Copyright © 2017 W3C ® (MIT, ERCIM, Keio, Beihang)
Vehicle's interet connection is the biggest attack surface
Sound Practices
We are building a framework for 3rd party apps (FB, Waze, Pandora)
See yesterday's Genivi / W3C Liaison presentation
Remember when you could account for every network connection?
Connected vehicles should be able to account for every connection
Possible package requirements for 3rd party apps. Suggestions partially address OWASP top ten
merely using SSL alone is not enough
Another idea
Continued
Hearing some are considering allowing full open browsing
Purpose of this presentation was to start the conversation