• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Hardware, Gadgets, and Products / How Your Car’s Tire Pressure Monitoring System Could Allow You To Be Tracked and Hacked

How Your Car’s Tire Pressure Monitoring System Could Allow You To Be Tracked and Hacked

2010-08-15 by Jason

Many modern vehicles (2008 or newer) have a Tire Pressure Monitoring System (TPMS) that alerts the driver when the tire pressure is getting low. In fact, it’s required for all new vehicles in the US following legislation that was prompted by the 2000 Firestone tire issue. For my car, that means this little orange light comes on to tell me if a tire reports that it is low on air pressure. Right now, the light says the tire is low because I had to get a new tire after a flat and it requires a tool only the dealer has to re-sync it. Researchers have now proven that it is possible to track a car and disable a component of the electronic system through a car’s TPMS.

Each tire has a unique 32-bit code and it can be queried by the car’s electronic system. The information is broadcast wirelessly from each tire’s RFID using an unencrypted signal which travels up to 130 feet. To researchers from Rutgers University and University of South Carolina, this meant an attack vector. Somebody could essentially track a car’s location by querying the broadcast ID at intersections, toll booths, or specific locations (seedy clubs, political rallies, medical clinics, etc.) to watch where one went or prove that they were there.

The other problem with this approach is that, not only could the messages be intercepted, they could also be forged. An attacker could send the control unit impossible messages sending the system into bugs or even breaking it. The researchers were able to confuse one control unit so much it wouldn’t operate, even after rebooting, and it had to be replaced. This raises concerns, as was verified by the researchers, that a car driving next to you at 65 mph could essentially launch this attack on your computer’s electronics and disable them while they are moving or reach other parts of the electronics system like the self-parallel parking of some luxury vehicles.

Fortunately the pay off is low and the sensors required to read and interact with the TPMS are expensive at $1,500 each. The messages are also only polled at 60-90 second intervals, reducing or making the malicious task tediously long. Despite these natural limitations to exploiting this, it is an important eye opener to the auto industry that security and input validation needs to be run on all messages as more things become wirelessly networked in our cars traveling 70MPH. This research and its concluding paper was presented at the USENIX conference on Thursday.

(via ComputerWorld)

Filed Under: Hardware, Gadgets, and Products, Security and Privacy

Trending

  • Know Your 4th Amendment Rights When It Comes To Police Searching Your Phone or Computer
    In Media, Security and Privacy
  • Simple Tip: Tricks For Weather.com
    In Media, Tech Solutions
  • USB port not displaying jump drive under My Computer
    In Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • How a DirecTV bill really works in 2015 How a DirecTV bill really works in 2015
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in