> Markdown version of [/videos/259-cyber-security-small-and-large?t=1502](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large?t=1502). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security: Small, and Large! A single software bug in a connected vehicle can trigger a catastrophic physical event. Learn to integrate cryptographic foundations from the very first line of your embedded code. - **Speakers:** Martin Schmiedecker - **Event:** WeAreDevelopers LIVE - **Published:** October 6, 2021 - **Duration:** 37:32 - **URL:** https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large ## Summary The automotive industry is undergoing a massive shift as vehicles evolve into connected software platforms, bringing profound cybersecurity challenges. What started a decade ago as academic curiosity—such as exploiting tire pressure sensors or triggering MP3 buffer overflow vulnerabilities—has escalated into real-world threats like remote hijacking over cellular networks and sophisticated key fob relay attacks. As software complexity multiplies through autonomous vehicle logic, continuous physical access, and ubiquitous telemetry, the attack surface expands exponentially, placing vehicles in the crosshairs of modern ransomware and supply chain attacks. To combat these vulnerabilities, the industry is transitioning from relying on physical isolation toward robust software paradigms and cryptographic foundations. Securing a modern car requires integrating security from the very first line of code, avoiding the common trap of bolting it on after deployment. Critical automotive ECU components, which frequently run fast, low-level C or Assembly on specialized microcontrollers, must increasingly rely on hardware security modules and rigid secure boot verification formats, even as economic feasibility hinders ubiquitous hardware trust anchors. The ongoing shift toward features like "smartphone as a car key" highlights the relentless push to replace legacy radio architectures with heavily authenticated digital credentials. Preparing for the future of mobility means prioritizing rigorous legal compliance alongside technical sophistication. Upcoming regulatory standards, such as ISO 21434 and UNECE type approvals, will legally mandate that manufacturers build verifiable, lifelong security processes into their fleets. For engineers navigating this embedded ecosystem, recognizing that a software bug can have catastrophic real-world momentum—echoing historical integer overflows in aerospace—is critical. Engaging with communities like the Automotive Security Research Group (ASRG) remains one of the best defenses for developers to stay ahead of adversarial advancements and ensure that millions of lines of code safely protect human life. **Keywords:** automotive security, car hacking platforms, incident response processes, key fob relay attacks, hardware security module, connected vehicles, ISO 21434 compliance, UNECE regulations, buffer overflow vulnerabilities, remote vehicle compromise, automotive software complexity, smartphone as a car key, supply chain hacking, autonomous vehicle safety, hardware trust anchors, vehicle telematics security, embedded C development ## Chapters 1. **Introduction to automotive security and digital forensics** (00:02) — Martin introduces his role investigating security incidents and details modern engineering focus on bespoke vehicle projects. 1. **Early explorations and academic research in automotive hacking** (03:24) — Academic research from 2011 reveals how spoofed sensor inputs and buffer overflows in media players enabled remote compromises. 1. **Highway compromise and wireless key fob vulnerabilities** (06:24) — High-profile remote attacks on driving cars and range extension tools prompted the industry to prioritize security against wireless threats. 1. **Advanced digital theft and vehicle odometer manipulation** (10:59) — Recent attacks demonstrate sophisticated token cloning for luxury vehicles and widespread tampering of digital odometers via consumer tools. 1. **Attacker motivations and the right to repair movement** (13:09) — Agricultural workers increasingly bypass software locks to repair necessary equipment while security researchers probe complex systems out of curiosity. 1. **Developer challenges in securing modern connected vehicles** (14:41) — Increasing vehicle network complexity introduces risks from supply chain attacks, wireless interfaces, and unauthenticated physical access by users. 1. **Software dependence and risks in autonomous driving algorithms** (19:18) — Relying on software abstraction for autonomous navigation introduces critical safety risks from issues like integer overflows and sensor spoofing. 1. **Transitioning to smartphones as secure digital vehicle keys** (23:13) — Replacing traditional key fobs with smartphone credentials offers better cryptography and seamless integration into modern shared mobility services. 1. **Navigating impending automotive security regulations and compliance** (25:02) — New international standards require manufacturers to implement auditable cybersecurity processes throughout a vehicle's entire production lifecycle. 1. **Following security research and continuous developer education** (26:38) — Developers must constantly track new vulnerabilities by engaging with networks alike the Automotive Security Research Group. 1. **Legal liability and software edge cases in autonomy** (28:35) — Tricky legal questions around automated accidents persist while engineers work to handle unpredictable edge cases safely in software. 1. **Standardization of hardware trust anchors in embedded systems** (30:45) — Implementing standardized cryptographic building blocks and hardware trust boundaries is essential for component verification but remains economically challenging. 1. **Programming languages optimized for embedded vehicle software** (33:10) — Embedded components rely on C, assembly, and custom firmware instead of full operating systems to guarantee fast execution times. 1. **Machine learning limitations and centralized server risks** (34:01) — The limitations of anomaly detection and the risks of centralized servers causing fleet-wide outages complicate fully connected vehicle deployments. ## Related Moments - [Identifying system risks and collaborative ecosystem legal challenges](https://www.wearedevelopers.com/videos/258-on-developing-smartphones-on-wheels) (from "On developing smartphones on wheels") - [Adapting industry practices for long-term vehicle software security](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") - [Approaching vehicle connectivity, offline telemetry, and software cybersecurity](https://www.wearedevelopers.com/videos/221-software-stack-under-and-over-the-hood-of-the-fastest-accelerating-car-in-the-world) (from "Software stack under and over the hood of the fastest accelerating car in the world") - [Managing cybersecurity risks throughout the entire vehicle lifecycle](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") - [Connected vehicle attack vectors and international cybersecurity regulations](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") - [Analyzing real world vehicle vulnerabilities and keyless theft attacks](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1306782-endpoint-security-engineer-ot) at **ZEISS Group** - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1998712-endpoint-security-engineer-ot) at **ZEISS Group** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio**