The teams maintaining all of this usually have a LOC/headcount ratio approaching 1 million too. It's a very different threat model than the old days when every manufacturer had their own systems and trying to craft an exploit required individualized work for all of them.
With the explosion of the number of those boxes, we added more surface of attack, but the number of good security people didn't increase.
I’m gonna steal this one from you - it’s quite clever IMO
I'd trust google to maintain the security in a fleet of robo taxi's where cars can be brought in, modified or replaced relatively quickly over Tesla trying to convince individual owners to do the same...
People are too attached with property and social status stuff.
Beyond that, it seems like the nature of self driving might be one of gradual incremental improvement, where in order to actually develop it you more or less have to run a fleet of robo taxi's in different places with different climates and different road conditions.
Finally, the people most likely to deliver it are google (waymo) and I think they have zero desire to sell cars to consumers but are literally running a taxi service as we speak.
Repossessing a self driving car, on the other hand...
It would be have it self-drive from the owner's home to someplace nearby not associated with the the thieves to get it out of sight from the owner's security cameras and whatever other security cameras in the neighborhood might be watching where the gang can disable the cloud connection and then transport it by truck or driving it in manual mode to their chop shop.
From what little has been leaked, I really doubt Tesla should be enar the top.
I didn't find the Ford one specifically, but I also didn't go surfing through the many pages of results
https://old.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...
You need systems secure against teams commercially motivated attackers with 10 M$+ budgets and tens of full-time professionals working for years. Nobody in commercial IT would even dare to claim they could stop such attacks even though they are regular occurrences these days. If they do not even dare to say they can do it, why on Earth would anybody believe those vendors have, what, accidentally made things better than they think?
Ranking companies by security is like ranking the relative resistance of individual sheets of toilet paper to bullets. Sure, maybe the single ply toilet paper is not as good as the two ply, but neither of them provide objectively useful degrees of protection. And that is just talking about the bare minimum to protect against current threats.
If you can hack every Honda at rush hour to turn off the brakes, slam the accelerator, and drive slightly into oncoming traffic how many people do you think would die in the next minute before anything can be done or people informed to stop driving their cars? 1K? 10K? 100K? 1M? Does Honda survive killing more people than died in most wars? If a criminal organization demonstrates they can and will do it, how much would Honda pay in extortion to avoid being put out of existence and their executives jailed? How much security is adequate to avoid the deaths of thousands to millions? Certainly orders of magnitude more than the 10 M$ attacks that steam roll the "best commercial IT security" available today. Any reasonable number is vastly in excess of what these companies can secure today.
20 years ago, the hackers were 18 year olds demanding 300 dollars from grandmas. 10 years ago, the hackers were 28 year olds founding businesses demanding 10 thousand dollars from small businesses. Now they are 38 year olds managing teams demanding millions from billion dollar companies. Soon we will see them demanding billions if the trends continue for 5-10 more years. The software security doomsayers were right, just early. Even Mark Zuckerberg took a decade with huge piles of VC funds to get to a multi-billion dollar valuation; you have to forgive the hacking teenagers who had to bootstrap their criminal enterprises for taking so long.