Panel: Tackling Automotive Hardware Vulnerabilities
Dennis
Nullcon Goa 2025 · Panel
Overview
The "Tackling Automotive Hardware Vulnerabilities" panel at Nullcon delved into the complex and rapidly evolving landscape of security threats facing modern vehicles. Featuring two experts, Dennis (a hardware security researcher) and Sain (an industry professional with experience in both automotive and medical domains), the discussion explored the critical intersection of hardware, software, and safety in the automotive sector. The panelists, guided by a moderator, illuminated why cars are increasingly becoming sophisticated Internet of Things (IoT) systems, inheriting many of the security challenges prevalent in that ecosystem.

Key moments
- 0:30 Common hardware vulnerabilities in automotive systems
- 2:00 Infotainment systems: the primary entry point for car hacks
- 3:45 Safety and Security: Tightly coupled in automotive design
- 6:00 Automotive safety standards: A history "written by blood"
- 7:50 How security measures can inadvertently compromise safety
Panel: Tackling Automotive Hardware Vulnerabilities
Speakers: Dennis, Sain
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=DKniWIju2hU
Overview
The "Tackling Automotive Hardware Vulnerabilities" panel at Nullcon delved into the complex and rapidly evolving landscape of security threats facing modern vehicles. Featuring two experts, Dennis (a hardware security researcher) and Sain (an industry professional with experience in both automotive and medical domains), the discussion explored the critical intersection of hardware, software, and safety in the automotive sector. The panelists, guided by a moderator, illuminated why cars are increasingly becoming sophisticated Internet of Things (IoT) systems, inheriting many of the security challenges prevalent in that ecosystem.
The core of the discussion revolved around identifying common hardware-based vulnerabilities, the inherent tension between safety and security, the struggle of regulatory bodies to keep pace with technological advancements, and the intricate challenges of securing a global supply chain. The panelists offered insights into how manufacturers currently approach these issues, the role of emerging technologies like Artificial Intelligence (AI) in both offense and defense, and the persistent threat of Radio Frequency (RF) attacks against vehicle access systems.
This talk is particularly relevant in an era where vehicles are transforming from mechanical machines into connected, software-defined platforms. Understanding these vulnerabilities is paramount for manufacturers, regulators, and security professionals to ensure the safety, privacy, and reliability of the next generation of automobiles. The insights shared underscore the urgent need for a proactive, "security by design" approach to protect against increasingly sophisticated attacks that could have real-world, life-threatening consequences.
Background
▶ Watch: Common hardware vulnerabilities in automotive systems (0:30)
The automotive industry is undergoing a profound transformation, with vehicles evolving from purely mechanical constructs into highly complex, interconnected computing platforms. As Dennis articulates, "nowadays the cars are more less cars but they are more software companies." This paradigm shift means modern automobiles share many characteristics with IoT systems, and consequently, inherit many of their inherent security vulnerabilities. The panel highlighted that many issues found in "broken IoT systems" are now prevalent in cars.
Historically, automotive safety has been paramount, with standards and regulations often "written by blood," as Dennis grimly notes, referencing past fatalities that led to crucial safety features like seatbelts. However, the introduction of extensive software, connectivity, and embedded hardware has introduced an entirely new dimension: cybersecurity. This creates a constant tension between safety and security, as measures intended to enhance one can inadvertently compromise the other. Sain emphasized that safety and security "don't go in silo; they go hands in hands together," stressing their tight coupling. For instance, a security system (like an Intrusion Detection/Prevention System - IDS/IPS) might incorrectly identify a sensor input as malicious and prevent the deployment of an airbag during a crash, turning a security feature into a safety hazard.
The problem is exacerbated by several factors:
- Complexity and Obscurity: Modern cars contain a vast array of devices, firmware, and software components, many of which are poorly understood or tracked, even by the car manufacturers themselves.
- Outdated Software: Infotainment systems, a primary entry point for attackers, often run outdated operating systems like Android, which are not regularly updated. These systems frequently have access to critical vehicle networks like the CAN bus, allowing attackers to potentially control safety-critical functions.
- Fragmented Supply Chain: Automotive manufacturers rely on a vast network of third-party suppliers for various electronic control units (ECUs), sensors, and software. This fragmentation means car companies often lack complete visibility into the security posture of these components, including access to source code for critical parts from major suppliers like Bosch.
- Slow Regulatory Pace: The panelists agreed that regulatory bodies and industry standards (like ISO 21434, mentioned by the moderator) are struggling to keep pace with the rapid evolution of attack techniques. Dennis highlighted that new attacks and tooling (e.g., fault injection for firmware extraction) emerge every few months, while regulatory updates can take years due to the involvement of multiple stakeholders with conflicting financial and political interests. This creates a constant "losing race" against attackers.
