BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.securityfest.com//2026//talk//MT7DSG
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2026-MT7DSG@cfp.securityfest.com
DTSTART;TZID=CET:20260528T150000
DTEND;TZID=CET:20260528T154000
DESCRIPTION:The In-Vehicle Infotainment (IVI) system is increasingly becomi
 ng the core interaction and computing platform in connected vehicles\, and
  is deeply coupled with in-vehicle networks through vehicle signal service
 s\, diagnostic channels\, and gateway policies. Engineering/Factory Mode\,
  designed for R&D debugging\, manufacturing validation\, and after-sales s
 ervicing\, typically provides highly privileged capabilities such as debug
  toggles\, logging/diagnostics\, configuration writing\, OTA-related opera
 tions\, and vehicle integration testing. If Engineering/Factory Mode remai
 ns accessible in production builds via hidden entry points\, weak authenti
 cation\, or unclear authorization boundaries\, attackers may obtain elevat
 ed privileges at low cost and expand their reach to vehicle control functi
 ons\, resulting in vehicle-level cybersecurity risks.\n\nIn this work\, we
  conduct a security assessment of Engineering/Factory components on produc
 tion IVI systems\, summarize common entry-path categories and weaknesses\,
  and evaluate the reachable control boundaries after privilege escalation 
 from the perspective of coupling between engineering utilities and vehicle
  control services/middleware We finally provide practical hardening recomm
 endations for production deployments to reduce vehicle-level risks introdu
 ced by engineering functions while preserving serviceability and operation
 al efficiency.
DTSTAMP:20260625T183727Z
LOCATION:Main Stage
SUMMARY:From Convenience to Consequences:  Vehicle-Level   Cybersecurity Im
 pact of Engineering Functions - Yuqiao Ning
URL:https://cfp.securityfest.com/2026/talk/MT7DSG/
END:VEVENT
END:VCALENDAR
