zzdcar
Home
/
Reviews
/
Tech
/
Researcher Discovers That Old Tesla Media Control Units Are Full Of Owner's Private Data Even After A Factory Reset
Researcher Discovers That Old Tesla Media Control Units Are Full Of Owner's Private Data Even After A Factory Reset-July 2024
2024-02-19 EST 22:10:32

Image for article titled Researcher Discovers That Old Tesla Media Control Units Are Full Of Owner's Private Data Even After A Factory Reset

There’s a hacker/security researcher with the that has been doing some interesting work with used Tesla parts. This time specifically, he’s acquired three Tesla Model 3 integrated media control units (MCU) and Autopilot (HW) units (known as the ICE computer, just for Models 3 and Y), and a Model X MCU unit. These were purchased off eBay, and despite having been reset, Green found that plenty of private owner information and passwords were still easily recoverable from the units.

Green took his , and gave them more information about how he acquired the units:

Prices on eBay for these units started to drop from more than $500 to $300 then $200 then $150 and so on, so more and more people started to buy them for research. They are useless in car repairs because there’s no easy way to use them in other cars. Since you need specialized knowledge to get started, some of those people turned to me and other ‘hackers’ to help them get started. Some units were sent to me to extract data out of them to bootstrap some research too. This is when I became aware of the data leakage happening. I then purchased a unit on eBay to confirm it works exactly like that. And it sure does.

Image for article titled Researcher Discovers That Old Tesla Media Control Units Are Full Of Owner's Private Data Even After A Factory Reset

There’s a number of reasons why Tesla owners may need to replace these units: if you’re adding on Autopilot to an existing car, for example, some early models had data-logging issues that caused failure after a few years, and various other wear-and-tear and failure issues.

Once he had the units, Green found that there was a surprising amount of data still on them, from what appear to be debugging screenshots taken every time a Model 3 starts up:

...to far more compromising data, which he described to InsideEVs:

“...owner’s home and work location, all saved wi-fi passwords, calendar entries from the phone, call lists and address books from paired phones, Netflix and other stored session cookies.”

That’s a security hole big enough to drive a Model X through, even with the Falcon Doors stuck open. And, speaking of the Model X, the unit he got from that model was physically crushed, but data was still recoverable.

Green gave more details on his Twitter feed, clarifying that the Spotify passwords are stored as plain text, and that the Netflix and Gmail passwords are stored in cookie format:

The ability to get calendar events and owner’s phone book and call history are also huge security breaches, too.

When owners decide to upgrade their cars’ computer, Tesla will only let them keep their original hardware for, . Yes, it’s strange to have to pay the company to take hardware that you should have owned when you bought your car, but

One of the less-considered side effects of car features moving from hardware to software is that…

InsideEVs attempted to contact Tesla and ask them why they don’t encrypt the data, or at least destroy it before discarding the old computers, and if they have any plans to improve their practices in the future, but, unsurprisingly for those of us who have attempted to contact Tesla in the past year or so, they received no response as of press time, and, if I had to bet, they won’t.

So, the takeaway here for Tesla owners is that, I suppose, if you’re replacing your car’s computer, do not expect that any of your information will remain secure.

If you can get access to your original computer, either by angrily paying a grand to Tesla or digging it out of your service center’s dumpster, you can try to really destroy it, maybe with an acetylene welding torch or something.

Beyond that, Tesla does not appear too concerned about your privacy, and, considering they haven’t really addressed the , I wouldn’t suggest any breath-holding.

This is a very different world of car parts and repair than we’ve really encountered before. Sure, buying parts on eBay can reveal information about who had that part before you, but that’s usually limited to finding a wadded-up Taco Bell wrapper inside an old VW heat exchanger. These kinds of data vulnerabilities are serious, and Tesla needs to address them.

Comments
Welcome to zzdcar comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Tech
Truck Fans Would Rather Wait For A Toyota Tacoma EV Than Buy A F-150 Lightning Or Cybertruck
Truck Fans Would Rather Wait For A Toyota Tacoma EV Than Buy A F-150 Lightning Or Cybertruck
fans are already cooling on despite more options on the market and news of upcoming models from the likes of Chevy and Ram. The and have yet to be released, while the has recently joined the and for sale in the U.S. And, yet, all of these current and...
Jul 26, 2025
Volkswagen EVs Can Now Power Your House For Two Days (Update)
Volkswagen EVs Can Now Power Your House For Two Days (Update)
Experts have said that one of the ways to speed up EV adoption is for them to support . The ability for owners to power their house off their car or from the grid is vital. Just nine EVs on the market currently support bidirectional charging, but now VW...
Jul 26, 2025
Danish Investors Dump Tesla Shares After Elon Musk Calls Strikes In Sweden 'Insane'
Danish Investors Dump Tesla Shares After Elon Musk Calls Strikes In Sweden 'Insane'
Danish pension fund PensionDanmark is dumping all of its stock and putting the U.S. EV maker on its exclusion list of the companies it chooses to invest in – or not. The fund is selling all of its shares due to Elon Musk’s refusal to enter into labor agreements...
Jul 26, 2025
Costco Will Sell The Chevy Blazer EV At A Discount To Go With Your Rotisserie Chicken
Costco Will Sell The Chevy Blazer EV At A Discount To Go With Your Rotisserie Chicken
knows that you keep coming back for the and Kirkland brand, but you can now also buy a cheaper at your local warehouse. Chevy notified its dealers that members are eligible for a $1,000 rebate on the through January 2, according to . The discount is part of ,...
Jul 26, 2025
Biden’s First EV Charging Station Goes Online After $7.5 Billion In American EV Investments
Biden’s First EV Charging Station Goes Online After $7.5 Billion In American EV Investments
Despite in investments for the development of in the , not a single charging station had gone live thanks to — until now. The first EV charger paid for by Biden’s Bipartisan deal has come online in Ohio, according to , which marks the operational start of what the...
Jul 26, 2025
GM Says It's Dropping Apple CarPlay And Android Auto Because They're Unsafe (Update)
GM Says It's Dropping Apple CarPlay And Android Auto Because They're Unsafe (Update)
GM is still dealing with the fallout of its decision to drop Apple CarPlay and Android Auto in favor of developing its own in-house system. In the last eight months, the company has had to deal with while still maintaining its in-house system will be “.” Since neither of...
Jul 26, 2025
Copyright 2023-2025 - www.zzdcar.com All Rights Reserved