Hacker Newsnew | past | comments | ask | show | jobs | submit | robinpie's commentslogin

nope, it really is assetnote's intentional testing going to the wrong target

Yeah, I'll try to do this, but I can't find anything better than the generic contact form.

Try search on LinkedIn. Often turns up folks who work there who you can reach out to.

Oh, and be sure to include "you're scanning a pool address so you're probably scanning a lot of other sites that don't belong to your customer". They should know it's potentially not one little web site.

I'm aware how much crap there is on the Internet, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny

It does bring attention to: how many other organizations are doing this?

Tesla is a large enterprise.

They almost certainly subscribe to some overpriced SaaS garbage which is manned by offshore drones who by definition do not care because they're not paid enough to care.

Unfortunately this isn't the 80s anymore where you can ring up a system administrator at a university and get a human on the other end.

That said: cool looking website btw.


Oh absolutely, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny

Oh absolutely, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny

I thought about trying this, but MPIC makes it very very very difficult (the round-robin has some geolocation magic baked in regarding what server it connects you to).

Out of curiosity, how is MPIC relevant? Not that familiar with it, but CNAME would resolve to your server regardless no?

pool-ntp.tesla.com --CNAME--> pool.ntp.org --GeoDNS--> thousands of possible servers, biased heavily by user location

Oops should have RTFA before commenting, I thought the CNAME was only to your servers.

Yes, they should absolutely be using a vendor zone instead of a CNAME under tesla.com.

It's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf

(OOP here). I wonder if switching my replies from 299 to 200 OK would be enough for some of them.

Unlikely, but the lazy wonks could enable stratum 1 time services with the cars GPS/cellular receiver and RTC. Having done that for equipment in the past, we all know it is literary only $8.43/unit in parts. Also, setting ntp time as the tertiary fall back has been around for over a decade. =3


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: