|
|
Log in / Subscribe / Register

Billions of devices imperiled by new clickless Bluetooth attack (ars technica)

Billions of devices imperiled by new clickless Bluetooth attack (ars technica)

Posted Sep 14, 2017 12:45 UTC (Thu) by janc (guest, #95095)
Parent article: Billions of devices imperiled by new clickless Bluetooth attack (ars technica)

Most devices are not discoverable all the time and attacker need to know BT address. This means that "developing a self-replicating worm that would spread from a single device to other nearby devices that had Bluetooth turned on, and from there those devices would infect other nearby devices in a chain reaction" is a bit exaggerated.


to post comments

Billions of devices imperiled by new clickless Bluetooth attack (ars technica)

Posted Sep 14, 2017 17:32 UTC (Thu) by alonz (subscriber, #815) [Link]

The researchers do mention this in their whitepaper; they also point out that if the device has any active Bluetooth-classic connections, the packet headers leak 24 bits of the BDADDR.
The researchers also point out that WiFi scans can leak the full BDADDR, which is true for many devices — the WiFi MAC and Bluetooth BDADDR are often closely related. WiFi MAC randomization somewhat helps here, but it's far from a panacea.

Billions of devices imperiled by new clickless Bluetooth attack (ars technica)

Posted Sep 15, 2017 18:17 UTC (Fri) by Wol (subscriber, #4433) [Link]

I *think* my phone actually disables bluetooth - it times out - so I have to switch it on every time I want to use it. Not bad - decent energy savings :-)

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds