Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

The Car Hacker’s Handbook isn’t a guide, it’s a wake-up call to automakers

Craig Smith readily admits that he’s paranoid by nature. As a digital security professional, paranoia is part of the job description. But unlike most security professionals, Smith is committed to unlocking secrets and demystifying what goes on in your car’s operating software. The theory goes that the best way to improve the code that keeps your car running is to get it out in the open and let everyone take a whack at it.

To help enthusiasts who want to know what’s really going on under the hood, Smith has written The Car Hacker’s Handbook, available now in both paperback and e-book editions from No Starch Press. The book is currently the top seller in its category on amazon.com. Digital Trends caught up with Smith for a discussion of the issues he raises in the book.

Craig-Smith“It’s about taking control of what you own,” Smith told Digital Trends. “Back in the day, automobile owner’s manuals had complete wiring diagrams, all the part numbers, and everything you needed to make any modification you wanted. Now they don’t. This book is for traditional mechanics who want to get into the electronic aspects of cars but have been stymied by the lack of information about this aspect and the taboo around it.”

The Car Hacker’s Handbook is a comprehensive guide to reverse-engineering and understanding the digital control systems in a modern vehicle. The book includes information on building your own test beds for analyzing the software in a vehicle’s control computers as well as background information on the vulnerabilities inherent in infotainment and two-way connectivity systems.

The result is a practical how-to guide for understanding and manipulating the software that controls virtually every function of a modern car.

Black hat, white hat

As you read The Car Hacker’s Handbook, the first thing that comes to mind is trouble. Malicious individuals could use the information and techniques described in this book to take control of people’s automobiles and use that control to demand ransoms, cause accidents, or even commit terrorism.

“If you knew that there was a vulnerability in a particular make and model of vehicle, you could have that ready to go as the car drove by.”

“The risk concerns me,” Smith admited. “But one thing I’ve learned is that keeping things to yourself works for the black hats. Once you shine a light on things, they get fixed. So if you’re not talking about it, that’s a worse situation. Sometimes it’s off-putting for industries when a researcher says there’s a problem with a product, so we do have to be sensitive. We have to play nice so we can all get safer sooner.”

Yet as previous researchers and hackers have shown, the potential for trouble is very real.

“Your research really needs to happen on test equipment that you build yourself. In that regard, you’re not actively hacking a vehicle that’s driving down the road,” Smith tells Digital Trends. “That being said, it is feasible to make an exploit using your own research and your own equipment that would be able to be deployed quickly. If you knew that there was a vulnerability in a particular make and model of vehicle, you could have that ready to go as the car drove by.”

Sizing up the problem

The average new car now carries about 100 million lines of software code. All that code is required to operate various systems throughout the vehicle, including engine and transmission management, traction and stability controls, and more. About 20 million lines of code are required just to run a standard navigation, infotainment, and connectivity system, and that’s one of the biggest areas of vulnerability.

DEF CON 23 - Charlie Miller & Chris Valasek - Remote Exploitation of an Unaltered Passenger Vehicle

Researchers Chris Valasek and Charlie Miller successfully hacked several cars through their data communications modules and in some cases managed to take substantial control of moving vehicles. Valasek and Miller’s exploits raised concerns about inadequate security provisions throughout the automotive industry, and prompted automakers to tighten up their safeguards.

What Smith’s book does is expose the tools and techniques that researchers use to identify and then exploit weaknesses in production cars. Starting with the CAN bus that most modern cars use as an onboard network, Smith takes the reader through the steps necessary to access the engine management system as well as the infotainment and communications systems. The book also covers how to write exploits and transfer them into a vehicle via the vehicle’s wireless connectivity systems.

Crowdsourcing security and compliance

One key result of the book is less obvious: The techniques of research and analysis described will enable widespread analysis of any automaker’s operating code. This is good, the author thinks.

The bar for automotive software quality just got raised.

Smith believes that private researchers will spot security holes, but also could potentially uncover intentional malfeasance.

“If you get more eyes on the problem, it’s harder to get away with stuff,” Smith pointed out. “Even just the threat of knowing that people are allowed to look at things will make others think twice about putting backdoors in place.”

Performance tuners and the EPA

The book covers engine management programming and how to alter the manufacturer’s code to increase a car’s power output. This is an area where the amateur may skirt very close to violating Federal law and regulations imposed by the EPA and Dept. of Transportation. It is illegal to tamper with any emissions control device, and a car’s engine management software is very much part of the emission control system.

“Of course it’s not good to add pollutants, but at the same time, we’re talking about 1 percent of people who are performance tuners,” Smith explained. “If we’re going to lock out people because of that fear, then you’re going to miss people like Volkswagen, which disabled an entire fleet of vehicles. In my mind, when the EPA came out with those rules, it wasn’t for the person who makes a race car and runs it around on Sunday. It was for fleets of vehicles.”

Open garages and responsibility

Smith is one of the founders of Open Garages, a loose organization dedicated to providing public access, documentation, and the tools necessary to understand today’s modern vehicle systems. The organization is seeking to bring the ethos of open source software to the automobile world, and this book is part of that effort. Smith is careful to caution that if you break something in your car, you cannot expect the automaker to fix it for you.

Vehicle Networks

“I recommend a switch or a jumper on the vehicle’s computer that disables the forcing of code-signed updates [from the automaker],” Smith said. “Now granted, when you do that, the secure boot loader should mark the car as tainted. So if you cause any damage to the engine, it’s on you. If you sell the car to anyone else, it would be obvious that the car was in its original factory-safe state or if it had been tampered with. That’s the same model Google uses with Chromebooks. I like that model, and I’d really like to see that.”

Don’t steal this book

Every so often, a book is published that pushes the boundaries of a controversial topic. Abbie Hoffman’s classic Steal This Book, published in 1971, detailed how to use and abuse government anti-poverty programs and charities, including how to cheat and steal effectively.

At the time, outraged people warned that Steal This Book posed a serious threat to continued freedom of the press — but it didn’t happen that way. People did steal the book, which led to bookstores keeping it under lock and key. Today, it’s a collector’s item and the material in it is simply quaint.

The Car Hacker’s Handbook is much the same. The information in this book is controversial, but not truly threatening. Malefactors who want to steal your car aren’t likely to spend months decoding assembly language programming to take control of your anti-lock braking system – they’d rather jump you at a stoplight.

This book is a wake-up call to automakers, legislators, and regulators, announcing the fact that technology enthusiasts can and will continue to fiddle with their cars. The bar for automotive software quality just got raised.

Jeff Zurschmeide
Former Digital Trends Contributor
Jeff Zurschmeide is a freelance writer from Portland, Oregon. Jeff covers new cars, motor sports, and technical topics for a…
Buy Now, Upgrade Later: Slate’s $25K Truck Flips the Script on EVs
many hybrids rank as most reliable of all vehicles evs progress consumer reports cr tout cars 0224

A new electric vehicle startup—quietly backed by Amazon CEO Jeff Bezos—is building something bold in Michigan. Not just a car, but a whole new idea of what an EV company can be. Slate Auto is a stealthy new automaker with one mission: ditch the luxury-first EV playbook and start from the affordable —which most drivers actually seek.
The start-up has been operating out of public sight since 2022, until TechCrunch found out about its existence. Of course, creating a little mystery about a potentially game-changing concept is a well-tested marketing approach.
But Slate truly seems to approach EVs in a very different way than most: It isn’t debuting with a six-figure spaceship-on-wheels. Instead, it's targeting the holy grail of EV dreams: a two-seat electric pickup truck for just $25,000. Yep, twenty-five grand. That’s less than a tricked-out golf cart in some neighborhoods. Slate is flipping the Tesla model on its head. Tesla, but also the likes of Lucid, BMW, and to a certain degree, Rivian, all started with high-end vehicles to build brand and bankroll future affordable car. But Slate wants to start with the people’s pickup—and letting it grow with you.
This isn’t just a cheap car. It’s a modular, upgradeable EV that’s meant to be personalized over time. Buy the basic model now, then add performance, tech, or lifestyle upgrades later—kind of like building your own dream ride one paycheck at a time. It’s a DIY car for a generation raised on customization and subscriptions. The company even trademarked the phrase: “We built it. You make it.”
Backing up this idea is an equally bold strategy: selling accessories, apparel, and utility add-ons à la Harley-Davidson and Jeep’s MoPar division. You’re not just buying a vehicle; you’re buying into a lifestyle. Think affordable EV meets open-source car culture.
Slate's approach isn't just novel—it's almost rebellious. At a time when other startups risk folding under the weight of their own lofty ambitions, Slate is keeping things lean, scalable, and customer focused. The company reportedly plans to source major components like battery packs and motors from outside suppliers, keeping manufacturing costs low while focusing energy on design, experience, and upgrade paths.
Sure, it’s all been kept under wraps—until now. With plans to begin production near Indianapolis by next year, the wraps are about to come off this EV underdog.
While, at least in spirit, the U.S. market has been dominated by high-end EVs, Slate’s “start small, scale with you” philosophy might be just the jolt the industry needs.

Read more
Kia EV9 and EV6 now fully qualify for the $7,500 tax credit – except for one trim
Kia EV 9

As Kia reported record first-quarter sales, Eric Watson, Kia America VP of sales, made a point of painting a rosy picture for the future: Now that the latest versions of its two best-selling electric vehicles, the EV9 and the EV6, are in full-scale production at Kia’s plant in Georgia, the road is paved for further sales growth.
After all, when Kia announced it was switching production of the EV9 to the U.S. from South Korea in 2023, it largely based its decision on its EVs being eligible for the $7,500 tax credit on new EV purchases offered under President Biden’s Inflation Reduction Act (IRA).
But the EV9’s battery still came from South Korea and China, which meant it would only receive a partial tax credit of $3,750. Starting this year, the EV9 can qualify for the full $7,500 credit, as Kia switched the sourcing of its battery to its Georgia plant.
As for the EV6, 2025 marks the first time its production takes place stateside, and most of its trims have also become eligible for the full tax credit.
However, there are notable exceptions: Both the EV6 and EV9 GT trims, which are known for providing more horsepower - ie, being faster – and offering a “more aggressive styling and accents”, won’t qualify at all for the tax credit: That’s because production for those vehicles remains based in South Korea, according to CarsDirect, which cited a Kia bulletin to its dealers.
The full credit should still be available for those who lease the vehicles, as leasing does not have the same sourcing requirements under the IRA.
Another big unknown for the GT trims is whether the U.S.’ 25% tariffs on all imported vehicles will again be applied. On Wednesday, President Donald Trump paused most tariffs announced in early April for 90 days.
While prices for the new EV6 and EV9 have yet to be revealed, the combination of the tariffs and the inegibility for the tax credit could seriously dent the appeal of the GT trims.

Read more
AR driving at last – this Android Auto feature could mean navigation on smart glass
AR driving

A heads-up display while driving has always been the dream use of AR glasses and now it looks like that could soon become a reality.

Looking at a screen for navigation while driving is undoubtedly a hazard. So overlaying guidance on glasses, that let you keep focused on the road, makes a lot of sense.

Read more