WeAreDevelopers LIVE β€’ Oct 6, 2021

Cyber Security: Small, and Large!

Martin Schmiedecker

A single software bug in a connected vehicle can trigger a catastrophic physical event. Learn to integrate cryptographic foundations from the very first line of your embedded code.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to automotive security and digital forensics

Martin introduces his role investigating security incidents and details modern engineering focus on bespoke vehicle projects.

#2 about 3 min

Early explorations and academic research in automotive hacking

Academic research from 2011 reveals how spoofed sensor inputs and buffer overflows in media players enabled remote compromises.

#3 about 5 min

Highway compromise and wireless key fob vulnerabilities

High-profile remote attacks on driving cars and range extension tools prompted the industry to prioritize security against wireless threats.

#4 about 3 min

Advanced digital theft and vehicle odometer manipulation

Recent attacks demonstrate sophisticated token cloning for luxury vehicles and widespread tampering of digital odometers via consumer tools.

#5 about 2 min

Attacker motivations and the right to repair movement

Agricultural workers increasingly bypass software locks to repair necessary equipment while security researchers probe complex systems out of curiosity.

#6 about 5 min

Developer challenges in securing modern connected vehicles

Increasing vehicle network complexity introduces risks from supply chain attacks, wireless interfaces, and unauthenticated physical access by users.

#7 about 4 min

Software dependence and risks in autonomous driving algorithms

Relying on software abstraction for autonomous navigation introduces critical safety risks from issues like integer overflows and sensor spoofing.

#8 about 2 min

Transitioning to smartphones as secure digital vehicle keys

Replacing traditional key fobs with smartphone credentials offers better cryptography and seamless integration into modern shared mobility services.

#9 about 2 min

Navigating impending automotive security regulations and compliance

New international standards require manufacturers to implement auditable cybersecurity processes throughout a vehicle's entire production lifecycle.

#10 about 2 min

Following security research and continuous developer education

Developers must constantly track new vulnerabilities by engaging with networks alike the Automotive Security Research Group.

#11 about 3 min

Legal liability and software edge cases in autonomy

Tricky legal questions around automated accidents persist while engineers work to handle unpredictable edge cases safely in software.

#12 about 3 min

Standardization of hardware trust anchors in embedded systems

Implementing standardized cryptographic building blocks and hardware trust boundaries is essential for component verification but remains economically challenging.

#13 about 1 min

Programming languages optimized for embedded vehicle software

Embedded components rely on C, assembly, and custom firmware instead of full operating systems to guarantee fast execution times.

#14 about 4 min

Machine learning limitations and centralized server risks

The limitations of anomaly detection and the risks of centralized servers causing fleet-wide outages complicate fully connected vehicle deployments.

Matching moments

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-JΓΌrgen Eidler Β· LIVE

1:23 min

Adapting industry practices for long-term vehicle software security

Henning Harbs Β· WWC 2023

5:14 min

Approaching vehicle connectivity, offline telemetry, and software cybersecurity

Denis Grahovac Β· WWC 2021

3:50 min

Managing cybersecurity risks throughout the entire vehicle lifecycle

Henning Harbs Β· WWC 2023

3:11 min

Connected vehicle attack vectors and international cybersecurity regulations

Henning Harbs Β· WWC 2023

4:02 min

Analyzing real world vehicle vulnerabilities and keyless theft attacks

Henning Harbs Β· WWC 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane