• Welcome to F150Lightningforum.com everyone!

    If you're joining us from F150gen14.com, then you may already have an account here!

    If you were registered on F150gen14.com as of April 16, 2022 or earlier, then you can simply login here with the same username and password!

Sponsored

This Is How Easy It Is to Hack EV Chargers | WSJ

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
64
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
It's a little sensationalized, but interesting none the less. Makes me want to take apart my FCSP and poke around.

Sponsored

 

Maxx

Well-known member
Joined
Jul 15, 2021
Threads
35
Messages
1,654
Reaction score
1,849
Location
MD
Vehicles
23 Pro, Sky RL, Frontier, Aurora V8, Buicks, ....
My charger is usually connected to the truck when it is charging so I doubt it could be used to bring the grid down.

I was not a fan of a connected charger but the deal was too good to pass.
 

Newton

Well-known member
Joined
May 27, 2021
Threads
5
Messages
184
Reaction score
245
Location
WA State
Vehicles
VW e-Golf, Lariat SR, Kia EV6, Toyota T-100
Although I don’t really like smart chargers this is just alarmist and they intentionally conflate home EVSEs and DC fast chargers. It would be really hard to hurt the EV because the logic is done in the car, not the charger.
At the nation state level knowing a zero day bug in both the EVSE and the car could let you do … something perhaps but the protocol between car and EVSE is pretty narrow which means opportunities for exploits are low. I’d attack the “Over air updates” instead. Rivian bricked a few cars with a bad one.

If you worry about your EVSE you should be petrified of your refrigerator.

My clipper creek is hacker proof.
 
OP
OP

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
64
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
Although I don’t really like smart chargers this is just alarmist and they intentionally conflate home EVSEs and DC fast chargers. It would be really hard to hurt the EV because the logic is done in the car, not the charger.
At the nation state level knowing a zero day bug in both the EVSE and the car could let you do … something perhaps but the protocol between car and EVSE is pretty narrow which means opportunities for exploits are low. I’d attack the “Over air updates” instead. Rivian bricked a few cars with a bad one.

If you worry about your EVSE you should be petrified of your refrigerator.

My clipper creek is hacker proof.
Yeah their link to infrastructure was a little flimsy and that's why I was saying it was a bit sensationalized. I was thinking the same thing when they were talking about power surges. If a car is fully charged or can't handle a higher rate, I'm not sure if that's something the charger can override?

I think the practical implications for the average person comes back to privacy concerns, how much data is collected by a charger, and if individuals are concerned with that data being possibly accessible by others.
 

Sponsored

bmwhitetx

Well-known member
First Name
Bruce
Joined
May 21, 2021
Threads
32
Messages
1,146
Reaction score
1,608
Location
DFW-Texas
Vehicles
2022 F150 Lightning Lariat ER
Occupation
Retired engineer
Just more meat for certain national news outlets to bash EVs. I’m sure my mother-in-law will inform me of this big issue the next time I see her. :rolleyes:

I don’t click on these vids anymore, they’re a waste of time. But appreciate the heads up from those that do. Then I click ignore thread ;).
 

VTbuckeye

Well-known member
First Name
Joseph
Joined
Jan 15, 2022
Threads
3
Messages
861
Reaction score
833
Location
Vermont
Vehicles
19 Bolt, 16 XC90T8, 22 XC40 P8 Recharge, 17 Tacoma
Is there a way to hack the evse to force the car to accept more power than it is asking for? Can a dcfc tell the car, too bad, you only want 50kW, but I'm giving you 250kW? I am unaware of those possibilities. It would suck to have your car charging and then have something happen (malicious or otherwise) and have the charging stop but if all of a sudden EA or Tesla had all of their dcfc stop I doubt the grid would be adversely affected. It is probably a bigger concern that a hacker (large terrorist organization or state sponsor) would do something to be corrupt/kill the grid, but it isn't going to done by turning on every evse all at once. And on top of that the affected units need to be plugged into a vehicle that is capable of receiving a charge (if your set to charge to 90 and the car is already at 90, the evse isn't going to force more energy into the battery).
Seems like this guy is coming up with a solution in search of a problem, well not even a solution, just a problem that doesn't really exist.
 

