The hack, the crash and two smoking barrels.
Thomas Sermpinis
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In "The hack, the crash and two smoking barrels," Thomas Sermpinis, a lead at Auxilium Pentest Labs, delivers a candid and critical assessment of the cybersecurity landscape within the automotive industry. His talk, presented at DEF CON 32, pulls back the curtain on what he terms the "stupid things that automotive industry is doing still in 2024," emphasizing that many modern vehicles, despite their advanced features, are built on fundamentally insecure foundations. Sermpinis aims to highlight the pervasive security vulnerabilities stemming from dated protocols and architectural missteps, framing these issues not merely as financial risks but as profound threats to user safety.

Key moments
- 0:00 Introduction: The Hack, the Crash, Two Smoking Barrels
- 2:08 Modern Vehicles: Computers on Wheels, Insecure Implementations
- 3:20 Vehicle Architecture & CAN Protocol's Security Flaws
- 4:15 Core CAN Vulnerability: No Encryption or Authentication
- 6:00 Prioritizing Safety over Financial Aspects in Car Security
- 6:30 Automotive Industry's Struggle with Software & Security
The hack, the crash and two smoking barrels.
Speakers: Thomas Sermpinis
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=MDndWJxfP-U
Overview
In "The hack, the crash and two smoking barrels," Thomas Sermpinis, a lead at Auxilium Pentest Labs, delivers a candid and critical assessment of the cybersecurity landscape within the automotive industry. His talk, presented at DEF CON 32, pulls back the curtain on what he terms the "stupid things that automotive industry is doing still in 2024," emphasizing that many modern vehicles, despite their advanced features, are built on fundamentally insecure foundations. Sermpinis aims to highlight the pervasive security vulnerabilities stemming from dated protocols and architectural missteps, framing these issues not merely as financial risks but as profound threats to user safety.
The presentation serves as a stark warning and a call to action, urging both the industry and the security community to recognize the gravity of the situation. Sermpinis argues that the rapid integration of complex functionalities and connectivity into vehicles has outpaced the implementation of robust security measures, leading to a precarious state where "our world is hanging in on in really thin threads." Through his insights, he seeks to foster greater interest in vehicle security, underscoring the critical importance of safety-related hardware that often goes overlooked or is inadequately protected, ultimately challenging the prevailing mindset driven by what he describes as "a bit of laziness and a sprinkle of capitalism."
Background
▶ Watch: Introduction: The Hack, the Crash, Two Smoking Barrels (0:00)
The modern vehicle has evolved dramatically from a purely mechanical device to a sophisticated "computer on wheels," often described by Sermpinis as a "living room on wheels" due to its extensive functionality and entertainment systems. This transformation, driven by consumer demand for richer services and enhanced connectivity, has introduced an unprecedented level of complexity into automotive architectures. However, this evolution has not been uniformly accompanied by a commensurate increase in security. Instead, Sermpinis points to a prevalent trend of "improper and insecure implementation of new functionality," resulting in a constant stream of security incidents, many of which make headlines for their financial implications, such as car theft.
The core of this problem lies in the automotive industry's historical roots and its struggle to adapt. Predominantly based on over a century of mechanical engineering traditions, the industry has been recently "forced to implement a lot of things they had no idea about." This rapid innovation cycle, coupled with stringent safety requirements and short development timelines, has created an environment where cybersecurity often becomes an afterthought rather than an integral part of the design process. The result is a landscape of complicated architectures comprising numerous Electronic Control Units (ECUs) – individual embedded components, each with a specific purpose. While these ECUs are theoretically segmented into "isolated buses" to prevent external communication and segment by criticality, Sermpinis highlights that critical interfaces are increasingly exposed, both internally and externally. A prime example is the onboard charging ECU, which has an exposed interface for communication with the charger and the vehicle. More critically, the main head unit, which users interact with, is often exposed to the internet via a telematics unit, facilitating services like SOS calls, over-the-air (OTA) updates, and other interconnected functionalities, thereby creating significant attack surfaces.
A fundamental technical vulnerability underpinning many of these issues is the continued reliance on the Controller Area Network (CAN) protocol. Despite its existence for over 40 years, the CAN bus remains the backbone for communication among the majority of ECUs in modern vehicles. While the protocol has seen several iterations since its inception for simpler systems, its primary flaw, as Sermpinis emphasizes, is the lack of standard encryption and message authentication. This fundamental omission leaves CAN messages flowing across vehicle buses "prone to interception, injection and replication" when additional protections are not implemented—a scenario that is "more common than you think even 40 years after its inception." This legacy protocol, originally designed for a different era of automotive engineering, has become a significant liability in the connected vehicle landscape of 2024, creating an inherent weakness that attackers can exploit to compromise vehicle safety and functionality.
Key Findings
▶ Watch: Vehicle Architecture & CAN Protocol's Security Flaws (3:20)
Thomas Sermpinis's talk reveals several critical findings that underscore the precarious state of cybersecurity in the automotive sector. Primarily, he highlights the widespread insecurity embedded within modern vehicle designs, a direct consequence of the industry's rapid adoption of advanced features without adequate security considerations. Despite their sophistication, many vehicles are built upon a foundation riddled with vulnerabilities, leading to a constant stream of security incidents.
A central technical finding revolves around the fundamental protocol weaknesses inherent in the CAN bus. Sermpinis stresses that this 40-year-old protocol, still widely used across the majority of ECUs in contemporary vehicles, fundamentally lacks standard encryption and message authentication. This absence of basic security primitives renders vehicle communication susceptible to interception, injection, and replication, allowing malicious actors to potentially manipulate critical vehicle functions. The persistence of such a vulnerable protocol, even in 2024, is presented as a major oversight.
Furthermore, the talk identifies the dangerous trend of exposed critical interfaces. Even within seemingly segmented vehicle architectures, components like the onboard charging ECU's communication interface and the main head unit's connection to the internet via a telematics unit represent significant attack vectors. These exposures facilitate external access to critical vehicle systems, creating pathways for remote exploitation that can compromise not only data but also operational safety.
Sermpinis also points to the automotive industry's slow pace of adoption for secure technologies. Despite the emergence of more robust alternatives like Automotive Ethernet and secure CAN transceivers, and the conceptual shift towards software-defined vehicles and centralized architectures, their widespread implementation by mainstream Original Equipment Manufacturers (OEMs) remains slow. This lag means that many new vehicles continue to ship with outdated and insecure designs. He contrasts this with "new type of OEMs that are basically IT companies that started building cars," which often demonstrate greater proficiency in implementing secure architectures dueating to their inherent IT experience.
Finally, a overarching finding is the speaker's assertion that product development in the automotive sector is often influenced by "a bit of laziness and a sprinkle of capitalism," leading to compromises in security for the sake of speed to market or cost efficiency. This mindset, he argues, directly contributes to the proliferation of insecure designs. Importantly, Sermpinis reorients the discussion to emphasize that cybersecurity issues in vehicles are fundamentally a safety concern, not merely a financial one, challenging the industry's often narrow focus on preventing theft or data breaches.
Technical Deep Dive
▶ Watch: Core CAN Vulnerability: No Encryption or Authentication (4:15)
The technical core of Sermpinis's talk dissects the intricate and often insecure architecture of modern vehicles. At a high level, contemporary cars are characterized by a distributed network of Electronic Control Units (ECUs). These are specialized embedded systems, each responsible for controlling specific functions, ranging from engine management and braking to infotainment and climate control. To manage this complexity and, theoretically, enhance safety and reliability, these ECUs are segmented into several "isolated buses." The intent behind this segmentation is to logically separate vehicle functions by criticality and purpose, thereby limiting the scope of any single failure or compromise. For instance, safety-critical systems might reside on a different bus than entertainment systems.
However, Sermpinis reveals that this segmentation often fails to provide robust security due to exposed interfaces. Despite the theoretical isolation, practical necessities for modern vehicle functionality lead to critical interconnections. He cites the example of the onboard charging ECU, which requires an exposed interface to manage communication between the external charger and the vehicle's internal systems. More concerning is the exposure of the main head unit—the user's primary interface for infotainment and vehicle settings—to the internet. This connectivity is typically facilitated by a dedicated telematics unit, which enables services such as emergency SOS calls, remote diagnostics, and crucial over-the-air (OTA) software updates. While these functionalities are desirable, the internet exposure of the telematics unit creates a direct pathway for external attacks to potentially reach the head unit and, by extension, other connected ECUs.