- Cost vs. Security: Implementing robust security measures adds cost, and customers are generally unwilling to pay a premium for "more crypto" or "better chips." This economic reality often leads companies, especially startups, to cut corners during design and development, creating technical debt and long-term vulnerabilities that can be exploited later.
The panel's discussion built upon a history of high-profile automotive hacks, such as Charlie Miller and Chris Valasek's remote compromise of a Jeep Cherokee in 2015, or the "CAN Badger" attack, which demonstrated the feasibility of remotely controlling vehicle functions. These incidents underscored the real-world implications of these vulnerabilities, pushing the industry to acknowledge the critical need for improved cybersecurity.
Key Findings
▶ Watch: Infotainment systems: the primary entry point for car hacks (2:00)
The panel discussion brought forth several critical findings regarding the state of automotive hardware security:
- Infotainment Systems are Primary Attack Vectors: The consensus was that infotainment systems are the "number one way how people get into devices" in cars. These systems frequently run unpatched, outdated Android versions and, critically, often have access to the vehicle's internal CAN bus, allowing an attacker to potentially take over the entire car. This highlights a fundamental design flaw where non-critical, internet-connected systems are insufficiently isolated from safety-critical controls.
- The Inseparable Link of Safety and Security: Sain emphasized that safety and security are "very, very tightly coupled" and must be addressed holistically from the outset of product design. Security measures, if not carefully implemented, can inadvertently degrade safety. The panel provided the vivid example of an IDS/IPS mistakenly blocking an airbag deployment, illustrating how security failures can have catastrophic safety consequences.
- Regulatory Frameworks are Critically Lagging: Dennis strongly argued that existing regulatory and certification frameworks are "not up to the time." The slow, multi-stakeholder process for updating standards means that by the time a new regulation is enacted, new attack techniques (like advanced fault injection methods for firmware extraction) have already emerged, leaving a perpetual gap between known threats and codified defenses.
- Supply Chain Security is a Major Blind Spot: Car manufacturers often rely heavily on third-party vendors (e.g., Bosch) for critical components but frequently lack access to their source code or detailed security assurances. While some manufacturers conduct their own penetration testing on vendor parts, many simply "trust blind" or operate under contracts that only address liability post-breach. This creates a sprawling attack surface where vulnerabilities in a single supplier's component can impact millions of vehicles across different brands.
- AI Presents a Dual-Edged Sword for Automotive Security: While AI is increasingly integrated into vehicles for features like autonomous driving and predictive maintenance, its role in security is complex. AI could enhance threat detection, but its deterministic behavior is crucial for safety-critical systems. Dennis expressed concern about AI making non-deterministic decisions, such as shutting down a critical system due to a perceived threat. Conversely, AI is rapidly becoming a tool for attackers, enabling sophisticated adversarial AI attacks that manipulate machine learning models.
- Persistent RF Vulnerabilities: Despite years of research and mitigation attempts, Radio Frequency (RF) attacks on key fobs remain a significant threat. The panel discussed how relay attacks, which extend the range of a key fob signal, and even more advanced techniques to bypass distance bounding mechanisms, continue to challenge vehicle security, underscoring the ongoing "race" between attackers and defenders.
- The Ethical Dilemma of Security Research: The panel touched upon the "villain or hero" perception of security researchers. While their work ultimately makes products safer, manufacturers sometimes view them as disrupting business models (e.g., by enabling features through simple bit flips that were meant to be paid subscriptions) or delaying product releases. However, Dennis asserted that identifying vulnerabilities publicly is crucial because "the problem doesn't go away just because I'm not talking about it."
Technical Deep Dive
▶ Watch: Safety and Security: Tightly coupled in automotive design (3:45)
The discussion provided a deep dive into several technical aspects of automotive security, highlighting specific vulnerabilities and mitigation strategies.
A central theme was the CAN bus (Controller Area Network), which serves as the primary internal communication network within a vehicle, connecting various Electronic Control Units (ECUs). The panel emphasized that infotainment systems, which often run outdated and vulnerable Android operating systems, frequently have direct or indirect access to the CAN bus. This connectivity is a critical flaw, as a compromise of the infotainment system can allow an attacker to send arbitrary messages on the CAN bus, potentially controlling safety-critical functions like braking, steering, or airbags. This highlights a fundamental lack of proper network segmentation and isolation within vehicle architectures.
Firmware was identified as a pervasive element and a source of vulnerability. Dennis noted that even safety-critical components like airbags contain firmware, whose security properties are often not fully understood or tracked by manufacturers. The increasing complexity of these embedded systems means that "no one really really knows how they work," leading to a degradation of security over time. To combat this, the concept of an S-BOM (Software Bill of Materials) was introduced as a "new kind of hip word" for tracking hardware and software components, their versions, and origins, which is crucial for managing supply chain risk.
