Sponsored

This Is How Easy It Is to Hack EV Chargers | WSJ

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
68
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
It's a little sensationalized, but interesting none the less. Makes me want to take apart my FCSP and poke around.

Sponsored

 

Maxx

Well-known member
Joined
Jul 15, 2021
Threads
41
Messages
2,058
Reaction score
2,406
Location
MD
Vehicles
23 Pro, Sky RL, Frontier, Aurora V8, Buicks, ....
My charger is usually connected to the truck when it is charging so I doubt it could be used to bring the grid down.

I was not a fan of a connected charger but the deal was too good to pass.
 

Newton

Well-known member
Joined
May 27, 2021
Threads
11
Messages
423
Reaction score
579
Location
WA State
Vehicles
VW e-Golf, 2023 Lightning Lariat SR, Kia EV6, Toyota T-100
Although I don’t really like smart chargers this is just alarmist and they intentionally conflate home EVSEs and DC fast chargers. It would be really hard to hurt the EV because the logic is done in the car, not the charger.
At the nation state level knowing a zero day bug in both the EVSE and the car could let you do … something perhaps but the protocol between car and EVSE is pretty narrow which means opportunities for exploits are low. I’d attack the “Over air updates” instead. Rivian bricked a few cars with a bad one.

If you worry about your EVSE you should be petrified of your refrigerator.

My clipper creek is hacker proof.
 
OP
OP

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
68
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
Although I don’t really like smart chargers this is just alarmist and they intentionally conflate home EVSEs and DC fast chargers. It would be really hard to hurt the EV because the logic is done in the car, not the charger.
At the nation state level knowing a zero day bug in both the EVSE and the car could let you do … something perhaps but the protocol between car and EVSE is pretty narrow which means opportunities for exploits are low. I’d attack the “Over air updates” instead. Rivian bricked a few cars with a bad one.

If you worry about your EVSE you should be petrified of your refrigerator.

My clipper creek is hacker proof.
Yeah their link to infrastructure was a little flimsy and that's why I was saying it was a bit sensationalized. I was thinking the same thing when they were talking about power surges. If a car is fully charged or can't handle a higher rate, I'm not sure if that's something the charger can override?

I think the practical implications for the average person comes back to privacy concerns, how much data is collected by a charger, and if individuals are concerned with that data being possibly accessible by others.
 

Sponsored

bmwhitetx

Well-known member
First Name
Bruce
Joined
May 21, 2021
Threads
43
Messages
2,220
Reaction score
3,093
Location
DFW-Texas
Vehicles
2022 F150 Lightning Lariat ER
Occupation
Retired engineer
Just more meat for certain national news outlets to bash EVs. I’m sure my mother-in-law will inform me of this big issue the next time I see her. :rolleyes:

I don’t click on these vids anymore, they’re a waste of time. But appreciate the heads up from those that do. Then I click ignore thread ;).
 

VTbuckeye

Well-known member
First Name
Joseph
Joined
Jan 15, 2022
Threads
5
Messages
947
Reaction score
911
Location
Vermont
Vehicles
22 Lightning Lariat ER max tow built Aug 22, 16 XC90T8, 22 XC40 P8 Recharge
Is there a way to hack the evse to force the car to accept more power than it is asking for? Can a dcfc tell the car, too bad, you only want 50kW, but I'm giving you 250kW? I am unaware of those possibilities. It would suck to have your car charging and then have something happen (malicious or otherwise) and have the charging stop but if all of a sudden EA or Tesla had all of their dcfc stop I doubt the grid would be adversely affected. It is probably a bigger concern that a hacker (large terrorist organization or state sponsor) would do something to be corrupt/kill the grid, but it isn't going to done by turning on every evse all at once. And on top of that the affected units need to be plugged into a vehicle that is capable of receiving a charge (if your set to charge to 90 and the car is already at 90, the evse isn't going to force more energy into the battery).
Seems like this guy is coming up with a solution in search of a problem, well not even a solution, just a problem that doesn't really exist.
 

