8 ms·
What your Bluetooth devices reveal
- TheSilva 8mo agoTangential, sort of: in the early days of mobile phones for the masses, when there was no WiFi/3G in the underground, I will often enable Bluetooth in my phone, look for nearby devices and try to match names and looks. That was before everyone had their "John's IPhone" or "Samsung A55" boring names everywhere and some of us cared to personalise our device's name. Anyone else played this game?
- mytailorisrich 8mo agoI do the reverse. I set my wifi hotspot or bluetooth to "MetPoliceUnit355" and I look for people making faces or looking around.
- tonetegeatinst 8mo agoYep 100% did the same. It was interesting to see what people named stuff as even back then I figured you could use that metadata for tracking devices...but even more interesting was looking at the Mac address to see the manufacturer and try and find some rare or cool device.
- oarla 8mo agoYeah, but it stopped pretty soon stores figured out that they could flood you with advertisements over Bluetooth. In some places it was bad enough that I had to turn off Bluetooth.
- patja 8mo agoHow did this play out? Were the ads from an app from the store that you had installed? Or did they spam you over SMS because they associated your bluetooth info with an account you have with the store, or contact info they bought from a third party?
- dylan604 8mo ago> Were the ads from an app from the store that you had installed? This is my main concern over installing apps in general but specifically store apps. I've noticed that grocery stores are moving past existing loyalty cards and want you to use their apps for exclusively available digital coupons. The prices I'm seeing are very compelling and are on top of existing loyalty card discounts, and I could see lots of people using the app because of it. The assumed amount of abuse keeps me from lemminging my way through the store.
- nonamenoslogan 8mo agoKroger here has done that with their app. The loyalty card/phone number still works for many of the specials, but the "digital deals" thing by using the app and scanning a QR code on the price sticker gives BIGGER discounts. Its not the most convenient way to shop, but I am willing to save 15-20% more usually.
- edent 8mo agoNeither. They used to discover your device and then send a Bluetooth push. "Would you like to receive a file from …" It was usually an image, movie, or audio file.
- patja 8mo agoWow that is wild. Thanks for explaining. I've never seen a prompt like that on my phone and would not have guessed this.
- oarla 8mo agoAs someone explained it below in this thread, walk into a mall with Bluetooth turned on and phone starts chiming with multiple "... wants to send you a media/audio/image etc." Not just ads, some bad actors would try to infect the phone with malware. Luckily never happened to me, but I heard from my acquaintances.
- styfle 8mo agoDid you ever try to communicate with them? https://en.wikipedia.org/wiki/Bluejacking https://en.wikipedia.org/wiki/Bluejacking
- jjkaczor 8mo agoHah, I change my device name and wifi hotspot all the time... "[Agency-acronym] Surveillance Van #43/44/etc.."
- herghost 8mo agohmmmmm... 2006, sat in a job interview. Interviewer says he'll Bluetooth over a file to me - what's by phone's name? 2006, the year that Tool's 10,000 Days had been released, which I was enjoying and, being a bit of an Edge Lord, I'd named my device after a lyric from Vicarious - which, IIRC fit perfectly into the name space and made me very happy: > ILikeToWatchThingsDie Excellent. Still got the job though!
- fer 8mo agoWhat I remember is that you could push OBEX calendar objects without much refusal from the phones and make people have alarms ringing at 3am, fun times!
- keraf 8mo agoWhen I set up my iPhone and it asked who's iPhone it is, I thought it would be funny to put in Kim Jong Un. Now it shows up as "Kim Jong Un's iPhone" when I enable my hotspot. Or even better, it says it out loud when I connect to some Bluetooth speakers.
- zoklet-enjoyer 8mo agoI read an article in 2012 about the feds (DHS?) placing Bluetooth enabled devices along I5 in Seattle. They were able to make profiles of people based on what Bluetooth devices they had in their cars. Is anyone familiar with this? I've periodically tried to Google it and can't find anything about it
- parpfish 8mo agoI remember an art exhibit by an online privacy activist made where it’d ping people’s phones to get a list of “known WiFi networks” and then display them on a screen in a room. Each person would get a unique fingerprint of named network locations
- post_break 8mo agoI believe Houston used bluetooth to measure congestion on 45.