The discussion also touched upon cryptography, specifically highlighting that vulnerabilities in automotive systems are rarely due to flaws in the cryptographic algorithms themselves (e.g., AES-128). Instead, as the panelists agreed, "most of the crypto vulnerabilities... are always implementation problems with... the keys," referring to insecure storage, weak key management, or improper deployment of cryptographic primitives within the hardware. This underscores the importance of a secure implementation lifecycle beyond just selecting strong algorithms.
Modern attack techniques were also brought to the forefront. Dennis mentioned fault injection as a powerful tool that allows researchers to "extract firmware from chips which we... were not able in the past." Fault injection involves introducing transient or permanent faults into a microchip to alter its behavior, often to bypass security mechanisms or extract sensitive data. This capability means that even "secure" chips can be compromised if physical access is gained, further challenging the notion of hardware-rooted trust.
The panel also discussed the implications of debugging interfaces like JTAG (Joint Test Action Group). Sain recounted an incident where a manufacturer initially dismissed warnings about an exposed JTAG port, only to later discover a modding community was using it to bypass subscription services on their devices. JTAG provides low-level access to a chip's internal state and memory, making it a powerful debugging tool but also a critical security risk if not properly disabled or protected in production devices.
The future of automotive security will heavily involve AI. While AI can be used for "detecting threats" and "identifying attacks very well in advance" (Sain), it also introduces new attack vectors. Dennis described adversarial AI attacks, such as placing a sticker on a street post that a Tesla's vision system misinterprets as a red traffic light, causing vehicles to stop unnecessarily. This demonstrates how physical manipulation can trick machine learning models, leading to potentially dangerous real-world consequences.
Another emerging attack surface is car-to-car (C2C) and infrastructure-to-car (I2C) communication. These systems aim to optimize traffic flow and enable advanced autonomous features by allowing vehicles to exchange data with each other and with smart city infrastructure (e.g., traffic lights telling cars they are green). Dennis expressed concern about the reliance on data from untrusted sources, highlighting the need for "secure protocols" and mechanisms to "trust other cars," possibly involving Hardware Security Modules (HSMs) at various points in the communication chain. Mistakes in securing these complex, distributed systems could lead to widespread disruptions, akin to the Waymo cars getting stuck in a loop in San Francisco, but potentially malicious.
Finally, RF attacks on key fobs were revisited. The panel noted that despite industry efforts, these remain a persistent problem. Early attacks involved relay attacks, where signals from a key fob inside a house were amplified and relayed to a car outside to unlock it. Manufacturers responded with distance bounding techniques, which measure the time-of-flight of RF signals to verify the physical proximity of the key fob. However, Dennis confirmed that researchers have developed tools to "still bypass that," indicating an ongoing cat-and-mouse game in this domain.
Demo / Proof of Concept
▶ Watch: Automotive safety standards: A history "written by blood" (6:00)
This session was structured as a panel discussion, with the moderator posing questions to the two panelists. As such, no live demonstration or proof of concept was presented during the talk. The speakers primarily shared their professional experiences, insights, and observations from their work in automotive and hardware security.
Defensive Implications
▶ Watch: How security measures can inadvertently compromise safety (7:50)
The panel discussion provided a wealth of insights for organizations seeking to bolster their automotive security posture, emphasizing a proactive and holistic approach:
- Embrace Secure by Design Principles: The most critical takeaway, particularly for startups, is to integrate security considerations from the very beginning of the product lifecycle. As Dennis advised, "don't try to kind of cut corners" in development. Instead, adopt a Secure Software Development Life Cycle (SSDLC) approach, including thorough threat modeling upfront. This proactive stance, while seemingly costly initially, is far more economical than fixing vulnerabilities in production or dealing with recalls.
- Implement Comprehensive S-BOMs: To manage the complexity of the automotive supply chain, manufacturers should rigorously implement and maintain a Software Bill of Materials (S-BOM). This involves meticulously tracking all hardware and software components, their versions, and their respective vendors. This visibility is crucial for identifying potential vulnerabilities, managing updates, and assessing overall risk.
- Strengthen Supply Chain Security and Vendor Management: Car manufacturers must exert stronger influence over their third-party suppliers. This includes:
- Enforcing Security Standards: Mandating adherence to recognized security standards (e.g., ISO 21434) and organizational security policies.
- Independent Penetration Testing: Conducting their own penetration tests on components received from suppliers, rather than blindly trusting vendor assurances, especially when source code access is limited.
- Clear Contractual Agreements: Establishing contracts that clearly define security responsibilities and liabilities.
- Isolate Critical Systems: A fundamental architectural principle, often violated, is the isolation of non-critical, internet-connected systems (like infotainment) from safety-critical networks (like the CAN bus). Robust network segmentation, firewalls, and secure gateways are essential to prevent a compromise in one domain from impacting another.
