A Chat About CyberSecurity with Dr. Steven A Wright
About this episode
Modern EVs are framed as internet-connected computers, bringing a new landscape of vulnerabilities—from software exploits and social engineering to deepfakes and data poisoning. Dr. Steven A. Wright explains EV charging as an ecosystem with multiple access points, including chargers, cloud back ends, apps, and payment systems that can expose personally identifiable information. He also highlights vehicle attack surfaces like OTA updates and contactless interfaces (NFC/RFID), plus why even “airgapped” setups can be compromised. Practical guidance centers on digital hygiene and verifying information.
In this episode of Kilowatt, we sit down for an engaging chat about technology law, ethics, and cyber security with Dr. Steven A. Wright. As an expert in navigating the complex intersection of law and emerging engineering tech, Dr. Wright shares critical insights into the security challenges facing the evolving EV infrastructure and power grids. We discuss the legal responsibilities of developers, the ethical ramifications of autonomous tech, and how modern architecture must adapt to protect user privacy and system integrity. Whether you are an engineer, a tech enthusiast, or simply curious about the legal frameworks shaping our future, this conversation offers a profound look at the safeguards we need today for the innovations of tomorrow.
Support the Show https://www.supportkilowatt.com/
Other Podcasts:
- Beyond the Post YouTube (https://www.youtube.com/@beyondthepostfm)
- Beyond the Post Podcast (https://www.beyondthepost.fm/)
- Shuffle Playlist (https://shows.acast.com/shuffle-playlist)
- 918Digital Website (https://www.918digital.com/)
News Links:
- Dr. Steven A. Wright on LinkedIn
- Dr. Steven A. Wright Official Website
- Books and Publications by Dr. Steven A. Wright
- Dr. Steven A. Wright on YouTube
- Dr. Steven A. Wright on X
*Show Art Created By Gemini
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Dodge Charger
"...erability. You could have somebody who's hacked a charger, for instance, and maybe that's a vulnerability o..."
The Dodge Charger is a car designed for performance, with a focus on fast driving and a sporty setup. The podcast mentions it in the context of hacking or security, meaning connected features and software can be a risk if they aren’t protected. The key point is that modern cars can have computer systems that need safeguarding.
The Dodge Charger is a performance-focused sedan (and in some years, a muscle-car style vehicle) known for strong acceleration and a sporty driving feel. In an EV-focused podcast context, it’s being mentioned because vehicle connectivity and software can create cybersecurity concerns—like the idea that someone could hack a “charger” (or a connected vehicle system) and exploit vulnerabilities. That makes it relevant to discussions about protecting modern cars from unauthorized access.
public charging network
"Otherwise, your car is a very expensive one somewhere and that could be home charging [344.9s] or that could be some public charging network. [353.3s] And typically those charging networks have cloud back ends..."
A public EV charging network is a company/service that lets you charge your car at public stations. They handle things like who can use the charger and how charging gets paid for.
A public charging network is a service that provides EV charging access at locations like parking lots and streets. It’s run by a charging operator that manages authentication and billing for drivers using the chargers.
cloud back ends
"And typically those charging networks have cloud back ends and some charging system operator [360.9s] that's administering who gets to use those charging systems."
In EV charging, the “cloud back end” is the remote server-side system that stores data and runs the logic behind charging access and billing. Because it connects to chargers and driver apps, it becomes a high-value target for cyberattacks.
charging system operator
"And typically those charging networks have cloud back ends and some charging system operator [360.9s] that's administering who gets to use those charging systems."
A charging system operator is the company that runs a network of EV chargers. They manage who can use the chargers and how charging gets billed.
A charging system operator is the organization that runs a charging network and administers access to chargers. They typically control user authentication, authorization, and billing workflows across chargers and apps.
personally identifiable information
"And once you get to that point, then you've got to have personally identifiable information [371.4s] about which accounts getting charged, how do you identify who it is that's making use [377.0s] of the service..."
Personally identifiable information (PII) is personal data that can point to you as a specific person. EV charging systems may collect it so they know who is charging and can charge you for it.
Personally identifiable information (PII) is data that can identify a specific person, such as account details tied to EV charging. EV charging systems may collect it for identifying users, tracking charging activity, and processing payments.