Amps

Well-known member
Joined
Feb 21, 2022
Threads
5
Messages
1,336
Reaction score
1,516
Location
Mid-Atlantic
Vehicles
Bolt
Just more meat for certain national news outlets to bash EVs. I’m sure my mother-in-law will inform me of this big issue the next time I see her.
No coincidence that WSJ is run by the same Australian billionaire family. :whistle:
 

trev5150

Well-known member
First Name
Trev
Joined
Jul 23, 2022
Threads
20
Messages
507
Reaction score
323
Location
Tucson, AZ
Vehicles
2022 F-150 Lightning Lariat SR
Occupation
Pilot of pilotless things
Any “headline“ that contains “This is...” or “Here’s what…”, and “What to Know about…” is an instant skip for me. Clickbait, filler, garbage, no journalistic integrity expected or implied, and usually packing some sort of agenda. Hard pass.
 

MickeyAO

Well-known member
First Name
Mickey
Joined
Apr 2, 2020
Threads
27
Messages
1,065
Reaction score
2,133
Location
San Antonio Tx
Vehicles
Rapid Red Lightning Lariat ER, Kia EV6 GT-Line AWD
Occupation
Retired Lab Manager of the Energy Storage Technology Center
Is there a way to hack the evse to force the car to accept more power than it is asking for? Can a dcfc tell the car, too bad, you only want 50kW, but I'm giving you 250kW? I am unaware of those possibilities. It would suck to have your car charging and then have something happen (malicious or otherwise) and have the charging stop but if all of a sudden EA or Tesla had all of their dcfc stop I doubt the grid would be adversely affected. It is probably a bigger concern that a hacker (large terrorist organization or state sponsor) would do something to be corrupt/kill the grid, but it isn't going to done by turning on every evse all at once. And on top of that the affected units need to be plugged into a vehicle that is capable of receiving a charge (if your set to charge to 90 and the car is already at 90, the evse isn't going to force more energy into the battery).
Seems like this guy is coming up with a solution in search of a problem, well not even a solution, just a problem that doesn't really exist.
Actually, this has been done and there is a thread on this forum. Once you find it, here is a little of the backstory ;)

A while back I was giving a tour of my lab to some cybersecurity guys from another division at the Institute. These are the guys that get hired to penetrate systems. I mentioned that if I was going to design an attack, I would go after the charging..I was thinking along the lines of a virus that would spread to EVSE and vehicles.

They got funded for an internal research project and went with a man in the middle attack (my name is also listed on the IR). You will want to find the thread for the details of what all they managed to do.

This was on a Level 2 EVSE...we are waiting to hear if we get funded for a DCFC attack.
 

Sponsored
OP
OP

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
68
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
Actually, this has been done and there is a thread on this forum. Once you find it, here is a little of the backstory ;)

A while back I was giving a tour of my lab to some cybersecurity guys from another division at the Institute. These are the guys that get hired to penetrate systems. I mentioned that if I was going to design an attack, I would go after the charging..I was thinking along the lines of a virus that would spread to EVSE and vehicles.

They got funded for an internal research project and went with a man in the middle attack (my name is also listed on the IR). You will want to find the thread for the details of what all they managed to do.

This was on a Level 2 EVSE...we are waiting to hear if we get funded for a DCFC attack.
Thanks for that note. I was able to find the article on SwRI's public site. Is the report available for public release? I work in cyber security for a not-for-profit and was wondering if you'd be able to send me the report if I pm you my work email?
 

MickeyAO

Well-known member
First Name
Mickey
Joined
Apr 2, 2020
Threads
27
Messages
1,065
Reaction score
2,133
Location
San Antonio Tx
Vehicles
Rapid Red Lightning Lariat ER, Kia EV6 GT-Line AWD
Occupation
Retired Lab Manager of the Energy Storage Technology Center
Thanks for that note. I was able to find the article on SwRI's public site. Is the report available for public release? I work in cyber security for a not-for-profit and was wondering if you'd be able to send me the report if I pm you my work email?
Sorry, that report is owned by another division and while I got a copy of the final report, I cannot send it. There are contact points in the press release that you might try to get a copy.
Sponsored

 
 







Top