- Prioritize Secure Cryptographic Implementation: While cryptographic algorithms like AES-128 are generally robust, their effectiveness hinges on secure implementation. Defenders must focus on best practices for key management, secure storage of cryptographic keys, and correct deployment of cryptographic primitives to avoid common "implementation problems."
- Prepare for AI-Driven Attacks and Defenses: As AI becomes ubiquitous, defenders must:
- Secure AI Models: Implement techniques to protect AI models from adversarial AI attacks, such as input validation, model hardening, and anomaly detection.
- Deterministic AI for Safety: Ensure that AI systems in safety-critical contexts behave deterministically and that security decisions made by AI do not inadvertently compromise safety.
- Leverage AI for Detection: Utilize AI algorithms for proactive threat detection, identifying anomalies, and predicting potential attacks across the vehicle's vast data streams.
- Fortify C2C/I2C Communication: The emerging landscape of vehicle-to-vehicle and infrastructure-to-vehicle communication requires rigorous security. This includes:
- Developing Secure Protocols: Designing and implementing robust, authenticated, and encrypted communication protocols.
- Establishing Trust Mechanisms: Implementing strong identity and trust mechanisms to verify the authenticity and integrity of data exchanged between vehicles and infrastructure, potentially utilizing Hardware Security Modules (HSMs).
- Address Persistent RF Vulnerabilities: The ongoing battle against key fob attacks requires continuous innovation. Defenders need to:
- Enhance Distance Bounding: Develop more sophisticated and resilient distance bounding techniques that are harder to bypass.
- Explore Alternative Access Methods: Investigate and implement alternative, more secure vehicle access and authentication methods.
- Continuous Monitoring and Updates: The dynamic nature of threats necessitates a continuous security posture. Regular software and firmware updates, combined with ongoing monitoring for new vulnerabilities and attack patterns, are crucial to maintain vehicle security throughout its lifecycle.
- Foster a Security-First Culture: As Sain noted, security should be a "basic DNA" within an organization, with "each and every individual" part of the project taking ownership. This cultural shift is vital to ensure security is embedded in every decision, from design to deployment.
Key Takeaways
- Automotive systems are complex IoT devices: Modern cars are essentially "software companies" on wheels, inheriting the broad range of hardware and software vulnerabilities common in the IoT ecosystem, with infotainment systems being a primary entry point.
- Safety and security are inextricably linked: Security measures must be designed in conjunction with safety requirements, as a security failure can directly lead to safety hazards (e.g., an IDS/IPS blocking an airbag deployment).
- Regulatory frameworks are struggling to keep pace: The slow, multi-stakeholder process for updating automotive security standards and regulations lags significantly behind the rapid evolution of attack techniques and tooling.
- Supply chain security is a critical challenge: Manufacturers face immense difficulty in enforcing security standards and gaining visibility into the security posture of components from numerous third-party vendors.
- AI presents both opportunities and threats: While AI can enhance threat detection and enable autonomous features, it also introduces new attack vectors like adversarial AI, which can manipulate vehicle systems.
- "Security by Design" is paramount: For both established manufacturers and startups, integrating security from the earliest design phases (SSDLC) is crucial to avoid costly retrofits, recalls, and reputational damage. Persistent issues like insecure crypto implementations and RF key fob vulnerabilities underscore the need for foundational security.
About the Speaker(s)
The panel featured two industry experts and was moderated by a host.
Dennis, affectionately referred to by the moderator as "Dennis the Menace," is a prominent figure in hardware security research. His background includes work with "hard Pawn lab" and extensive experience analyzing the security of modern vehicles, particularly Teslas and other EV companies. Dennis approaches automotive security from the perspective of a "breaker" — someone who actively identifies and exploits vulnerabilities. His insights often highlight the practical realities of hacking embedded systems and the challenges manufacturers face in securing complex hardware and firmware.
Sain brings a unique perspective to the panel, having a dual background in both the automotive and medical device industries. This experience allows him to speak authoritatively on the delicate balance between safety and security, a critical concern in both domains. Sain's contributions focused on the organizational and policy aspects of security, emphasizing the need for integrated safety and security considerations from the design phase and the importance of robust organizational policies for managing third-party vendor risks.
The panel was moderated by Aasim, who guided the discussion by posing insightful questions that steered the conversation through the various facets of automotive hardware security.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent panel covering well-trodden automotive security terrain — CAN bus isolation, supply chain opacity, RF relay attacks, infotainment as attack surface. Nothing new for anyone who's followed car hacking since Miller and Valasek, but the safety/security coupling angle and the medical-device cross-domain perspective add modest texture. Fills a slot without embarrassing the conference.
Heather Calloway (CISO) — WEAK
Competent survey of automotive security terrain — supply chain gaps, safety-security coupling, regulatory lag — but it stays at the survey level throughout. The panel names real problems without producing usable decisions, and the defensive implications read like a vendor checklist rather than earned guidance.