EV chargers
"There's other issues around EV chargers themselves. [419.0s] The public EV chargers are perhaps a little more robust than the private ones..."
EV chargers are the machines that provide electricity to your car. They also have software and connections to networks, so they can be targeted by hackers.
EV chargers are the hardware units that deliver electricity to an EV and communicate with the network for authorization and payment. Because they include both power electronics and networked software, they can be vulnerable to attacks.
private EV charger
"The public EV chargers are perhaps a little more robust than the private ones [426.4s] because you tend to have some physical security around the private EV charger. [433.2s] So it's typically inside your garage..."
A private EV charger is one installed for a specific home or property rather than for public use. Because it’s often in a more controlled area, it may be harder to tamper with.
A private EV charger is a charging unit intended for a specific location or owner (for example, at home or a private facility). The transcript notes that physical security is often stronger for private chargers, which can affect the threat model.
protocols standardised
"from the early days of the initial EVs, a lot of the software to access the charges [453.1s] was all proprietary. [462.8s] But there have been some protocols standardised around communications with charging systems."
Standardized protocols are common “rules” that chargers and charging apps use to communicate. Using shared rules can make systems work together more easily, but it can also spread security weaknesses if they exist.
Standardized protocols are agreed-upon communication rules that charging equipment and software use to talk to each other. Standardization can improve interoperability, but it also means security issues in widely used protocols can affect many networks.
Tesla
"And I guess that's maybe perceived as a strength for somebody like Tesla [567.9s] that has the sort of soup to nuts approach."
Tesla is an electric-car brand. When people talk about hacking, they often focus on the car’s software and how it connects to networks, because that’s where attackers may try to get in.
Tesla is an electric-vehicle brand known for tightly integrating software with the car. In cybersecurity discussions, that “software-first” design can matter because attackers may target connected systems and update pathways rather than only physical components.
malware
"Have you ever heard of any sort of malware or anything like, [574.9s] even through Pondone or some other contests like that,"
Malware is harmful software made to cause trouble or take over a device. In cars, it could be used to mess with systems or try to get access through the car’s connections.
Malware is malicious software designed to harm, spy on, or take control of a device. In a connected vehicle context, malware can be used to disrupt systems or attempt to gain access through entry points like updates, connectivity, or compromised subsystems.
over the air software updates
"A lot of vehicles have not just a charger connection, [601.6s] but also have over the air software updates. [605.9s] And so that's another attack factor."
Over-the-air updates are software updates that get sent to the car wirelessly. If someone could tamper with those updates, they might be able to put harmful software onto the vehicle.
Over-the-air (OTA) software updates are remote updates sent to a vehicle over a wireless connection. Because they change code inside the car, they can become an attack surface if an attacker can interfere with the update process or trick the vehicle into installing malicious software.
infotainment systems
"There's been compromises through systems on the vehicle, [619.7s] like the in-vehicle entertainment, infotainment systems. [624.7s] Sometimes those have been hacked."
Infotainment systems are the car’s screens and entertainment features—like music, navigation, and apps. If hackers get into that system, they may be able to reach other parts of the car too.
Infotainment systems are the car’s in-cabin entertainment and information tech, typically including the touchscreen, media playback, navigation, and connectivity features. If an infotainment system is compromised, it can sometimes be used as a stepping stone to reach other vehicle computers over internal networks.
near field communications
"So those are things like near field communications and RFID interfaces. [662.4s] They typically don't have as much security as some of the more rigorous protocols"
Near-field communications are the short-range “tap to connect” wireless feature. If a car uses it for access or authentication, attackers might try to abuse that tap connection if it isn’t well protected.
Near-field communications (NFC) are short-range wireless links used for things like tapping a card or phone to a reader. In vehicles, NFC can be a contactless entry point, and if its security is weak, it may be exploited to gain unauthorized access.
RFID interfaces
"So those are things like near field communications and RFID interfaces. [662.4s] They typically don't have as much security as some of the more rigorous protocols"
RFID is a radio-based way to identify something—like a key or card—without plugging it in. If the car’s RFID system isn’t secure, someone might be able to spoof or misuse that identification.
RFID (radio-frequency identification) interfaces use radio signals to identify objects or credentials, often at close range. In vehicles, RFID can be part of keyless entry or other access systems, and weak RFID security can enable unauthorized identification or access attempts.
charging station
"Is it the vehicle itself? Is it the charging station? Is it the back end systems with the payments?"