- coldbrewed 8mo agohttps://www.kuow.org/stories/privacy-advocates-flag-a-potentially-dark-side-to-quicker-commutes https://www.kuow.org/stories/privacy-advocates-flag-a-potent...
- Spooky23 8mo agoPossible, but they buy data from the carriers with similar profile possibilities. The DEA operates long standing and pervasive surveillance in “drug corridors” like I-95 from Maine to Miami. They do things like LPR and grabbing passenger pictures. If Bluetooth is used, it may be a way to get a count of passengers or if the passengers change. I know based on newspaper accounts that they are particularly interested in cars that stop in Philly or Baltimore. This stuff is frequently used against cops too so they may use the tech in similar ways. If you’re someone worried about getting raided, spotting a large number of new signals at the front door is an early warning potentially.
- angus-g 8mo agoThere are realtime systems for traffic analysis. I know of Addinsight, e.g. https://news.addinsight.com/bluetooths-leap-forward-the-evolution-of-probe-data-collection https://news.addinsight.com/bluetooths-leap-forward-the-evol...
- jjbiotech 8mo agoI suspect the e-scooters left around town (Lime, Bird, etc) are massive Bluetooth / LoRa dragnets. You pay them to increase coverage or visibility to social hot spots.
- hammock 8mo agoWow e-scooter wardriving is something I hadn’t thought of. Could be happening somewhere
- thenthenthen 8mo agoThere is a startup (in Stuttgart i believe?) that adds camera ms to these scooters.. this is 100% illegal (and I think the ccc is filing lawsuits?). Some of the earlier Tier model scooters even had a dedicated space for a camera in their head tubes.
- jeena 8mo agoAbout 10 years ago i had HomeAssistant running and thacking my bluetooth devices. It does so per default by jus memorizing a mac adress an recording when it's visible and when not. No need for pairing or anythung. It also stores the custom name if available. Anyway, the default dashboard also automatically generated a view when my neighbours "Katie's iPhone' was at home and when not, until I actively deleted it and the data it stored.
- avel 8mo agoSimilar story - "Home assistant picked up my neighbours Bluetooth toothbrush and now I can see when they brush their teeth" https://www.reddit.com/r/homeassistant/comments/1306pcw/home_assistant_picked_up_my_neighbours_bluetooth/ https://www.reddit.com/r/homeassistant/comments/1306pcw/home...
- trashb 8mo ago> We’ve normalised the idea that Bluetooth is always on. Phones, laptops, smartwatches, headphones, cars, and even medical devices constantly broadcast their presence. The standard response to privacy concerns is usually “nothing to hide, nothing to fear.” I guess anything you send out can be used to profile you. Some of my friends live on a farm near a semi busy road, however far enough from other farms to not be able to receive their wifi. They showed me their router logging all the wifi accesspoints that appear/disappear. There where A LOT of access points named "Audi", "BMW", "Tesla" etc. similar to those devices leaking bluetooth data. We had a discussion that it would be easy to determine who was passing by at what times due to these especially when you can "de-anonymize" the data for example link it to a numberplate. I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.
- pixl97 8mo ago> even medical devices constantly broadcast their presence I mean yes, said medical devices are a whole lot less useful to me if they are not transmitting data. For some of this stuff you can't have your cake and eat it too.
- xanrah 8mo agoThere’s a middle ground here. There is no technical reason a pacemaker constantly broadcasts itself - there is ways to allow communication to such devices without yelling your name all the time. And there is definitely no reason for such a name to be a unique identifier.
- pixl97 8mo agoI mean if not a name, how would a mac id be any different?
- ssl-3 8mo agoThere are technical reasons, though. Let's suppose we have a pacemaker, and it has data that is beneficial to read -- maybe even in real-time on their pocket computer, or opportunistically as the patient walks by their reader-device, or however that is done. So we want this data, and we want it over RF. It probably seems obvious that it should only transmit when it is told to do so, right? So how do we tell the pacemaker to transmit? On its face, that problem seems solved by integrating a receiver that sits and waits for a valid instruction. Except: That receiver takes power to run. And since changing batteries inside of a person is problematic, we want them to last as long as they can while still performing the desired task. Now we get to the not-obvious part: In terms of power, it's often less costly to intermittently transmit a string of data than to continuously operate a radio receiver. And maybe it's a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway. But a transmit-only radio? Good luck hacking that. So... we do intermittent transmission, and this works for pacemakers. It also works for the cheap Zigbee thermometer I have (wherein I don't normally request the temperature; it just delivers it periodically, and it runs for years and years on a coin cell). (Now: Should that pacemaker data be encrypted? Yes, of course. And so should the ID. In fact, the whole transmission should be indistinguishable from background noise by unrelated devices. In this way, authorized devices can then use pre-shared keys to receive and decode these messages and others receive nothing. That kind of cuts BLE and thus also the pocket computer out of the monitoring mix, but tradeoffs are tradeoffs.)
