• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Hardware, Gadgets, and Products / How Your Car’s Tire Pressure Monitoring System Could Allow You To Be Tracked and Hacked

How Your Car’s Tire Pressure Monitoring System Could Allow You To Be Tracked and Hacked

2010-08-15 by Jason

Many modern vehicles (2008 or newer) have a Tire Pressure Monitoring System (TPMS) that alerts the driver when the tire pressure is getting low. In fact, it’s required for all new vehicles in the US following legislation that was prompted by the 2000 Firestone tire issue. For my car, that means this little orange light comes on to tell me if a tire reports that it is low on air pressure. Right now, the light says the tire is low because I had to get a new tire after a flat and it requires a tool only the dealer has to re-sync it. Researchers have now proven that it is possible to track a car and disable a component of the electronic system through a car’s TPMS.

Each tire has a unique 32-bit code and it can be queried by the car’s electronic system. The information is broadcast wirelessly from each tire’s RFID using an unencrypted signal which travels up to 130 feet. To researchers from Rutgers University and University of South Carolina, this meant an attack vector. Somebody could essentially track a car’s location by querying the broadcast ID at intersections, toll booths, or specific locations (seedy clubs, political rallies, medical clinics, etc.) to watch where one went or prove that they were there.

The other problem with this approach is that, not only could the messages be intercepted, they could also be forged. An attacker could send the control unit impossible messages sending the system into bugs or even breaking it. The researchers were able to confuse one control unit so much it wouldn’t operate, even after rebooting, and it had to be replaced. This raises concerns, as was verified by the researchers, that a car driving next to you at 65 mph could essentially launch this attack on your computer’s electronics and disable them while they are moving or reach other parts of the electronics system like the self-parallel parking of some luxury vehicles.

Fortunately the pay off is low and the sensors required to read and interact with the TPMS are expensive at $1,500 each. The messages are also only polled at 60-90 second intervals, reducing or making the malicious task tediously long. Despite these natural limitations to exploiting this, it is an important eye opener to the auto industry that security and input validation needs to be run on all messages as more things become wirelessly networked in our cars traveling 70MPH. This research and its concluding paper was presented at the USENIX conference on Thursday.

(via ComputerWorld)

Filed Under: Hardware, Gadgets, and Products, Security and Privacy

Trending

  • Remote Administration – Troubleshooting without leaving your chair
    In Software, System Administration, Tech Solutions
  • Book Review: Rootkits – Subverting the Windows Kernel
    In Reviews, Security and Privacy
  • Apple announces iPhone SE, iOS 9.3, 9.7-inch iPad Pro while FBI announces dropping its case
    In Featured, Hardware, Gadgets, and Products, News

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Command line to take ownership and change permissions Command line to take ownership and change permissions
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • Creating and editing views in phpMyAdmin Creating and editing views in phpMyAdmin
  • Configure Outlook to recurring appointments for the last weekday of the month Configure Outlook to recurring appointments for the last weekday of the month
  • How to Purchase Cryptocurrencies? How to Purchase Cryptocurrencies?
  • Top 6 necessary aspects to consider when hiring Angular developers Top 6 necessary aspects to consider when hiring Angular developers
  • Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business
  • Benefits of End-To-End Testing That Will Match Company Expectations Benefits of End-To-End Testing That Will Match Company Expectations
  • 3 Key Features of Pets Health Monitoring Systems 3 Key Features of Pets Health Monitoring Systems
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How to Purchase Cryptocurrencies?
  • Top 6 necessary aspects to consider when hiring Angular developers
  • Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2023 · Magazine Pro Theme on Genesis Framework · WordPress · Log in