A charging station is the place/device you plug your EV into to get electricity. It’s not just a dumb outlet—modern chargers have computers and connections, so they can also be targeted or protected like other devices.
A charging station is the EV charging hardware (often a wallbox or public charger) that provides electrical power to the vehicle. In cybersecurity discussions, it’s a key “device” because it can communicate with back-end services and may have its own software and network connections.
back end systems with the payments
"Is it the charging station? Is it the back end systems with the payments? Are you trying to, with the charging station and even the vehicle attacks,"
That phrase means the online computer systems that run the charging service—like logging your session and charging you for it. If someone attacks those systems, it can affect billing or access to charging.
“Back end systems with the payments” refers to the remote servers and software that manage charging sessions, authentication, billing, and payment processing for EV charging. These systems are part of the overall EV charging ecosystem, so attacks can target accounts, authorization flows, or payment-related services.
destabilize the grid
"is it really against those devices or are you trying to destabilize the grid in some ways from the power by having power attacks on the grid? Yeah?"
The “grid” is the big electricity network that powers homes and businesses. If something destabilizes it, the electricity can become less stable—like the system losing control of how much power is flowing and how steady it is.
“Destabilize the grid” means disrupting the electrical power network so voltage, frequency, or power flow becomes unstable. EV charging can interact with the grid through power electronics and control systems, so an attack could theoretically cause harmful power behavior.
unsafe power delivery
"Or are you trying to do some unsafe power delivery into the electric vehicle itself? Whether that's to destroy other components or degrade the batteries. So there's a lot of different targets associated with this as well."
This means delivering electricity to the car in a way that could be dangerous—like the wrong amount or the wrong way. The concern is that a compromised system could make the charger or vehicle behave unsafely.
“Unsafe power delivery” refers to providing electrical power to an EV in a way that’s outside safe operating limits (for example, incorrect voltage/current or improper control timing). In cybersecurity terms, attackers might try to manipulate charging control so the vehicle receives harmful power.
degrade the batteries
"Whether that's to destroy other components or degrade the batteries. So there's a lot of different targets associated with this as well. It's not just a financial attack on somebody's account or some provider in the chain."
Battery degradation means the battery doesn’t last as long or can’t hold as much charge as it used to. The concern here is that unsafe charging could make that happen faster.
“Degrade the batteries” means reducing battery health over time, typically by stressing the cells beyond what they’re designed to handle. In EV cybersecurity discussions, the idea is that malicious charging behavior could accelerate wear or damage battery components.
vulnerability
"It's then a matter of have the systems been patched to protect against what's been discovered in the lab or how serious is the vulnerability? So let me talk about it from the software vulnerability perspective."
A vulnerability is a security weakness in software or a device. If it’s found and not fixed, an attacker might be able to use it to cause problems.
A “vulnerability” is a weakness in software or systems that can be exploited to cause harm—such as unauthorized access, incorrect behavior, or denial of service. The speaker frames it as something discovered in a lab and then evaluated for severity and whether systems have been patched.
supply chain of software
"So let me talk about it from the software vulnerability perspective. You have a big supply chain of software associated with all of these systems. So the way almost everybody writes software is you're including libraries from elsewhere"
This means the software you use is often built from other people’s code. If that upstream code has security problems, your EV system can inherit them unless it’s checked and updated.
A “supply chain of software” is the chain of dependencies used to build EV-related systems—like libraries and components written by other developers. If upstream software has security issues, those weaknesses can flow into the final product unless updates and checks are done.
open source software
"So the way almost everybody writes software is you're including libraries from elsewhere that other people have developed. These are typically open source software, so then you need to continuously check"
Open source software is computer code that’s publicly shared. It’s widely used, and that means security teams need to watch for bugs or security issues that get reported over time.
“Open source software” is code whose source is publicly available and can be used or modified by others. In EV cybersecurity, open-source dependencies are common, so teams must monitor them for newly reported vulnerabilities and apply updates.
upstream software
"These are typically open source software, so then you need to continuously check whether there have been any vulnerabilities detected in that upstream software. "
Upstream software is the code you rely on from other developers. If that code has a security flaw, it can create problems for the EV system that uses it.
“Upstream software” means the earlier, third-party components and libraries that your system depends on. If vulnerabilities are found upstream, they can affect downstream EV systems unless patches and dependency updates are applied.
Linux kernel
"Right, if I miraculously found a problem in the Linux kernel and I've got to get Linux Torvalds to approve it, that might take a while."
The Linux kernel is the main “engine” of the Linux operating system. If a security problem exists there, it can impact lots of devices that use Linux.
The Linux kernel is the core software that manages hardware resources like CPU, memory, and device drivers. In EV and vehicle cybersecurity, vulnerabilities in widely used components like the Linux kernel can affect many devices that run Linux-based systems.
drones
"There's drones and other unbanned vehicles and then there's things like the Jetson-1, these personal flyers and robotaxis"
Drones are flying devices that can be controlled by software and sometimes by a remote connection. If something goes wrong or gets hacked, the risk can be different than with a car because it’s in the sky.
Drones are unmanned aerial vehicles controlled via onboard software and often via wireless links. In a cybersecurity context, drone systems have different threat models than cars because failures can have immediate physical consequences in the air.
e-bikes
"There's a much broader range of EVs. There's a lot of e-bikes and e-trikes and things like that that people are using."
E-bikes are bikes with an electric motor. If they have connected features or updatable electronics, they can also have software security issues.
E-bikes are bicycles with electric motors, typically controlled by an onboard electronic system. Cybersecurity can apply to their motor controllers, connectivity features, and any companion apps that manage settings or firmware.
e-trikes
"There's a lot of e-bikes and e-trikes and things like that that people are using."
E-trikes are electric three-wheel vehicles. They use electronics to control the motor, so software security can matter.
E-trikes are electric three-wheeled vehicles (tricycles) with motorized assistance or full electric drive. Like e-bikes, their electronic control systems can be part of the cybersecurity surface area.
robotaxis
"these personal flyers and robotaxis and stuff like that. So there's a much broader variety of electric vehicles that consumers may be engaged with either as an operator or as a passenger in various robotaxi services"
Robotaxis are self-driving cars used for rides. Since they drive using software, hackers targeting that software could create real safety risks.
Robotaxis are autonomous ride-hailing vehicles that operate with self-driving software rather than a human driver. Cybersecurity matters because attacks could affect vehicle control, passenger safety, or the service’s ability to operate safely.
Jetson-1
"There's drones and other unbanned vehicles and then there's things like the Jetson-1, these personal flyers and robotaxis and stuff like that."
Jetson-1 sounds like a small computer platform used for robotics and self-driving projects. It’s the kind of hardware that runs software that can have security bugs, just like computers do.
Jetson-1 appears to refer to NVIDIA’s Jetson platform line, which provides embedded computing for robotics and autonomous systems. These devices often run Linux-based software stacks, making them relevant to the cybersecurity “upstream fix” discussion.
airborne
"whether terrestrial or airborne. And so how do you issue a safe safety in that environment"
Airborne means operating in the air, like flying drones. If a system fails, the danger can be different than for a car on the road.
In this context, airborne refers to electric vehicles operating in the air (like drones or personal flyers). The key point is that safety and consequences differ from ground vehicles, affecting how cybersecurity risk is evaluated.
Tesla Model Y
"... accessories or apps that I use with my car, of a Model Y. The question was something like, were there any ..."
The Tesla Model Y is an electric SUV that runs on a battery instead of gasoline. It uses a phone app and connected features to control things and add accessories. The podcast is talking about how those apps and connections work and what risks or concerns might exist.
The Tesla Model Y is an all-electric compact SUV built by Tesla, widely discussed for its software-driven features and app-based controls. It comes up in the podcast around accessories and apps—specifically how owners use connected services and whether there are security or access concerns tied to those apps. That makes it a relevant example for how EVs rely on software and connectivity in day-to-day use.
Request an Explanation
Heard something you'd like explained? We'll add it to this episode.
Sign in to request explanations for terms you heard.
Want to learn more?
Browse our glossary for plain-English explanations of automotive terms, jargon, and concepts.
Help improve this episode
See something that's not quite right? Our annotations are AI-generated and can sometimes miss the mark. Click the flag icon on any annotation to suggest a correction.