Listen to the full episode.
What this episode examines
In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we dissect the staggering UC San Diego research disclosure revealing how dealer-installed aftermarket anti-theft modules bypassed entire OEM security architectures. What starts as a localized dealer convenience ends as a systemic collapse of the trust boundary.
We go under the hood—literally—to trace the five-stage failure chain: from the initial blind trust of physical splicing, through CAN bus propagation with zero source authentication, to the nightmare of containment when 2.2 million cars cannot be fixed with an over-the-air update.
But this is not just a post-mortem. We dive into the central engineering dilemma of the decade:
Regulatory mandates (UN R155, ISO/SAE 21434) demand rigorous, state-aware cyber risk management.
Right-to-repair legislation demands open, interoperable access to the exact same systems.
Can both coexist? We debate hardline transaction-level state checking versus risk-based interoperability APIs, and we propose a defensible tiered architecture: an unbreakable vault for propulsion, braking and steering; a monitored turnstile for diagnostics and infotainment.

