5 ms·
Is Your Bluetooth Chip Leaking Secrets via RF Signals?
- vardump 11mo agoA side channel attack revealing AES key from just 90,000 traces. Sigh, side channel attacks seem to be everywhere now.
- sitzkrieg 11mo agopeople are finally aware everything leaks, it's just a matter of how closely you look
- boulevard 11mo agoEverything leaks if you stare at it long enough
- formerly_proven 11mo agoThere's a lot of signal left between you and the noise floor!
- namibj 11mo agoWorse: noise floor is a matter of definition.
- czbond 11mo agoEverything has data exhaust.... the exhaust type just differs.
- barbegal 11mo agoThat 90,000 traces did take 225 hours to capture so it is truly a huge amount of data and not a trivial attack.
- karlgkk 11mo agoOn the other hand, I’d argue that it’s close enough to trivial to be considered trivial. How many embedded devices transmit sensitive information? Now, I know that pretty much every Bluetooth based credit card reading device explicitly defends against a channel such as this, but there are tons of access control solutions, and medical devices that don’t Would you notice a raspberry pi tucked into the mess of wires beneath the security guard guards desk?
- throwaway89201 11mo ago> How many embedded devices transmit sensitive information? Every Zigbee device uses AES keys to secure the network, although the security of the protocol is pretty weak in most deployments, especially when new devices join the network. Leaking the network key would provide access to the entire network. The ARM Cortex-M4 is often used, which the side-channel attack in the article is about.
- kragen 11mo agoThat's less than two weeks.
- userbinator 11mo agoFor one key, assuming it does not change within that time.
- ghostpepper 11mo agoand assuming the protocol needs to continuously transmit for weeks at a time
- 3abiton 11mo agoI read the abstract, while not familiar with the topic, how would we go about limiting the inpact?
- Retr0id 11mo agoRotating keys frequently would probably help. But the best thing to do is use implementations that are less leaky in the first place (which is easier said than done).
- ryukoposting 11mo agoAs someone who finally recently escaped bluetooth firmware development: yes, Bluetooth is leaking secrets and it doesn't even require any silly RF shenanigans. Almost nothing actually implements LESC. Apple refuses to implement OOB pairing, so no peripherals can force you to use it, so everything is subject to MITM attacks. The entire ecosystem is a mess of consultants and underpaid devs copy-pasting Nordic sample code, with no time or financial incentive to do more than the bare minumum. Never trust any product that moves sensitive data through Bluetooth.
- matthewdgreen 11mo agoApple claims to have implemented an entire second security level for their Bluetooth apps based on iMessage, but I trust it not at all. (To be clear, I trust the iMessage protocol with reasonable confidence. I judge the probability that Apple has applied this extra layer of security uniformly to all sensitive data to be about 8%.)
- cozzyd 11mo agoText written with a non-apple Bluetooth keyboard is green?
- ggm 11mo ago8.75% surely? you need at least two digits of specious precision on that non-random number.
- cozzyd 11mo agoMore likely 8.333% I would think (1/12). The same probability of a broken clock yielding the correct hour.
- hulitu 11mo ago> Apple claims to have implemented an entire second security level for their Bluetooth apps based on iMessage, iMessage... the golden standard for 1click RCE. /s
- 11mo ago
- Verdex 11mo agoTime for everyone to implement some variation of https://www.bluetooth.com/specifications/specs/authorization-control-service-1-0/ https://www.bluetooth.com/specifications/specs/authorization... ?
- deleted 11mo ago[deleted]
- voidUpdate 11mo agoI really think we need a modern replacement to bluetooth, something that doesn't have weird behaviour with headphones, is more secure and doesn't have weird connection issues all the time, and is as ubiquitous as bluetooth is now. I know it will never happen, but I can only hope
- zwirbl 11mo agoI guess that's where Bluetooth LE and LE Audio should come in, but it's coming along very slowly or not at all in Apples case. Or maybe it is, they don't talk about it
- abdullahkhalids 11mo agoIf I am reading this [1] correctly, regular Bluetooth >5.0 offers transfer speeds of 50Mbits/sec, while Bluetooth LE offers 2Mbits/sec. Does Bluetooth LE even solve fundamental problems like high quality bidirectional audio? [1] https://en.wikipedia.org/wiki/Bluetooth#Specifications_and_features https://en.wikipedia.org/wiki/Bluetooth#Specifications_and_f...
- zwirbl 11mo agoI never knew about the 50Mbaud figure, is anything above 10M even achievable in a real world scenario? It does solve this by having a different topology. It supports a configurable number of streams in each direction, so at least in theory 5.2 surround with a stereo microphone should be possible, we'll see if it's usable It also supports what is often called 'true wireless' earbuds by default, as each audio sink can stream only the channel it's interested in. Finally there's all that broadcasting stuff, which works fine in our tests most of the time but also with a myriad of issues, some of them in the spec, others in the Android implementation, which is currently the de facto target to support
- imglorp 11mo agoYes please, immediately. It's been so terribly bad since it came out. You know it's bad when there's even an xkcd about it: this one is from 5 years ago, joking about 10 years before that. https://xkcd.com/2055/ https://xkcd.com/2055/
- pcdoodle 11mo agoIt still leaks when you turn bluetooth off in "control center". Last time i checked you're broadcasting an unchanging uuid that only changes every 12 hours or so. It's gross.
- deleted 11mo ago[deleted]