HeadlinesBriefing favicon HeadlinesBriefing.com

TPMS Privacy Risks: How Car Sensors Leak Driving Habits

Hacker News •
×

Researchers discovered that tire pressure monitoring systems (TPMS) transmit identifiable data in plain text, revealing driver presence, vehicle weight, and movement patterns. Using $100 spectrum receivers, they captured transmissions from 20,000 cars over 10 weeks, exposing unique identifiers that persist for months. This work demonstrates how passive TPMS signals can be exploited to track individuals, raising alarms about automotive privacy vulnerabilities.

The study analyzed 12 test vehicles but noted that attackers could scale efforts to monitor thousands. TPMS data, broadcast every 1-2 minutes, leaks details like driver presence duration and typical routes. Malicious actors could correlate this with public records to infer identities, the team warned. Such tracking requires minimal technical expertise or investment, making widespread surveillance feasible.

Current TPMS designs lack encryption, leaving data exposed to anyone with affordable radio equipment. Researchers urged automakers and regulators to prioritize privacy-preserving upgrades, such as randomized identifiers or encrypted transmissions. These changes would prevent systematic profiling of drivers without consent, addressing a critical gap in vehicle security.

The findings highlight an urgent need for industry action. With TPMS adoption near-universal in modern cars, unsecured signals pose systemic risks. A $100 investment enables extensive surveillance, underscoring the vulnerability of everyday technologies to privacy breaches.