Powerwall Network Activity

Sdílet
Vložit
  • čas přidán 6. 08. 2024
  • Looking at the network activity of the Tesla Powerwall. Also a bit of an insight as to how the fault finding and resolution process of that company operates.
    curl -k -O -c cookies.txt -X POST powerwall/api/login/Basic -H "Content-Type: application/json" -d "{\"username\": \"customer\",\"email\": \"your.login@mail.address\",\"password\": \"PASSWORD\"}"
    curl -k -O -b cookies.txt powerwall/api/meters/aggregates
  • Věda a technologie

Komentáře • 95

  • @frankcellini9363
    @frankcellini9363 Před 8 měsíci +4

    Tesla probably wants to monitor its equipment and see if there is any way to improve the gear in future. I largely agree with you, the systems can be improved and I think Elon wold be open to improvements. Elon is a single minded kind of guy who powers ahead with all the amazing stuff he is doing with cars, space X, Star-link, robots. If it wasn't for him dragging us all into the 21st century, we'd be stuck in the mire of bureaucracy getting nowhere at the speed of light. Human history needs Elon types every now and then, to take society forwards. Look at governments and bureaucracy around the world, we have never been in a worst situation! Look at NASA, once was achieving a lot , now stagnating. Look at OPTUS, QANTAS all top heavy orgs with people on MASSIVE salary packages ad they have forgotten what they are supposed to be doing for Australians. Your videos are very interesting.

  • @burneternally
    @burneternally Před 23 dny +1

    Great packet analysis and API poking. Please keep doing these type of videos.

  • @cakesoup
    @cakesoup Před 8 měsíci +6

    😂 Spot on folder name for the *.pem files !!!

  • @MikoKnight
    @MikoKnight Před 8 měsíci +1

    Thanks for these videos. Love the no bullshit approach.

  • @tobmaster1985
    @tobmaster1985 Před 8 měsíci +5

    Looking forward to a teardown / inspection of the old powerwall computer ;)

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      They took that with them.

    • @tobmaster1985
      @tobmaster1985 Před 8 měsíci +2

      @@TallPaulTech oh ok, then I misunderstood that part. I thought the device you showed was the computer from the powerwall.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      No, it's the power meter from the previous unit.

  • @jcxtra
    @jcxtra Před 8 měsíci +2

    I'm glad we have smart folk out there that can figure out how to make most of this stuff offline. I've never been a fan of things 'dialing home'... since that assumes that the internet is perfect, the company will always exist, there won't be things that break....
    Also I love the folder you have for us. I saw your message about local cultures and censorship a while back and definitely don't want you to stop being yourself.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Oh, the CZcams me is only half of me. For the full uncensored version, you'll have to be at the yearly meetup.

    • @jcxtra
      @jcxtra Před 8 měsíci +1

      @@TallPaulTech Might be a bit of a distance problem with that ;)

  • @owenschwartz
    @owenschwartz Před 8 měsíci +1

    Just found your channel and your videos are so educational and entertaining. Please keep up the amazing work!

  • @davidd6599
    @davidd6599 Před 8 měsíci +2

    Hey Paul,
    I wanted to point out the x509-Extension: Basic Constraints: CA-FALSE doesn't mean that there's no Certificate Authority present its just there to prevent this certificate to be used for signing other NEW certificates. That way you can prevent a hacker (who maybe received a real Certificate for 1 specific purpose) from just creating new certificates in a certificate chain that will be valid when going up the chain. The Extension CA-TRUE is only present in Root-CA or intermiediate CA's that actually sign new certificates.
    Correct me if i'm wrong :)

    • @davidd6599
      @davidd6599 Před 8 měsíci +2

      The unknown-issuer error youre getting is like just that the cert-chain cannot be completed. So it seems that other certificates like the root ca are missing on the device. I don't know how much that error changes if the certificates in the chain are just expired. There could be any other explainaiton to that just as the OS removing invalid certificates for some storage.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Yeah you're right, I realised later. I just whipped up that video mainly to point out the validity period of what it used to be to what it is now.

  • @hdwill
    @hdwill Před 8 měsíci +1

    I REALLY enjoyed the whole tesla network activity saga. Great analysis and great insight into how some bigcorps network managment can be. Thx

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      Only one more to go on the weekend, then I'll be done with the shit and back to normal videos.

  • @accesser
    @accesser Před 8 měsíci +2

    I enjoy this style, great video

  • @Mcfryguy5555
    @Mcfryguy5555 Před 8 měsíci +1

    Great video, nice find!

  • @LukePWilkinsVids
    @LukePWilkinsVids Před 8 měsíci +1

    Love your videos!

  • @JimNichols
    @JimNichols Před 8 měsíci +2

    Of course you know that it is data they are after, Tesla like all the others use the data in the creation of their products and sell the rights to the metadata. I almost think that Tesla would give their cars away if you agreed to keep a cellular contract open just for the real world driving data mining that they do.
    I like your videos, the videography, the scripting and the edits are spot on. Even though you are one crusty, salty, angry at the world guy you do know your stuff...The networking and language knowledge you have is impressive.. thanks for the videos.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      Damn, you're onto me. Is it coming through that strongly?!

    • @Tschacki_Quacki
      @Tschacki_Quacki Před 8 měsíci

      2/10 conspiracy theory
      Tesla would benefit the competiton if they would sell their user data. You even mention the importance of that data yourself.
      Tesla isn't selling user data.

  • @Kiddio
    @Kiddio Před 8 měsíci +1

    You should take a look at Rich Rebuilds. He has very much the same opinion on Tesla as you do and documented his experience of owning a Tesla for years that he self-serviced and worked on.
    He rebuilt the vehicle after a flood and went through a series of buying other flooded Tesla’s to try and salvage the parts for his own one because they wouldn’t give him the access he needed to buy those parts himself.
    He’s a major advocate for right to repair.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Of course I've heard of him. Who hasn't? Yes, he and many others have the same opinion of me. He has a much bigger audience too.

  • @FRITTY12348546
    @FRITTY12348546 Před 8 měsíci +1

    thanks Paul great episode and insight

  • @e74av
    @e74av Před 8 měsíci +1

    That's one of the reasons Smart Home devices are confusing people in general. It's like "remote switches" and everything else, though technically possible, due to "corporate isolation" policies is being presented in a way which eventually ends up with poor security and unnecessarily complex systems.
    It's hard for users, hard for companies to develop and extremely hard to integrate things.
    HA community is doing great job but we all know it's not how it's supposed to be for equipment and services side.
    So, we get interesting and affordable Amazon devices which mostly don't work right with amazon's alexa app. Designed in a very wrong way... All because some manager thought tha such a device should be used to "sell more amazon goods". "The guy/team" simply has no clue how to approach new IOT era and how to expand services. They prefer supporting what they already have.
    Sadly.
    Thnx for the vid. Great one.

  • @jdloop
    @jdloop Před 8 měsíci +3

    Am in awe of your wireshark/etc capabilities, esp placing the pi4 as your router and accessing it to do all the linux magic. Have you ever considered making an image of that pi4 available for general use [with instructions as to how to customize it for individual use of course]. I could ..almost.. do this, but you have already done it for NAT/IPv6/DHCP/vlan/etc/etc. Easy to make an image available and post it on sourceforge. I have don it for my own projject.

  • @wva5089
    @wva5089 Před 8 měsíci +2

    Love to see a mitm session of this..

  • @gunnargu
    @gunnargu Před 8 měsíci +8

    the basic constraints CA:FALSE means that this cert cannot be used as a CA, not that there _is no_ ca.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +4

      Ah okay

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +7

      I keep trying to tell people that I'm just some cunt with a camera and a youtube account, but for some reason they keep coming here!