The most critical technical vulnerability highlighted by Sermpinis is the pervasive use of the Controller Area Network (CAN) protocol. Developed over 40 years ago, CAN was designed for efficient, real-time communication in industrial and automotive environments, prioritizing speed and determinism over security. While it has undergone several iterations (e.g., CAN FD for higher data rates), its fundamental security shortcomings persist. Sermpinis explicitly states that the CAN protocol, as widely implemented, lacks two crucial security features: standard encryption and message authentication.
The absence of encryption means that all messages transmitted across the CAN bus are sent in plaintext. Any attacker with physical or logical access to the bus can easily intercept and read these messages, gaining insights into vehicle operations, sensor data, and control commands. The lack of message authentication is even more critical. Without cryptographic verification of a message's origin and integrity, an attacker can not only intercept but also inject arbitrary messages onto the bus or replay previously captured valid messages. This allows for the spoofing of legitimate ECUs, enabling an attacker to send commands that could, for example, disable brakes, manipulate steering, or control engine functions, all without the real ECU’s knowledge or consent. Sermpinis notes that this vulnerability, making messages "prone to interception, injection and replication," is "more common than you think even 40 years after its inception," indicating a systemic failure in the industry to adopt modern security practices for a foundational component.
Sermpinis acknowledges that the industry is aware of these limitations and is moving towards more secure architectures, often referred to as "software-defined vehicles" and centralized computing platforms. These newer paradigms often incorporate technologies like Automotive Ethernet and secure CAN transceivers, which offer inherent cryptographic capabilities and better isolation. However, he laments that these advancements are not yet widely implemented, especially by traditional OEMs who are struggling to catch up with "new type of OEMs that are basically IT companies that started building cars" and have a more inherent understanding of cybersecurity from their core business. This gap highlights a significant technical debt that the mainstream automotive industry is carrying, with direct implications for vehicle safety and security.
Demo / Proof of Concept
▶ Watch: Prioritizing Safety over Financial Aspects in Car Security (6:00)
While Thomas Sermpinis's talk heavily emphasizes the critical need for improved vehicle security and outlines numerous architectural and protocol-level vulnerabilities, the provided transcript does not include a specific description of a live demonstration or proof of concept. The speaker mentions the importance of understanding "what the demos are representing later," suggesting that demonstrations might have been part of the full presentation. However, without further details in the transcript, it is not possible to describe the specifics of any tools used, attack chains executed, or the visual outcome of such a demonstration. The talk primarily focuses on the "why you should care" rather than a step-by-step "how to do it."
Defensive Implications
▶ Watch: Automotive Industry's Struggle with Software & Security (6:30)
The insights shared by Thomas Sermpinis carry significant defensive implications for various stakeholders within the automotive ecosystem, from manufacturers to regulators and consumers. Addressing the systemic vulnerabilities he outlines requires a multi-faceted approach.
For Automotive Manufacturers (OEMs) and Suppliers, the most immediate and critical defensive action is to fundamentally re-evaluate their approach to in-vehicle communication security. The continued reliance on the CAN protocol without standard encryption and message authentication is a glaring vulnerability that must be rectified. Manufacturers should prioritize the implementation of secure CAN transceivers and cryptographic overlays for CAN messages, ensuring integrity and authenticity. Beyond CAN, all in-vehicle communication buses should adopt modern, secure protocols like Automotive Ethernet with robust encryption and authentication mechanisms built-in from the ground up, rather than as an afterthought.
Securing exposed interfaces is another paramount concern. Telematics units, which connect vehicles to external networks, must be treated as highly sensitive components. They require rigorous hardening, including strong authentication, authorization, intrusion detection systems, and strict network segmentation to isolate them from safety-critical ECUs. Communication between the telematics unit and the rest of the vehicle's network should be encrypted and authenticated. Similarly, interfaces for components like onboard charging ECUs need to be secured against unauthorized access and manipulation, ensuring that external interactions cannot compromise internal vehicle systems.
From an architectural standpoint, manufacturers must accelerate the transition towards software-defined vehicles and centralized, secure computing platforms. This shift allows for more holistic security management, easier patching, and the implementation of advanced security features like secure boot, hardware-rooted trust, and continuous monitoring. Investing in a robust Security Development Lifecycle (SDL) that integrates security considerations from the initial design phase through deployment and maintenance is crucial. This includes comprehensive threat modeling, security code reviews, penetration testing by independent experts, and vulnerability disclosure programs. Furthermore, OEMs must invest in training and upskilling their engineering teams in cybersecurity best practices, recognizing that mechanical and electrical engineering expertise alone is insufficient for the demands of connected vehicles.
Regulatory Bodies, such as the National Highway Transportation Safety Administration (NHTSA) mentioned in the Q&A, have a vital role to play. They need to establish and enforce mandatory cybersecurity standards for vehicle manufacturers, moving beyond voluntary guidelines. These standards should cover not only data privacy but, more importantly, safety-critical systems, ensuring that vehicles meet a baseline level of security before they are allowed on the road. This regulatory push can help level the playing field and prevent market pressures from leading to security shortcuts.
For Consumers, the defensive implication is primarily one of awareness and advocacy. Understanding that their "computer on wheels" carries significant security risks should prompt them to demand more secure products from manufacturers. While direct defensive actions might be limited, choosing vehicles from OEMs known for strong security practices can send a powerful market signal.
Finally, for Security Researchers and Penetration Testers, the call to action is to continue identifying and responsibly disclosing vulnerabilities. Their work is essential in holding the industry accountable and providing the necessary pressure and insights for improvement. Focusing research on safety-critical systems and the widespread vulnerabilities in protocols like CAN will continue to be invaluable.
Key Takeaways
- Pervasive Insecurity in Modern Vehicles: Contemporary cars, despite being "computers on wheels" with extensive functionality, are often built with significant security vulnerabilities due to insecure implementations and outdated design philosophies.
- Critical CAN Protocol Weaknesses: The 40-year-old CAN bus protocol, widely used in modern vehicles, fundamentally lacks standard encryption and message authentication, making in-vehicle communication highly susceptible to interception, injection, and replication, posing severe safety risks.
- Dangerous Exposed Interfaces: Critical vehicle components like telematics units and onboard charging ECUs expose interfaces that create direct attack vectors, allowing external access to internal vehicle networks and potentially compromising safety-critical systems.
- Automotive Industry's Lag in Security Adoption: The mainstream automotive industry is slow to adopt modern cybersecurity practices and technologies, such as Automotive Ethernet, secure CAN transceivers, and software-defined vehicle architectures, lagging behind the security maturity seen in IT-centric OEMs.
- Cybersecurity is a Safety Imperative: Vehicle security vulnerabilities are not just financial risks (e.g., car theft) but fundamentally safety issues, with potential for physical harm or loss of life due to remote manipulation of critical functions.
- Call for Collective Action: Improving automotive cybersecurity requires concerted efforts from manufacturers (prioritizing security-by-design, adopting modern protocols), regulators (enforcing mandatory standards), and security researchers (identifying and disclosing vulnerabilities).
About the Speaker(s)
Thomas Sermpinis, also known as Crow Tom, is a prominent figure in the cybersecurity community, particularly passionate about vehicle security. He leads an "amazing team" at Auxilium Pentest Labs, which, at the time of the talk, was actively competing and performing well in the car hacking village. Sermpinis describes himself as someone who loves to hack "everything day night, whatever," driven by a desire to expose the fragility of our interconnected world and highlight how many products are created with "a bit of laziness and a sprinkle of capitalism." While he humbly admits he is "the worst" at crafting extreme exploit chains, his core mission is not to teach "how to do it," but to demonstrate "why you should be here too and why you should care" about the critical security shortcomings in modern technology, especially within the automotive industry.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Thomas Sermpinis delivers a blunt, necessary assessment of automotive cybersecurity, revealing that despite modern features, vehicles are built on fundamentally insecure foundations. He meticulously details the pervasive, decades-old vulnerabilities in the CAN bus protocol and the dangerous exposure of critical ECUs through telematics units, emphasizing these are not just financial risks but profound threats to human safety. The talk serves as a stark warning and a call to action for an industry that prioritizes speed and cost over robust security, offering critical insights for manufacturers, regulators, and security researchers alike.
Heather Calloway (CISO) — MUST SEE
Thomas Sermpinis's talk delivers a clear, unsentimental assessment of systemic cybersecurity failures within the automotive industry. He effectively frames the pervasive insecurity of modern vehicles, particularly the reliance on outdated protocols like CAN and exposed interfaces, as a profound safety and business risk rather than merely a technical or financial one. The presentation is a direct call to action for manufacturers and regulators, highlighting critical institutional accountability gaps and the urgent need for secure-by-design architectures to protect human lives and ensure operational resilience in connected vehicles.