“If you’re going to get those wrong, then everything just falls down.”
A major automaker’s dealership portal had authentication so broken that attackers could modify the login page code to bypass security entirely. The result was access to customer data and remote vehicle control across over 1,000 dealerships. This is what happens when car companies rush to add internet connectivity to everything while treating security as an afterthought. Your car is now just another poorly secured IoT device with wheels.