It may help if you think of your car as just another server. Any connection between the server and client can be encrypted of course, using well-known tools. Besides that, the car can be made to not accept updates that are not signed by the manufacturer, so your only exposure is to the manufacturer.
Of course someone may have physical access to your car and be able to write new software locally, but then they may also be able to do mechanical sabotage, so it's not a new risk.
So you basically have to trade off one kind of security (the manufacturer can update my car remotely) with another (security bug announced in the software my car runs, I am now a sitting duck).
It definitely takes a shift in perspective, but in the brave new world where cars (and other things) run millions of lines of code, over-the-air updates are a necessity. (but of course I'd say that).
I've written a bit more about this conundrum here - https://resin.io/blog/you-cant-secure-what-you-cannot-update...
[1] https://www.usenix.org/system/files/conference/usenixsecurit...
Device has a per-device key burned in at the factory and the private keys sit in a manufacturer HSM. Updates are signed by the manufacturer and also encrypted with the per-device key for each device. The device itself will have tamper-proof (well, as tamper resistant as they can be) chips and a secure boot-loader that will do all the dirty work.
Nothing is ever 100% secure, but you shouldn't believe it is something similar to a piece of software on your computer where it is just "hit this https URL for the executable and run it". Or maybe you should believe that and force manufacturers to come out and state otherwise :)
I'm not saying your comment is ungrounded, I'm just saying that a process locking up or sending wrong information is not likely, or even possible, to net you 100% loss of use in your brakes.
Cars are the most highly regulated consumer product on earth. Brake systems nor Tesla fly under the radar here.
I felt that way too, til I watched few of the talks from the people that were doing the testing of Toyota electronics after all of the unintended acceleration problems.[1]
Did you realize, for example, that while there are coding standards that one should adhere to while doing embedded systems-critical stuff (like MISRA guidelines), there are no requirements for automotive companies to adhere to any such software standardization, and that it's left up to the individual manufacturers to decide upon standards?
The US automotive industry is unique in that it doesn't have a rigor requirement for software. Planes and heavy equipment do have such requirements within the states.
Toyota didn't even use bug tracking or source management, and used their own software guidelines. That's scary given the complexity is so high that the entire system cannot be fully tested in a feasible way.
Atop the software issues, the hardware ECM was made in such a way so as to make the secondary 'cross-checking' processor basically useless. Both CPUs were checking the same I/O, if that was the fault then BOTH would read bad data, and the hardware was made in such a way as to make that impossible to work around.
An old Camry isn't anywhere near as complex as a modern electric car, and I personally have more faith in Tesla than I do Toyota, but it makes me want to push US legislation into requiring US auto manufacturers into following the strict software guidelines that are available to them.
Fun trivia: MISRA guidelines were originally pushed by the automotive industry in the early 90s/late 80s, and now they are one of the only critical systems groups to not follow them.
[1]:http://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_s...
As far as Toyota is concerned, right now I'd trust them as much, of not more, than Tesla. Tesla has been doing great things and doesn't have much, if any, of a bad track record for failures. However, you have to realize that Toyota has also been making cars far longer than Tesla, produce more, and has one of the best reliability ratings in the industry.
I believe Tesla can achieve this or better. However, it's hard to compare when Tesla doesn't have the numbers that Toyota has.
Which is fine, but I'm unnerved hearing the people who seem to consider Tesla infallible. 'They'll never make a mistake like that, they're Tesla!'
Errors probably means errors here. As in yeah, most recently trying to land a booster on a barge and missing.
Mistakes happen. The wrong number in a configuration somewhere and everyone's car suddenly has a vampire that sucks down the battery 50% faster, or causes a misreading of wheel speed for anti-lock braking, or etc.
Once you trust you trust, and if you don't, you don't update. Not much space between (for me) ...
I have no idea how Tesla does this, but in most cases you're deal with deterministic software or real time OS's, massive testing suites, coding guidelines that guarantee positive outcomes, etc.
JPL published its guidelines. Do you think Google and Apple are this stringent with their mobile toys? Of course not. They have zero economic interest to do so. They just have to make things good enough that kids and housewives won't complain too much.
http://spinroot.com/gerard/pdf/P10.pdf
or more specific to autos
http://en.wikipedia.org/wiki/MISRA_C
Mistakes will always happen, but Apple or Google are not good examples of what well written software is.