The Dodge Charger is a car designed for performance, with a focus on fast driving and a sporty setup. The podcast mentions it in the context of hacking or security, meaning connected features and software can be a risk if they aren’t protected. The key point is that modern cars can have computer systems that need safeguarding.
A public EV charging network is a company/service that lets you charge your car at public stations. They handle things like who can use the charger and how charging gets paid for.
In EV charging, the “cloud back end” is the remote server-side system that stores data and runs the logic behind charging access and billing. Because it connects to chargers and driver apps, it becomes a high-value target for cyberattacks.
Personally identifiable information (PII) is personal data that can point to you as a specific person. EV charging systems may collect it so they know who is charging and can charge you for it.
EV chargers are the machines that provide electricity to your car. They also have software and connections to networks, so they can be targeted by hackers.
A private EV charger is one installed for a specific home or property rather than for public use. Because it’s often in a more controlled area, it may be harder to tamper with.
Standardized protocols are common “rules” that chargers and charging apps use to communicate. Using shared rules can make systems work together more easily, but it can also spread security weaknesses if they exist.
Tesla is an electric-car brand. When people talk about hacking, they often focus on the car’s software and how it connects to networks, because that’s where attackers may try to get in.
Malware is harmful software made to cause trouble or take over a device. In cars, it could be used to mess with systems or try to get access through the car’s connections.
Over-the-air updates are software updates that get sent to the car wirelessly. If someone could tamper with those updates, they might be able to put harmful software onto the vehicle.
Infotainment systems are the car’s screens and entertainment features—like music, navigation, and apps. If hackers get into that system, they may be able to reach other parts of the car too.
Near-field communications are the short-range “tap to connect” wireless feature. If a car uses it for access or authentication, attackers might try to abuse that tap connection if it isn’t well protected.
RFID is a radio-based way to identify something—like a key or card—without plugging it in. If the car’s RFID system isn’t secure, someone might be able to spoof or misuse that identification.
A charging station is the place/device you plug your EV into to get electricity. It’s not just a dumb outlet—modern chargers have computers and connections, so they can also be targeted or protected like other devices.
That phrase means the online computer systems that run the charging service—like logging your session and charging you for it. If someone attacks those systems, it can affect billing or access to charging.
The “grid” is the big electricity network that powers homes and businesses. If something destabilizes it, the electricity can become less stable—like the system losing control of how much power is flowing and how steady it is.
This means delivering electricity to the car in a way that could be dangerous—like the wrong amount or the wrong way. The concern is that a compromised system could make the charger or vehicle behave unsafely.
Battery degradation means the battery doesn’t last as long or can’t hold as much charge as it used to. The concern here is that unsafe charging could make that happen faster.
This means the software you use is often built from other people’s code. If that upstream code has security problems, your EV system can inherit them unless it’s checked and updated.
Open source software is computer code that’s publicly shared. It’s widely used, and that means security teams need to watch for bugs or security issues that get reported over time.
Upstream software is the code you rely on from other developers. If that code has a security flaw, it can create problems for the EV system that uses it.
Drones are flying devices that can be controlled by software and sometimes by a remote connection. If something goes wrong or gets hacked, the risk can be different than with a car because it’s in the sky.
Robotaxis are self-driving cars used for rides. Since they drive using software, hackers targeting that software could create real safety risks.
Term
Jetson-1
Jetson-1 sounds like a small computer platform used for robotics and self-driving projects. It’s the kind of hardware that runs software that can have security bugs, just like computers do.
The Tesla Model Y is an electric SUV that runs on a battery instead of gasoline. It uses a phone app and connected features to control things and add accessories. The podcast is talking about how those apps and connections work and what risks or concerns might exist.
LIVE
Hello everyone and welcome to Kilowatt, a podcast about electric vehicles, renewable
energy, autonomous driving and much, much more.
My name is Bode and I am your host and on today's episode, we have an interview, but
before we get to that, just kind of want to give a little introduction here.
So at the moment, we live in a very hyper connected world, even compared to what it
was five years ago.
If you drive an electric vehicle or really any modern vehicle nowadays, you're not just
driving a car, you're driving a computer that's constantly connected to the internet and it's
collecting data and sending it back to, you know, like the mothership, whatever the mothership
happens to look like.
Now this does bring a ton of convenience for sure, but there is a downside and that downside
is a whole new landscape of different vulnerabilities that can come from software exploits or even basic
social engineering, which is something we'll talk about in this episode with our guest,
Dr. Steven A. Wright, who honestly has a very unique background and perspective on this.
Dr. Wright holds an MBA, which is impressive in its own right, but he is also, he has a
PhD in computer engineering and he has a law degree.
So this is, again, a very unique perspective.
He specializes in data governance, cybersecurity, and he helps organizations manage the gap
between legal problems and technical execution.
He's also the author of a book called Securing Your Data Supply Chain, which I'll put links
in the show notes to all of this.
And in this particular episode, we're going to talk about security risks surrounding EVs,
e-bikes, autonomous vehicles.
We'll talk about different threats when it comes to deep fakes and data poisoning.
This is a very accessible interview.
We don't dive deep into any of these topics, but what I wanted to do is have Dr. Wright
on so that we can discuss this so we can keep everybody's, we'll say, digital hygiene nice
and tight.
There are so many bad actors out there and the more connected our world becomes, the
more vigilant we need to be.
So having said all that, let's welcome Dr. Wright to the show.
Glad to be here.
Thanks for having me.
Stephen, you have a very unique background.
I don't, I'm not, I've had lawyers on the show.
I've had people who are involved in like cybersecurity on the show.
I don't think I've had somebody who does all in one.
So why don't you tell people just a little bit about your background?
Sure.
So my educational background, I have a MBA, a PhD in computer engineering and a law degree.
My main focus at the moment is, well, it's really around the sort of problems that companies
get into where they need people with all three expertise.
So typically I'm helping one part of the organization translate what's going on in
another part of the organization and helping them sort out those problems.
In general, this tends to be things in cybersecurity or the legal issues around that or the data
governance, again, the legal issues around that, trying to explain the legal problems
to the technical folks and the technical issues to the legal folks.
Now that is an amazing way of putting that because obviously if you're an engineer, you're
not going to speak lawyer.
And if you're a lawyer, typically not going to speak engineer.
And there's lots of room in between that to have misunderstandings.
So that's fantastic.
And both groups tend to get very upset when the CEO says, but what about the business?
Why are we making money?
Yeah.
Yeah.
I would imagine it's even worse when you get a marketing person in there in that meeting.
Yeah.
They have a different access of viability, yes, but that comes with the territory trying
to figure out who's your audience and what they're looking for.
But today we're talking about electric vehicles.
Yeah.
Let's start on that because we're living in a much more connected world than we were
even five years ago.
If you have an EV, there are several access points that could be a vulnerability.
You could have somebody who's hacked a charger, for instance, and maybe that's a vulnerability
or some small part that is a connected part that some supplier didn't secure in terms of
a way in.
So let's talk a little bit about, you did some research on some different vulnerabilities
with electric cars.
Do you want to start us off with those?
Sure.
I'm glad you mentioned the charging because it's more than just the electric car and indeed
there's more things than just cars to worry about.
It really does help to think about the broader ecosystem.
So with your electric cars, you've typically got some charging arrangement.
Otherwise, your car is a very expensive one somewhere and that could be home charging
or that could be some public charging network.
And typically those charging networks have cloud back ends and some charging system operator
that's administering who gets to use those charging systems.
And once you get to that point, then you've got to have personally identifiable information
about which accounts getting charged, how do you identify who it is that's making use
of the service and preserve all that data from a sort of payments perspective.
And so those, the charging points themselves and also the cloud back ends and the apps
that access those cloud back ends, all of those things become potential target areas
for attacks of various kinds.
And there have been some breaches of ChargePoint operators that have exposed the sort of PII,
personally identifiable information of owners of EVs, for example.
So that's one area of vulnerabilities.
There's other issues around EV chargers themselves.
The public EV chargers are perhaps a little more robust than the private ones
because you tend to have some physical security around the private EV charger.
So it's typically inside your garage, although it doesn't have to be.
You could put it outside and let your neighbours use it.
But there's those issues.
There have been cases where people have attacked public EV charger locations.
There's Cabinet Smilers out of the road where you can plug your car in, I guess,
from the early days of the initial EVs, a lot of the software to access the charges
was all proprietary.
But there have been some protocols standardised around communications with charging systems.
These are more focused on the mechanics of getting the data backwards and forwards
that they need to get their systems to operate.
And they've been criticised in terms of the level of encryption and authentication
that's associated with them.
So they may not be as rigorous from a system point of view as you'd like to see.
Yeah, I don't think a lot of people, I mean, people typically who listen to this show
and other shows like this have a better understanding in general.
But I don't think a lot of people have an understanding of,
like, if you go to Joe Bob's Charge Point in, you know, wherever,
we'll pick Tempe, Arizona, that's just where I live.
And there are so many layers of different organisations.
There's somebody that's taking and processing your credit card.
There's the company that built the cabinet.
There's, like you said, the folks on the cloud side.
There's folks monitoring it to make sure that it's not down.
And all of these things, it's not all necessarily the same company
like Tesla would typically be.
They built everything.
I'm sure they probably still use some third party stuff,
but for the most part, it's Tesla's supercharger.
But that doesn't necessarily mean that's going to be the case
for every Charge Point operator out there,
which, like you said, leaves a lot of room for exploiting vulnerabilities.
Yeah, the more people you have in the chain,
the more attack points there are between all of those parties.
And I guess that's maybe perceived as a strength for somebody like Tesla
that has the sort of soup to nuts approach.
Have you ever heard of any sort of malware or anything like,
even through Pondone or some other contests like that,
where they're able to put something on the vehicle itself
through the charger or vice versa?
I don't know of a specific attack against the vehicle coming through the charger.
There have been attacks.
A lot of vehicles have not just a charger connection,
but also have over the air software updates.
And so that's another attack factor.
And there have been some compromises there.
There's been compromises through systems on the vehicle,
like the in-vehicle entertainment, infotainment systems.
Sometimes those have been hacked.
And then once they get that compromise system in the vehicle,
then it can move elsewhere within the vehicle into other systems.
And if you go around the vehicle and think of what other communications entry points
are there into the vehicle, there are contactless interfaces
to sometimes both the chargers and the vehicles.
And sometimes those can be exploited.
So those are things like near field communications and RFID interfaces.
They typically don't have as much security as some of the more rigorous protocols
for more rigorous communication protocols or banking security type protocols.
I think the other dimension to think about is what's really the target of the attack.
Is it the vehicle itself?
Is it the charging station?
Is it the back end systems with the payments?
Are you trying to, with the charging station and even the vehicle attacks,
is it really against those devices or are you trying to destabilize the grid in some ways
from the power by having power attacks on the grid?
Yeah?
Or are you trying to do some unsafe power delivery into the electric vehicle itself?
Whether that's to destroy other components or degrade the batteries.
So there's a lot of different targets associated with this as well.
It's not just a financial attack on somebody's account or some provider in the chain.
Now, I've been doing this for almost 10 years now.
I haven't really heard of anything in the wild.
Are these theoretical or are these just things that people have done in a lab
or have we seen some of these things out in the wild?
There's been some of these things out in the wild.
Not all of them, but some of them, I think all of them have been done in the lab.
It's then a matter of have the systems been patched to protect against what's been discovered
in the lab or how serious is the vulnerability?
So let me talk about it from the software vulnerability perspective.
You have a big supply chain of software associated with all of these systems.
So the way almost everybody writes software is you're including libraries from elsewhere
that other people have developed.
These are typically open source software, so then you need to continuously check
whether there have been any vulnerabilities detected in that upstream software.
And so most software development organizations have been in various stages of maturity
trying to follow some government directives about trying to have a more rigorous bill
of materials for the software components in their supply chain to understand what these
components are.
Are they on the latest versions?
Have they updated everything and so forth?
But it really is an ongoing challenge for the software developers to keep that stuff
up to date because it's not just the software they're developing.
It's all of these other pieces from upstream have an ongoing risk of vulnerabilities being
created either from newly introduced code for feature upgrades in these other patches
or it's somebody finally discovered a vulnerability in something upstream and it takes time to
get those things patched and rolled through to your production environment.
And so this is the kind of thing that you may have seen some headlines from Anthropic
with their Mythos product where they discovered a lot of vulnerabilities that were existing
in code bases.
So that's something that needs to be resolved and it's not always easy to resolve those
vulnerabilities directly from the final users of the library because it's managed by some
upstream party that may take time to get fixes injected.
Yeah and for folks who don't know what Mythos is, it's a tool that Anthropic released to
like 20 different companies to find vulnerabilities.
It's really good.
It's an AI tool, really good at finding different vulnerabilities but not everybody has it.
Like a small company like Slate for instance, although Slate is mostly owned by Jeff Bezos
so maybe there could be some sort of deal on that side of things.
But a small company is typically not going to have it.
It's typically given to like an HP or a Microsoft, I think.
Yeah I mean there are other tools that do similar things.
It's just, I think you could use OpenAI's codecs to do something similar and I think
there are other tools that aren't AI related that help you search for software vulnerabilities
of different types as well.
The point is how rigorously do you search and how quickly can you act on the results
of the search?
I mean ultimately it's a big advantage but also if you have a small team fixing these
bugs and all of a sudden all of these organizations are now having to deal with how do we fix
all of these things that we didn't even know, didn't even have a clue were a problem.
Yeah and it takes time to do that and you may not have direct control of an upstream
source library.
So for your listeners who aren't directly in the software business, let me try and explain.
Usually particularly in open source projects you have a large community of volunteers that
are maintaining that software and depending on how active the community is, you may have
a mechanism where you can report a bug and then over time those folks will work on their
bug list and improve the software and they have people reviewing their checks to make
sure they're doing what the fix is supposed to do but these are all either unpaid volunteers
or there are other companies that are in the ecosystem that have a financial incentive
to...
You'd also think like a moral right because they are using from the open source and there
is an expectation that you contribute back to the source code.
Yeah but there's a...
What are the project?
The issue is the sort of response time and performance, how quickly can you get a fix
and that's even if you're XYZ EV vehicle company and you discover a fix and you've got a big
team of software engineers but the problem is in some upstream software community, if
you're coming in new to that community, how quickly can you get a fix through that community's
process?
Oh yeah, that's a good point.
Right, if I miraculously found a problem in the Linux kernel and I've got to get Linux
Torvalds to approve it, that might take a while.
Just a part of the challenge of mitigating these things but the good news is lots of
people are working on fixing these things as problems become detected.
And I kind of derailed you a little bit.
I don't want to get too far off topic because I apologize.
Now with some of the other vulnerabilities that you were researching, is there anything
else that stands out to you?
There's several things.
Let me go back up at a very macro level and you talk about EVs as a category and your
mind tends to go to things like cars like Teslas.
But there's a much broader range of EVs.
There's a lot of e-bikes and e-trikes and things like that that people are using.
There's drones and other unbanned vehicles and then there's things like the Jetson-1,
these personal flyers and robotaxis and stuff like that.
So there's a much broader variety of electric vehicles that consumers may be engaged with
either as an operator or as a passenger in various robotaxi services, whether terrestrial
or airborne.
And so how do you issue a safe safety in that environment, right, because there's certainly
different consequences if a drone falls out of the sky versus if your stereo on your Tesla
or whatever brand EV suddenly starts playing the wrong channel.
So there's a much broader range of consequences here.
And then there's the sort of consumer protection for information.
You talked about financial information.
But I think there's other privacy issues around location, for example.
And so there's quite a few different areas to worry about.
Sure.
With that, if we were to look at...
We could turn this into a very scary episode and I don't want...
All of these things exist, but they exist for anything that's...
Even things that are airgapped, you can still have somebody come inside your airgapped network
and throw a USB in and put malware on the system.
This stuff happens everywhere and they're dedicated people who are trying to stop it
and they're dedicated people who are trying to cause more problems, whether it's like
you said, to steal information, personal information or to cause chaos.
But with that, what do you see in terms of different vulnerabilities in the supply chain?
We kind of touched on this a little bit in the beginning.
Like back in the day when photo frames came out where you can just hook a frame up to Grandma and Grandpa's...
An online frame, a digital frame to Grandma and Grandpa's house.
Meanwhile, it had no security and it would just left the whole network open to different types of vulnerabilities.
Not that our average person would necessarily have to worry about that.
But the same kind of thing can happen in a supply chain.
The smallest part from the smallest company could potentially be an entrance point for an attacker, like you said.
How do we shore up that supply chain?
I think you really have to have all of the players in your supply chain take cybersecurity seriously.
Maybe that has a number of different ways it gets expressed.
It may be contractual requirements on subcontractors who are supplying components.
For example, it may be industry standards or government regulations around understanding your bill of materials
and keeping things within a certain range of what's the currently recommended versions.
Maybe educational as well for the users of these systems to be aware of what kinds of things are out there
and the ways in which scams can happen so they can be vigilant for that kind of thing.
Ooh, yeah. That is a good point.
What is it called when you hack a person?
I'm blanking.
So, social engineering is another whole direction we could spend a long time on.
But I think the thing I would say there is as the underlying systems get hardened,
the easiest vulnerability remaining is the people at the top.
More and more attacks target the people rather than the systems.
That's an even bigger problem with the advent of a readily accessible AI systems
because it makes it so much easier to generate things like deepfakes,
to engage in things like data poisoning or data suppression,
which it's errors of commission and omission in the information that's made available to you.
So, you need to be vigilant for those kinds of things.
What would that look like?
What would somebody working that kind of an attack on somebody,
what would that look like and what should somebody look out for?
Well, the short answer is I wrote a whole book on that.
No, no. I know. I did research.
So, deepfakes is the obvious one.
The first thing is awareness.
You've got to be aware that this stuff could be happening.
So, from a consumer perspective, the example I tend to use that people resonate with
is something like revenge porn, whether that's your favorite political enemy
or whatever dancing in the inappropriate clothing
or a more serious deepfake where there have been some attacks on companies
where you had the CEO in a Zoom call where all of the other participants
were deepfake videos and not real people scamming the company.
Data suppression and data poisoning is messing with the information you're receiving.
So, just because you make an inquiry on Google or chat GPT or whatever
and get some answer back, what can you do to verify that information?
Can you ask somebody else?
Can you verify it in some other way?
The simplest example is if you're using an AI system to collect your information
all of these ethical guardrails and safety rails that the promoters of these systems talk about
are in some way filtering or misleading the results coming out of those systems.
So, they're either emitting information or they're putting new information in which is not correct.
So, for example, there were some cases of people generating images of George Washington
but he was portrayed as a black skin color which was factually incorrect, right?
So, that sort of thing going on and this various efforts to suppress information.
The most obvious suppressions tend to be political type topics.
You could imagine if you're using an AI system to do shopping for you
and the vendor of your AI system has kind of deal with vendors in the area
that you're asking to promote their products and they're being returned and not competitive products.
You could see how that could be an incentive that would not be helpful to consumers
and so you need to be aware of that kind of thing.
So, with this, right, it's not like there's not a lot you can do if someone throws malware on a charger, right?
You as a person, there's not a lot you can do to protect yourself.
This kind of all relies on the companies that are doing all this.
Every one of those companies that are in the stack that we talked about,
all the different layers that's on them to make sure that their security is tight.
What are some things that consumers can do up to and including being able to report
when they think something is compromised?
Yeah, I think it's just firstly awareness and then knowing who to report things to.
