3 ms·
The diagram in the post has the user device talking to the attacker device over Bluetooth, and the bug description explicitly says "An attacker within bluetooth
by chc4 2y ago
The diagram in the post has the user device talking to the attacker device over Bluetooth, and the bug description explicitly says "An attacker within bluetooth range" - which heavily implies to me your device actually is pairing with the attacker device somehow! If already being paired with the attacker Bluetooth device is a prerequisite for this attack that's much less of a concern imo.
- lxgr 2y agoAs far as I can tell, no pairing (or indeed any kind of logical Bluetooth connection) is required in the protocol used. The (device containing the) authenticator broadcasts a Bluetooth LE advertisement, and the "client platform" (i.e. usually the browser) has to be able to receive its contents to prove physical proximity. Such a (by definition unidirectional) Bluetooth LE advertisement can easily be received and relayed over arbitrary distances.
- warp 2y agoIIRC caBLE ("cloud assisted bluetooth low energy") sidesteps the usual bluetooth pairing process by using out-of-band channels (QR codes, NFC) to exchange initial pairing information.
- 3np 2y ago"range" here refers to physical distance (adjusting for interference). No prior pairing required.