• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less

1

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

2

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

3

Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Techcar hacking

Tesla-Stealing Hack is about Much More than Tesla

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
November 26, 2016, 12:14 PM ET
A Tesla Motors Inc. Software Update
An instrument panel illustrates the road ahead using Autopilot technology just prior to the Tesla Motors Inc. 8.0 software update inside a Model S P90D vehicle in the Brooklyn borough of New York, U.S., on Monday, Sept. 19, 2016. The latest overhaul of the car's operating system, known as Tesla 8.0, biggest change is how Autopilot shifts towards a heavier reliance on its radar than its camera to guide the car through traffic. Photographer: Christopher Goodney/Bloomberg via Getty ImagesChristopher Goodney — Bloomberg via Getty Images
Add Fortune on Google for similar content.

An often-asserted downside of internet-connected vehicles is that they’re subject to various forms of hacking, including theft. On Wednesday, a Norwegian security company called Promon claimed to have found something like the Holy Grail of vehicle hacking—by compromising a Tesla owner’s Android phone, they could take control of Tesla’s mobile app and steal the car.

The hack relies on tricking a Tesla owner into downloading a malicious app, for instance through a spoofed public Wi-Fi hotspot that would direct them to a deceptive Google Play download. That app could then escalate permissions on the owner’s phone and corrupt the Tesla app. Attackers could then, according to Promon, communicate with the Tesla server to issue remote commands including locating the victim’s car, opening its doors, and enabling keyless driving.

Get Data Sheet, Fortune’s technology newsletter.

There are a few caveats. The specific exploit used by Promon only works on Android versions 5.1 or older—that is, phones that haven’t been updated in nearly two years. More to the point, Promon acknowledged in a followup note that “this attack is not Tesla specific, and in generalized form can be used against any app”.

Promon does point out that an authorization token used by the Tesla app was unencrypted, making the hack easier, and that a few extra measures could have protected the app even after the phone was compromised. But at bottom, the flaw highlighted by Promon was in an outdated version of Android, not in the Tesla app itself. Choosing Tesla as a target was just savvy marketing by a company selling app security tools.

What’s not clear is whether that should make anyone feel better. Moralizing experts can scold users to keep their OS updated and not click on bad links. But in the real world, around 20% of Android devices still run 2012’s Jelly Bean, largely because hardware manufacturers don’t maintain device support. And hacking through deception (“social engineering”) will probably never die—by definition, half of all people are below average at spotting scams.

For more on hacking, watch our video.

The consequences of phone hacking will get more severe as remote-control apps become more common in the Internet of Things, making it possible for both owners and hackers to control everything from cars to home locks to desktop computers. Tesla itself, alongside its recent introduction of autonomy features, has said owners will someday be able to summon their cars from across the country using their phones. Some of those phones will, simply according to the law of averages, be compromised.

Of course, connection has its benefits, too. Tesla vehicles send real-time location data to owners’ apps, which last year helped a Vancouver couple relocate their stolen S 85D. Promon’s app hack doesn’t involve shutting down the car’s GPS feed, so even if a thief were to pull it off, they might not keep their prize for long.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

GTA 6 release date is finally here—but the $80 price tag and missing disc have gamers furious
Arts & EntertainmentGaming
GTA 6 release date is finally here—but the $80 price tag and missing disc have gamers furious
By Whizy Kim and Tech BrewJune 25, 2026
36 minutes ago
stock
InvestingMarkets
How one chip stock reversed the global tech selloff, exposed AI’s ‘memory tax’ and made the case for an entire valuation regime change
By Nick LichtenbergJune 25, 2026
3 hours ago
Larry Ellison quietly gave $45 million to a pro-Trump group—then Oracle landed a starring role in a $500 billion AI buildout
PoliticsLarry Ellison
Larry Ellison quietly gave $45 million to a pro-Trump group—then Oracle landed a starring role in a $500 billion AI buildout
By Sydney LakeJune 25, 2026
4 hours ago
Sundar Pichai
SuccessCareers
Google CEO tells graduates to stop obsessing over first jobs because ‘very few moments are make or break’ in life—a lesson he learned in Vegas
By Preston ForeJune 25, 2026
5 hours ago
Softbank CEO dismisses Elon Musk’s extraterrestrial data center idea in favor of maximizing Earth-side construction now: ‘He who strikes first wins’
AITech
Softbank CEO dismisses Elon Musk’s extraterrestrial data center idea in favor of maximizing Earth-side construction now: ‘He who strikes first wins’
By Marco Quiroz-GutierrezJune 25, 2026
5 hours ago
VivaTech entrance in Paris.
NewslettersEye on AI
Europe’s AI wake-up call: cybersecurity threats, sovereignty fears, and a growing demand for ROI dominated VivaTech
By Beatrice NolanJune 25, 2026
5 hours ago

Most Popular

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
2 days ago
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
Success
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
By Sydney LakeJune 25, 2026
13 hours ago
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Retail
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
By Nick LichtenbergJune 24, 2026
1 day ago
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
Asia
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
By Nick LichtenbergJune 24, 2026
1 day ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
2 days ago
Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants
Success
Ikea’s billionaire founder was so frugal that he bought clothes from flea markets and took free salt and pepper from restaurants
By Orianna Rosa RoyleJune 25, 2026
13 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.