Amps

Well-known member
Joined
Feb 21, 2022
Threads
5
Messages
1,295
Reaction score
1,425
Location
Mid-Atlantic
Vehicles
Bolt
Just more meat for certain national news outlets to bash EVs. I’m sure my mother-in-law will inform me of this big issue the next time I see her.
No coincidence that WSJ is run by the same Australian billionaire family. :whistle:
 

MickeyAO

Well-known member
First Name
Mickey
Joined
Apr 2, 2020
Threads
22
Messages
1,009
Reaction score
1,852
Location
San Antonio Tx
Vehicles
Rapid Red Lightning Lariat ER, Kia EV6 GT-Line AWD
Occupation
Lab Manager of the Energy Storage Technology Center
Is there a way to hack the evse to force the car to accept more power than it is asking for? Can a dcfc tell the car, too bad, you only want 50kW, but I'm giving you 250kW? I am unaware of those possibilities. It would suck to have your car charging and then have something happen (malicious or otherwise) and have the charging stop but if all of a sudden EA or Tesla had all of their dcfc stop I doubt the grid would be adversely affected. It is probably a bigger concern that a hacker (large terrorist organization or state sponsor) would do something to be corrupt/kill the grid, but it isn't going to done by turning on every evse all at once. And on top of that the affected units need to be plugged into a vehicle that is capable of receiving a charge (if your set to charge to 90 and the car is already at 90, the evse isn't going to force more energy into the battery).
Seems like this guy is coming up with a solution in search of a problem, well not even a solution, just a problem that doesn't really exist.
Actually, this has been done and there is a thread on this forum. Once you find it, here is a little of the backstory ;)

A while back I was giving a tour of my lab to some cybersecurity guys from another division at the Institute. These are the guys that get hired to penetrate systems. I mentioned that if I was going to design an attack, I would go after the charging..I was thinking along the lines of a virus that would spread to EVSE and vehicles.

They got funded for an internal research project and went with a man in the middle attack (my name is also listed on the IR). You will want to find the thread for the details of what all they managed to do.

This was on a Level 2 EVSE...we are waiting to hear if we get funded for a DCFC attack.
 
OP
OP

reffahcs

Well-known member
First Name
Tim
Joined
Jan 28, 2024
Threads
2
Messages
62
Reaction score
64
Location
Tampa, FL
Vehicles
Ford F-150 Lightning
Actually, this has been done and there is a thread on this forum. Once you find it, here is a little of the backstory ;)

A while back I was giving a tour of my lab to some cybersecurity guys from another division at the Institute. These are the guys that get hired to penetrate systems. I mentioned that if I was going to design an attack, I would go after the charging..I was thinking along the lines of a virus that would spread to EVSE and vehicles.

They got funded for an internal research project and went with a man in the middle attack (my name is also listed on the IR). You will want to find the thread for the details of what all they managed to do.

This was on a Level 2 EVSE...we are waiting to hear if we get funded for a DCFC attack.
Thanks for that note. I was able to find the article on SwRI's public site. Is the report available for public release? I work in cyber security for a not-for-profit and was wondering if you'd be able to send me the report if I pm you my work email?
 

MickeyAO

Well-known member
First Name
Mickey
Joined
Apr 2, 2020
Threads
22
Messages
1,009
Reaction score
1,852
Location
San Antonio Tx
Vehicles
Rapid Red Lightning Lariat ER, Kia EV6 GT-Line AWD
Occupation
Lab Manager of the Energy Storage Technology Center
Thanks for that note. I was able to find the article on SwRI's public site. Is the report available for public release? I work in cyber security for a not-for-profit and was wondering if you'd be able to send me the report if I pm you my work email?
Sorry, that report is owned by another division and while I got a copy of the final report, I cannot send it. There are contact points in the press release that you might try to get a copy.
Sponsored

 


 


Top