    • @klaernie
      @klaernie Před 8 měsíci +4

      Well, that particular cunt has dug his head way too deep into shit to not understand it, hence knows more than the other cunts that didn't eat that much shit yet ;)

  • @2Fast4Mellow
    @2Fast4Mellow Před 8 měsíci +3

    Actually the reason why the replace a complete component instead of just updating it, is that sometimes they have hardware with newer revisions.
    Also training service desk personal how they can update an obsolete firmware is far more costly that just replace the damn thing. The fact that the left the comm device with you tells me that it is of an older generation. Normally they just give the client a new box, take the old one with them, back at the depot they check if they can revive the old box and they can service it to another customer...
    It is the same with ISP modems/routers. Once the issue is not covered by an agent script, they just replace your box, because that is much cheaper and often you get newer hardware and often have better/faster WiFi even if those AP can handle just 3 or 4 devices anyway. I have a fiber connection and running my own hardware (UDM) and I just asked my provider for the PPPoE credentials, but if I don't get it to work, they don't provide any support unless I connect their router box, which I think is fair...

  • @Callofdootie
    @Callofdootie Před 8 měsíci +2

    I have no idea what you are saying 60% of the time but I enjoy the content.

  • @roadkisserful
    @roadkisserful Před 8 měsíci +1

    Thankyou always big brother is watching :-)

  • @-someone-.
    @-someone-. Před 8 měsíci +2

    Hey off topic, but I wanted to make use of a spare raspi, and test out a SIEM..., wazuh. Have you played with this? I have an 8gb pi4. Do you recommend a different SIEM tool for the raspi?
    Cheers Paul👍

  • @hgbugalou
    @hgbugalou Před 8 měsíci +2

    Elon has the power walls running Twitter bots now I see. 😂

  • @TheMostOrdinaryPersonOnEarth
    @TheMostOrdinaryPersonOnEarth Před 8 měsíci +2

    I was going to post something like "just run up a CA in your DNS and point that getcert URL to it" - But then I realised that it's the modern era, I bet this stupidly unsecure device needs security updates at some point :( So far i've resisted everything that needs an internet connection but I know my resistance is futile in the end.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Come on man, don't settle for this as the new way of life!

  • @gunnargu
    @gunnargu Před 8 měsíci +2

    the powerwall hostname probably works via mDNS

  • @maxmyzer9172
    @maxmyzer9172 Před 8 měsíci +4

    7:12 hmm window text

  • @jaimeb5550
    @jaimeb5550 Před 8 měsíci +1

    Out of interest... Apart from the outbound telemetry, is there anything that is exploitable on these batteries interfaces?... Getting solar on Tuesday, decided its probably time to actually start isolating my devices...😅

  • @Stroid9
    @Stroid9 Před 8 měsíci +1

    Interesting video! How are you performing the package capture? i know that you are using wireshark but are you running ws on your router? Would like to do analyse the activity of my robot vaccume..

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      Is that like a vacuum? I run tcpdump on the router, and pipe it to wireshark locally.

    • @Stroid9
      @Stroid9 Před 8 měsíci

      @@TallPaulTech yes sorry, I meant Robot Vacuum. Thanks!

  • @ReubenHorner
    @ReubenHorner Před 8 měsíci +3

    What happens if you disable internet acces for it but continue to get HA to get data

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +4

      It goes fine... that's what I was doing for a long time. It was only when it fucked up for some reason that I had to (try to) put it back online. That was a few years ago now. As I've said in previous videos though, if it has no internet connection for 24 hours, it reboots, unless it's off-grid.

    • @xandrios
      @xandrios Před 8 měsíci +1

      @@TallPaulTechHow does it know that it’s off grid? Purely based on certain power feeds…or that is a setting made by the guys installing the device? Sounds like something we should be able to change. Even when not off grid I may be without internet and wouldn’t want the power wall to reset daily..

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      Well it's connected with the grid, so if the grid vanishes, it knows.

    • @michaelknight2342
      @michaelknight2342 Před 8 měsíci

      @@TallPaulTech Does it still reboot if it's getting the am-i-online file from your local network? Also, does aluminium foil work as a crappy faraday cage for the cellular modem?

  • @SminkyBazzA
    @SminkyBazzA Před 8 měsíci +1

    I'm currently in the same situation you were with the TEG not talking to Tesla because a previous owner didn't bother connecting it to the internet. But can I get an engineer to come and replace it? No chance, they only want to do full installations.
    Do you think there's any chance I could manually update the cert via SSH if someone were kind enough to provide me one? I don't know if anyone ever figured out the creds.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      I'd say you're fucked then... welcome to Tesla crap, and the way of the future.

