<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PAAK on trifinite.org</title>
    <link>https://trifinite.org/tags/paak/</link>
    <description>Recent content in PAAK on trifinite.org</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 03 Jan 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://trifinite.org/tags/paak/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Project TEMPA</title>
      <link>https://trifinite.org/stuff/project_tempa/</link>
      <pubDate>Tue, 03 Jan 2023 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/project_tempa/</guid>
      <description>The security of Tesla&amp;rsquo;s cars has been a hot topic in recent months. In addition to being one of the safest cars on the road, it is also well-protected from hacks and attacks. But how does Tesla make sure their vehicles are safe and secure?</description>
    </item>
    
    <item>
      <title>Tesla Authorization Extraction/Replay Attack</title>
      <link>https://trifinite.org/stuff/tempa_autorization_replay_attack/</link>
      <pubDate>Mon, 25 Jul 2022 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/tempa_autorization_replay_attack/</guid>
      <description>Note: This is related to Project TEMPA. Please follow this link for an overview!
The Tesla Authorization Replay attack is using a tool like temparary in order to extract VCSEC AuthorizationResponses from a whitelisted smartphone app. For AuthorizationRequests - that are mainly used for passive entry functions - the vehicle communicates a challenge token, that the smartphone app has to answer with an AuthorizationResponse which is embedded in a VCSEC SignedMessage object that has a SIGNATURE_TYPE_AES_GCM_TOKEN SignatureType.</description>
    </item>
    
    <item>
      <title>Tesla Crypto Counter Confusion Attack</title>
      <link>https://trifinite.org/stuff/tempa_counter_confusion_attack/</link>
      <pubDate>Mon, 25 Jul 2022 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/tempa_counter_confusion_attack/</guid>
      <description>Note: This is related to Project TEMPA. Please follow this link for an overview!
The Tesla Crypto Counter Confusion attack works by impersonating a vehicle with a tool like temparary. Once the app on the owner&amp;rsquo;s phone starts communicating to the emulated BLE interface of the impersonated car, the temparary tool will request an authorization from the phone.</description>
    </item>
    
    <item>
      <title>Tesla Key Drop Attack</title>
      <link>https://trifinite.org/stuff/tempa_keydrop_attack/</link>
      <pubDate>Wed, 29 Jun 2022 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/tempa_keydrop_attack/</guid>
      <description>Note: This is related to Project TEMPA. Please follow this link for an overview!
The Tesla Key Drop attack works by impersonating a vehicle with a tool like temparary. Once the app on the owner&amp;rsquo;s phone starts communicating to the emulated BLE interface of the impersonated car, the temparary tool will request an authorization from the phone.</description>
    </item>
    
    <item>
      <title>Tesla Authorization Timer Attack</title>
      <link>https://trifinite.org/stuff/tempa_authorization_timer_attack/</link>
      <pubDate>Sat, 04 Jun 2022 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/tempa_authorization_timer_attack/</guid>
      <description>Note: This is related to Project TEMPA. Please follow this link for an overview!
After unlocking the vehicle via NFC, Tesla allows potential attackers to store a key on the vehicle for a period of approx. 130s. No warning or similar will be displayed on the vehicle screen during this process.</description>
    </item>
    
    <item>
      <title>Tesla BLE Relay Attack</title>
      <link>https://trifinite.org/stuff/tempa_relay_attack/</link>
      <pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate>
      
      <guid>https://trifinite.org/stuff/tempa_relay_attack/</guid>
      <description>Note: This is related to Project TEMPA. Please follow this link for an overview!
Besides the ability to relay the 2.4GHz radio signal between the PhoneKey and the Tesla vehicle, it is also possible to relay information on protocol level by using standard software like gattacker.</description>
    </item>
    
  </channel>
</rss>