- webdoodle 8mo agoDoesn't HackRF with Cha0s do something similar?
- HNisCIS 8mo agoAnd kismet
- gruez 8mo agoBluetooth desperately needs mac randomization. Wifi mac randomization is welcome, but it doesn't do much when many (most?) people have bluetooth accessories broadcasting a persistent identifier whenever they're on.
- neilalexander 8mo agoRandom Bluetooth MACs are already possible. iOS devices have been doing it for years alongside the random Wi-Fi MACs.
- avidiax 8mo ago> Bluetooth desperately needs mac randomization. Bluetooth already has a well developed MAC randomization scheme. Lookup "resolvable private address". The short of it is, your phone can find your headphones or vice-versa, despite one or both having random addresses. The addresses can be regenerated or rotate at an interval (say 15 minutes). The first part of the address is a nonce (pRand), and the rest of the address is a 24-bit hash of pRand with an identity resolving key (IRK). So the other party just listens passively for addresses, and sees if any of them happen to have the right hash. I don't think this is as airtight as people think it is. Certainly, if you are following somebody and one address disappears right as another appears (rotation), it's quite easy to infer the new/old addresses belong to one device. I tried briefly to convince the Android developers to synchronize that rotation globally. You can also probably infer that if you see a pair of random MACs arrive, and they have a certain pattern of timing and payload size, you can say with some certainty that they are particular devices, say an iPhone and an Apple Watch. But that requires sophisticated equipment since most Bluetooth LE communication is over a non-cryptographic frequency hopping arrangement. Lastly, radio fingerprinting is widely known in academia, but requires special equipment.
- bigiain 8mo ago> Lookup "resolvable private address". The short of it is, your phone can find your headphones or vice-versa, despite one or both having random addresses. Is that just for the connection phase? Or does it then start publicly broadcasting a persistent MAC onced it's connected, so if you earbuds or watch are connected and communicating with your phoine, would a sniffer see a persisten MAC address or the session randomised one? That's a problam (one of many problems) with WiFi MAC address randomisation - you can sniff the network names a phone is trying to connect to, then stand up a wifi access point with one of those names and the phone will reveal its real MAC address when it connects. I experimented a long time back with having a raspi that broadcast itself as a McDonalds free wifi access point, a huge number of phones would try to connect while I was out in public with it.
- _slih 8mo agoran something similar on a home network once and was surprised how many of my neighbors' devices showed up with full manufacturer names and model numbers. you don't even need to try hard.
- wolvoleo 8mo agoYeah here in the city I scan for 2 minutes and I know half the neighbours names and what phones, computers and TVs they use.
- deleted 8mo ago[deleted]
- bpoyner 8mo ago"We agreed on a 150-day disclosure window". Isn't that longer than Google Project Zero gives to release fixes?
- ifh-hn 8mo agoWonder what the difference is between this and: https://github.com/ArgeliusLabs/Chasing-Your-Tail-NG https://github.com/ArgeliusLabs/Chasing-Your-Tail-NG
- RamRodification 8mo agoThat one doesn't seem to do bluetooth at all, I think?
- nine_k 8mo agoThis is not very different from collecting visual cues. You can notice a delivery van arriving. You can see the driver's face, same with passers-by. The biggest difference is that a camera needs to be more conspicuous, while a BT receiver can be invisible and undetectable. Much cheaper, too.
- bigiain 8mo agoI have an ESP32 Cam in front of me right now. I think I paid maybe 8 bucks for it. If I wanted to, I could very easily hide the tiny camera in my front door, and use it to both collect bluetooth and wifi metadata (including MAC addresses) and correlate images/faces to MAC addresses when people pass by close enough so that I can identify them later from longer range wifi/ble detections. (I actually do plan to install this at my front door, but aimed mainly to detect when a deliver/parcel in on my doorstep, and I don't (yet?) plan on sniffing bluetooth/wifi with it)
- nine_k 8mo agoA decent optical part is comparably expensive, and somehow visible.