    • @SminkyBazzA
      @SminkyBazzA Před 8 měsíci +1

      @@TallPaulTech Indeed. I can't get Tesla Support to say those words, though I keep trying! Thanks for the vid, great stuff

  • @68HC060
    @68HC060 Před 8 měsíci +2

    Stuff that need a network connection to work, I don't want. 😉
    -That includes software, especially software you need to enter a code for every third month in order to use it.
    I had games that I needed to enter a code for every time I installed them, the companies that sold the games no longer exist, so I'm stuck with a bunch of games I can't play. 😥

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Sonic The Hedgehog still works without a login :)

    • @PascalxSome
      @PascalxSome Před 8 měsíci +1

      Yeah like what would happen to your $100.000 Car if the company goes bankrupt? Can't drive it because it can't connect to the services? F that. We're on the way to such. What if Steam closes, who actually still has access to his or her games? Consumer Laws are made wayyy to slow, regarding how fast innovation and technologie changes.

    • @68HC060
      @68HC060 Před 8 měsíci +1

      🤣@@TallPaulTech - Otherwise just play an open-source version. 😉
      -Sadly software piracy made it necessary for companies like AmbrosiaSW to put codes on Deimos Rising and Escape Velocity Nova (two of my favorite games) - it's still possible for me to install those even though they require codes, because I can set the date back 20 years and use my original install codes.

    • @68HC060
      @68HC060 Před 8 měsíci +1

      ​@@PascalxSome - On the other hand, if the police can just tell a drunk-driver's car to stop, then a lot of lives could be saved.
      -But I'm still against any kind of control of things I own (so ... I use no Microsoft products in my home).
      Sometimes I really miss...
      "R: Tape loading error" ...

    • @Tschacki_Quacki
      @Tschacki_Quacki Před 8 měsíci +1

      @@PascalxSome Nothing happens to your car when the manufacturer goes bankrupt.
      How come you can still use your phone or your computer when they are not connected to the services?
      If Steam closes, your game library is screwed and you have to renew it somehow if you want to. I think this would be a gigantic business opportunity and someone would have quickly got you covered.
      We have to do this with media from time to time and things unfortunately get lost. Not every LP ever recorded made it to MP3. Not every camera tape made it onto a solid state drive.

  • @KaldekBoch
    @KaldekBoch Před 8 měsíci +2

    For anyone a bit concerned about the directory Paul uses, note that it's possible to use C U Next Tuesday as a term of endearment here in Australia.
    However, given the littany of stupid comments I sometimes get on my own videos, you never know....

  • @scootergirl3662
    @scootergirl3662 Před 8 měsíci +4

    Tesla: move fast and do do things the most expensive way possible

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      And over complicate things to try and be cool

  • @JB-fh1bb
    @JB-fh1bb Před 8 měsíci +1

    8:24 You sleeping on `jq`?

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +1

      Yeah I thought about it, but couldn't be fucked. I just wanted to show something.

    • @JB-fh1bb
      @JB-fh1bb Před 8 měsíci

      @@TallPaulTech that tracks

  • @penrite01
    @penrite01 Před 8 měsíci +1

    Why are you dressed like "Miami Vice"? ... Just saying... Once again... Great video.....

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +2

      Haha, that show actually popped into my head when I was driving down the Gold Coast today :)

    • @2Fast4Mellow
      @2Fast4Mellow Před 8 měsíci +1

      The 80s were my childhood days while during the 90s I was in my teen years. Best two decades of my life!

  • @antronx7
    @antronx7 Před 8 měsíci +5

    Sell this Tesla high tech crap and go with 48v LiFePO4 server rack batteries and hybrid all in one inverter. Its cheaper too. But then you will not have rant topics to make internet videos for.

    • @John_Smith100
      @John_Smith100 Před 8 měsíci +1

      I shill sunsynk hybrid inverters , battle tested in that failed state south Africa where powercuts are a daily occurrence.

  • @lowguidoschopshop
    @lowguidoschopshop Před 8 měsíci +4

    🤣🤣🤣 /foryoutubecunts$ had me rolling.

    • @TallPaulTech
      @TallPaulTech  Před 8 měsíci +3

      Well, you know what they're like.... cunts.