
DEF CON 33 - Uncovering the Secrets of Tire Pressure Monitoring Systems - Yago Lizarribar
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:56
[TPMS systems are highly vulnerable to both passive monitoring and active spoofing due to lack of encryption or authentication, enabling attackers to track vehicles or manipulate tire pressure data with simple, low-cost hardware]2:15.
Key Takeaways:
• Direct TPMS sensors transmit unencrypted data with no authentication, allowing passive tracking of vehicle movements using affordable SDR hardware 3:30.
• TPMS signals from the same car are highly correlated in timing, enabling accurate vehicle identification through cross-correlation or ID pattern analysis 5:50.
• Toyota vehicles transmit pressure data every 15 minutes regardless of motion, making them especially vulnerable to long-range tracking up to 200 meters 14:28.
• Attackers can spoof TPMS signals using open-source tools and SDRs, tricking the ECU into accepting fake pressure or temperature readings, potentially causing unsafe vehicle behavior 16:50.
• Passive monitoring is feasible even without line-of-sight, with detection working up to 50 km/h and over 200 meters due to unsecured signal transmission 15:32.
Current TPMS systems offer no real security; no production vehicles implement encryption or authentication, and while indirect TPMS may suffice for basic safety, direct TPMS remains a significant risk due to its unsecured design.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right. So, thank you for joining today. Um, and I would like to thank also the car hacking village for giving me the opportunity to give this talk which is going to be about the kind of attacks that you can do on high pressure monitoring systems. Uh, my name is Agitha River and I'd like to introduce myself a bit before we dive deep. Uh, I'm a researcher in Switzerland uh doing sort of work in the intersection between cyber security and and artificial intelligence now. So like machine learning, deep learning and these kind of models apply to cyber to cyber security. I've done I do a lot of work as well in spectrum sensing networks and I did in the past long time ago some work in autonomous vehicles. But this work I'm presenting today it's a bit the intersection between spect spectrum se…