4 ms·
There are vulnerabilities in the "standard" LE pairing, even with MITM, that make these things possible. Fixed with the BT LE Secure Connections key exchange,
by keybuk 8y ago
There are vulnerabilities in the "standard" LE pairing, even with MITM, that make these things possible.
Fixed with the BT LE Secure Connections key exchange, but many devices don't implement that
- dmitrygr 8y agoPlease cite
- larkeith 8y agohttps://www.digikey.com/eewiki/display/Wireless/A+Basic+Introduction+to+BLE+Security https://www.digikey.com/eewiki/display/Wireless/A+Basic+Intr... (Heading: Pairing Methods for LE Secure Connections (4.2 devices only))
- dmitrygr 8y agoThat talks about 4.2 pairing methods. I'm looking for a citation claiming that 4.1 pairing method is in any way insecure
- snaky 8y ago> BLE 4.2 adds 'Secure Connections'. This is apparently also broken and what's more it was broken in 2008 when the same pairing method was used in Bluetooth 2.1!! It doesn't totally break pairing - only the passkey entry method - and you only learn the passkey, not the LTK. But it does allow an attacker to perform a MitM attack if the passkey isn't changed for every pairing attempt. https://devzone.nordicsemi.com/f/nordic-q-a/14481/secure-ble-pairing---is-it-possible https://devzone.nordicsemi.com/f/nordic-q-a/14481/secure-ble...