So, most of the chargers that I'm aware of, you tend to be using an app with them
rather than putting a credit card into the machine kind of operation
because there have been card skimmers and things like this in the ATM industry
and I think they've generally tried to avoid that in the ChargePoint operators.
But if you have apps on your phone, then you as the operator of your phone
need to maintain reasonable operational hygiene or security hygiene on your phone.
So, not downloading spurious apps that you don't trust from wherever,
keeping your passwords safe and not repeating them,
that kind of security hygiene which is regrettably not as widely practiced as it should be.
But I think that's kind of the things that are within your control
and then being careful about what information you're sharing and how you're sharing it.
So, that may unfortunately mean you need to read the terms and conditions
of all of these apps that you've put on your phone to see which ones they're sharing with
and which things you can actually turn off.
I was just asked recently to go on a show to talk about different accessories
or apps that I use with my car, of a Model Y.
The question was something like, were there any apps that you used to check your car
in more detail than what Tesla's app gives and blah, blah.
And I was like, I don't do any of that.
First of all, I'm not putting anything on my car that's going to void my warranty
because I don't have that much money to eat that.
And second of all, I don't know if I open up this to this third-party company.
And early on, I had several companies, app companies that were like,
hey, do you want to use this app?
I didn't have a Tesla at the time, so it really wasn't a big deal.
But I still wouldn't have used it because you're just Joe working in your bedroom,
in your spare bedroom.
Like, I don't know what you've done to make sure that this information isn't getting out
and I don't know what you're doing with this information.
This seems like a terrible idea.
So yeah, I don't throw any third-party stuff on my car or apps
because there are plenty of apps out there that will surface just tons of information
about what your car is doing.
And that's cool, but who else is getting that information?
Like, GM got in trouble for sharing customer data to insurances.
You know what I mean?
There's lots of stuff out there that we don't need more data just to leak out.
And we don't need to be the cause of that leak.
Yeah, I mean, if you're...
I guess that is another point.
I mean, you need to consider that you could be the cause of the leak.
So it may be that this other app is perfectly legitimate
and it's taking all good efforts to take care of things on its end.
But because their app is on your phone and your phone gets hacked,
then you've not only exposed your information,
but potentially you provide a vector into somebody else.
So yeah, it's sometimes the ease of use gets ahead of thinking through the consequences.
No, 100%.
And if you're tired and you're hungry and you're just trying to get something to work,
all of a sudden, all of those spidey senses that you might have,
they go away real quick if you're just like,
okay, I'm just going to turn off all of this safety so I can just get it to connect.
And then maybe I'll go back and fix it later.
Oh yeah, that happens way too often.
Which is where most organizations have layers of protection
to try to prevent you from doing that or at least do whatever is sandboxing
or scoping to minimize the blast radius when you do things like that.
And that's a lot harder for consumers to do,
most of whom don't even know what all the settings are on their phone.
Yes, I will say my wife knows almost nothing about technology,
but she is a zealot when it comes to cybersecurity.
If somebody sends her a sketchy text, she's like, hey, just be aware.
This goes out to the entire family.
My 13-year-old, my 30-year-old doesn't really matter.
It goes out to my father-in-law, it goes out to everybody.
Be aware this is happening.
She is constant vigilance with that one.
That may sound a little overkill, but I think that's better to be safe than sorry.
Security and this stuff isn't my job, it's more my hobby.
But when it comes to making sure that everything's safe, that is fully my wife.
She'll be like, have you heard of this?
I'm like, I have.
She's like, should we be worried about it?
And I was like, probably not.
We're not presidential quality.
They're not looking for us.
But we will make little adjustments here and there to make sure that,
especially my 13-year-olds, because they're young and impressionable and have phones,
make sure they're aware.
Well, Steven, thank you so much for coming on.
You mentioned you had a book.
Can you tell us a little bit about your book?
Sure.
The book is called Securing Your Data Supply Chain.
It's available on Amazon, and it talks about those emerging data threats,
the deep fakes, data suppression, and data poisoning,
and why enterprises in particular need to worry about their data governance.
