5 ms·
7 octets is the minimum set by the SIG, not a mandatory length to support for all devices. For devices that transfer sensitive information (phones, keyboards, e
by jwtorres 7y ago
7 octets is the minimum set by the SIG, not a mandatory length to support for all devices. For devices that transfer sensitive information (phones, keyboards, etc.), a larger key length can be enforced. This would be enforced by the application written by the product designer, not the BT chipset vendor nor the BT SIG.
- jjoonathan 7y agoWhy 7? Is that the longest key the NSA can crack quick enough to mount the attack?
- LeonM 7y agoI expect it's a trade-off between power usage and brute-force resilience.
- pgt 7y agoPowern and time (latency).
- Tuna-Fish 7y agoAny actual sensibly picked tradeoff would have much more entropy. The rumor is that 7 bytes is the shortest maximum key length of any devices currently in circulation. 7 bytes is still laughably bad, ofc.
- codesushi42 7y agoI'm guessing this is because DES was also 7 bytes. And DES is laughably insecure, even 3DES was retired years ago. Op is correct, this is not a solution.
- codesushi42 7y agoNope. DES also used 56 bit keys. It was crackable by the NSA the moment it was introduced in 1975. And by the 2000s, anyone could crack it. Even back then, the choice of 56 bits had nothing to do with speed. Chips were more than capable of handling 128 bit keys even in 1975. It's 2019 and we're still proposing 56 bit key lengths? Wow.
- clort 7y agoNo, they are not proposing 56 bit key lengths. I understand the key is always 128 bits. They are saying that the entropy should be minimum of 56 bits. In fact the entropy is always 128 bits but this negotiation reduces it because 'some' governments didn't want other governments to have stronger encryption. See [1] page 1050, figure 2. I don't know how much difference that makes (I am not an encryption expert), but it is a fact that affects your comparison to DES. [1] https://www.usenix.org/system/files/sec19-antonioli.pdf https://www.usenix.org/system/files/sec19-antonioli.pdf edit: citation
- codesushi42 7y agoI understand the key is always 128 bits. No, the article is about KNOB, which allows the attacker to arbitrarily shorten key length. The proposed solution is to have a minimum 56 bit key length, which is still too short.
- cryptonector 7y agoWas DES crackable by the NSA way back when? Are they known to have had the necessary HW?
- klodolph 7y agoThat doesn't sound plausible. Bluetooth still needs to run the radio, even at low power.
- bjt2n3904 7y agoMy guess is they're trying to support legacy hardware that might not have the crunching power to do 128/256 with the tight timing constraints on channel hopping? Either way, still not a good decision.
- mtgx 7y agoYes, because that always goes well. I'm predicting like 80%+ of the implementations will use exactly that minimum key length.