it by using APIs (application programming interfaces, which is basically software that allows applications to communicate) and now he says he [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8313,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[],"class_list":["post-14032","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-e-cars"],"_links":{"self":[{"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/posts\/14032","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/autosector.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14032"}],"version-history":[{"count":0,"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/posts\/14032\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/autosector.com\/index.php?rest_route=\/wp\/v2\/media\/8313"}],"wp:attachment":[{"href":"http:\/\/autosector.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14032"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/autosector.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14032"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/autosector.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14032"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}