And all of those threats are either generated from AR,
or they're massively magnified by the easy availability of AI systems.
And yes, you can use AI to fight AI, but you've got to be aware of the problem,
and you've got to have systems set up in your company to check the data as it's coming in
and make sure it is actually valid and not just faked in some way.
This is good information, not only for the security and CISO team,
but also everybody.
Yeah.
Now, you and me as consumers, we don't have a security team backing us up on everything.
And so it's...
Just my wife.
Exactly.
It's much more an issue of awareness and education on the consumer front
and just having a certain amount of critical thinking,
and this doesn't smell right.
For most, for the average consumer, you're probably not going to be the target
of a nation-state nefarious attacker that has the resources to do all of this stuff.
You may be the unfortunate bystander to some random script kitty
who's sent something out there that has a sufficient blast radius to capture people.
And so that's more of the kinds of things most consumers need to be aware of
and do what they can to avoid.
And that's kind of within the feasible range of control.
And so that's what I'd suggest folks worry about.
Awesome.
Where would people find you?
Are you on LinkedIn or where else are you that people can go and follow what you're doing?
Sure.
You can find me on LinkedIn or you can find me on X.
I do have a mailing list and a small YouTube channel.
So it's at Dr. Steven A. Wright on X or Twitter and on LinkedIn.
It's easy to find me.
And I'll put all of the links and the proper spelling of Steven and Wright in the show notes as well.
Fantastic. Thank you very much.
Thank you, Steven.
All right.
I want to thank Dr. Steven A. Wright for coming on and being such a great guest.
This was honestly, this is kind of, I'd like to do more stuff in the realm of cybersecurity
and EVs and autonomous driving and stuff like that.
Because I do think this is really important for us to keep tabs on.
I know a little bit, but I don't know a lot.
I mean, it's just a fraction of what somebody who actually knows what they're talking about.
I barely know a fraction of a fraction.
So it's good to get somebody on who actually knows about this stuff.
If you'd like to know more about what Dr. Wright is up to, I put all of the links in the show notes.
So it's nice and easy for you to find, because I don't know if you know this,
but there's a famous comedian named Steven Wright.
So if you try putting in Steven Wright into Google, you're going to get him 99% of the time.
So just to make it easier, I put all of Dr. Wright's links in the show notes.
So I would highly encourage you to go and follow him.
And yeah, watch it, check out his YouTube channel, follow him on LinkedIn, all that fun stuff.
And if you do, let him know you came or heard him on Kilowatt.
All right, everybody, if you want to support this show, you can go to supportkilowatt.com.
You're given two choices, Supercast or Patreon.
If you want to support the show, that's where you do it.
And all of the money goes back into the show.
None of the money from Patreon or Supercast goes back into my own pocket.
And yeah, you can sign up for as little as a dollar.
I try to keep it really affordable.
All right, I think that's it.
I hope you all had a wonderful week.
Next episode, we'll be talking news.
So be good and I will talk to you soon.
About this episode
Modern EVs are framed as internet-connected computers, bringing a new landscape of vulnerabilities—from software exploits and social engineering to deepfakes and data poisoning. Dr. Steven A. Wright explains EV charging as an ecosystem with multiple access points, including chargers, cloud back ends, apps, and payment systems that can expose personally identifiable information. He also highlights vehicle attack surfaces like OTA updates and contactless interfaces (NFC/RFID), plus why even “airgapped” setups can be compromised. Practical guidance centers on digital hygiene and verifying information.
In this episode of Kilowatt, we sit down for an engaging chat about technology law, ethics, and cyber security with Dr. Steven A. Wright. As an expert in navigating the complex intersection of law and emerging engineering tech, Dr. Wright shares critical insights into the security challenges facing the evolving EV infrastructure and power grids. We discuss the legal responsibilities of developers, the ethical ramifications of autonomous tech, and how modern architecture must adapt to protect user privacy and system integrity. Whether you are an engineer, a tech enthusiast, or simply curious about the legal frameworks shaping our future, this conversation offers a profound look at the safeguards we need today for the innovations of tomorrow.