- clarabennett26 8mo ago[dead]
- thenthenthen 8mo agoI mean.. these services have apps right? It is, mostly, pretty trivial to track drivers and it would not surprise me if they have a fixed ID.
- clarabennett26 8mo ago[dead]
- rsync 8mo agoThe project describes - and shows - a web interface. Is there a simple CLI interface that can be redirected or pipelined into other tools ?
- cadamsdotcom 8mo agoThis could be used for a truly eye-opening art installation: a screen that as you walk by it, tells you when you were last there.. Even wilder would be to buy data on you in real time and display that.
- supertrope 8mo agoThe Hollywood movie Minority Report has a scene where an advertising display personalizes the ad by your name. https://www.youtube.com/watch?v=7bXJ_obaiYQ https://www.youtube.com/watch?v=7bXJ_obaiYQ
- ck2 8mo agoHas anyone ever studied what happens with Bluetooth contention where thousands of people are gathered in a small space? Like a marathon mass-start with 10,000 sometimes 20,000 or more people How does bluetooth handle that? Or it doesn't?
- supertrope 8mo agoEven licensed wireless stops functioning. All circuits are busy.
- username_here 8mo agoIn my experience, just fine. I recently ran a large (~30k) marathon and my AirPods and watch never glitched once, streaming the whole time including in the packed start corrals. I had the same thought about RF contention, but Bluetooth didn't seem to care.
- just6979 8mo agohttps://en.wikipedia.org/wiki/Frequency-hopping_spread_spectrum https://en.wikipedia.org/wiki/Frequency-hopping_spread_spect..., combined with the inverse square law, is pretty amazing. The amount of data needed to send audio to your ear-buds is quite small compared to the spectrum available, so only needs tiny slices of spectrum and for relatively tiny slices of time. And also relatively tiny amounts of power since it's only going max 100 feet, hence a pretty small chunk of space. If all those 10K-30K devices are constantly jumping around the frequency band to transmit tiny payloads a tiny distance, then a whole metric fuck-ton of them can interoperate in what seems to us to be very tight quarters. But to those specialzied radios it probably seems like a fairly wide open field.
- catsquirrel28 8mo ago> This isn’t about paranoia. It’s about understanding the trade-offs > Bluetooth mesh networks—no internet required, no servers, no phone numbers LLM slop. Both the article and the Python script
- the-anarchist 8mo agoI second that. This website, including its look and layout, appears to be a copy of some more prominent indieweb ones that have been frequently featured here, filled with what seems to be almost entirely copied and/or LLM generated content.
- 0xdeadbeefbabe 8mo agoWait doesn't BLE randomize the UUIDs?
- nmstoker 8mo agoYes, I was surprised there would be enough to go on with the MAC addresses rotating and I had assumed the UUID would too, but it sounds like there's enough to go on to identify targets.
- f0r3st 8mo agoyou said " blocking ads network-wide with AdGuard". It's better to block it with a Pihole.
- dalemhurley 8mo agoRing: thank you for the idea, "Introducing Ring Face-Off, face masks covering faces during a break-in is no an issue for Ring, we will track the thieves until they reveal their face to our Ring network."
- bigiain 8mo agoFor immediate release: BLE N95 Facemasks Inc (YCombinator Summer 2025) is proud to come out of stealth mode and announce our acquisition by Ring. This follows a major private angel investment by Palintir with a post money valuation of $500 million.
- bigbuppo 8mo agoI can assure you this has been talked about and is known and it's why you still find a headset port on devices handed out to government officials, though most of them ignore the advice to not use bluetooth.
- fennec-posix 8mo agoEmit at your own peril
- haberlerm 8mo agoBLE Tire pressure sensors are great vehicle identification devices. Static MAC adress gives 4 unique keys to a vehicle when actively scanning.
- WaitWaitWha 8mo agoI am personally aware that Washington DC, same areas of Maryland, Virginia and Delaware have been tracking car Bluetooth (and EZ-Pass) for decades for "traffic management". The more BT detected the heavier tracking. The longer time between detectors for the unique BT/EZ-Pass, the slower the traffic. Adjust traffic lights down the road to improve traffic flow. (when I write Ez-Pass, i mean the toll transponder, but not detected by a toll booths or overhead arches.)
- ggm 8mo agoHeard a talk in Paris about a guy who "war drove" around town using a higher layer Mobile IP ap which could sweep up open SSID, connect, and (ab)use the bandwidth to maintain a link "above" it (I guess like an agile VPN) he was getting 100mbit class speeds routinely. Also patches of nothing, but it was interesting. That was over 5 years ago.
- stevage 8mo agoYears ago I was interested to discover that my local road authority uses Bluetooth tracking of drivers to monitor traffic speed on certain major roads. Detect a particular Bluetooth ID at one point, pick it up again 2km down the road, you know how fast the traffic is going. Pretty useful for getting an immediate alert if traffic speed suddenly plummets.
- anonymousiam 8mo agoWithin the past two years, I began leaving BT turned off on all of my devices unless I needed it. It means that I need to pause a moment to turn it on when I get in the car, use my headphones/airpods, or other BT devices. For me, it's worth the extra trouble because I noticed a significant reduction in battery life on my mobile devices. The reduction coincided with the rollout of Apple's "Find My" service, which was followed by Google's "Find Hub" service. (I have devices in both ecosystems.) I wish there was a separate way to opt out of the "Find" services, but AFAIK, even if you opt out, your device may still relay traffic from other nearby devices. So it seems that the only way to preserve device battery life is to just shut off the BT.
- chii 8mo ago> I began leaving BT turned off on all of my devices unless I needed it i've been doing that since the inception of BT being available on my devices. I'm just surprised at so many people's cavalier attitude to security and privacy. And then later, it is too late to reverse course.
- GordonS 8mo agoSame. Security aside, I also didn't want to waste the battery when I knew I was unlikely to use Bluetooth.
- efilife 8mo agoI am fucking sick of seeing this everywhere. I gave this article a benefit of the doubt until: > Bluehood isn’t a hacking tool. It’s an educational demonstration of what’s possible with commodity hardware and a bit of patience. > This isn’t about paranoia. It’s about understanding the trade-offs we make when we leave wireless radios enabled on our devices. This LLM spam needs to end. Tons of people on HN got tired of this, and it often shows in the comments. Let's maybe start adding [LLM] to the titles of AI generated submissions?
- RockRobotRock 8mo agoThe AI written blog posts will continue until morale improves.
- stingraycharles 8mo ago> The Problem Nobody Talks About head explodes do these people writing these blog posts not recognize just how super bad their blog posts look with this slop?
- farkanoid 8mo agoSomewhat related - I've been working on a design using Nordic's NRF52840 SOC for work; Intensely focusing for the past few weeks on antenna tuning for maximum BLE range. Part of the testing involves using the 'nRF Connect' app, which lists all nearby Bluetooth devices, plots signal strengths, and allows for some rudimentary communication. It doesn't seem to be Nordic-specific. I'd frequently leave the app open scanning during development late in the evening, and rarely, an unidentified Bluetooth LE device would pop up for a few minutes then disappear. Turns out it was my dad's pacemaker, which sends telemetry via Bluetooth to a 4G gateway they gave him (this only happens after he lies down with little movement apparently). This prompted me to look into pacemakers and deactivation after death of course. I wish I hadn't, it turns out they leave it in the corpse unless it's scheduled for cremation. Because of the aforementioned research, and the open field tests I was performing, it somehow devolved into me having a nightmare where I was RF testing at a graveyard, and the app suddenly displaying a bunch of pacemakers underground. ...I really hope this isn't possible - The signal through 6ft of dirt and concrete would be marginal but still detectable.
- Footprint0521 8mo agoRandom question, but will this be open sourced at any point? Just asking as a curious party who just bought one for exploration lol Also super random question but would you happen to have any idea/advice on how to get a Raytac MDBT50Q-CX Nordic nRF52840 Dongle (https://www.amazon.com/gp/product/B0DP6MVDZQ https://www.amazon.com/gp/product/B0DP6MVDZQ) flashed with ButteRFly (https://github.com/whad-team/butterfly https://github.com/whad-team/butterfly)? I got it flashed through nrfutil with sniffer and sweyntooth, but butterfly has not been working no matter what I try and do… Thanks for even taking the time to read this :)
- farkanoid 8mo agoHi, sorry I missed your reply - Unfortunately it's a proprietary design, the vendor provides the firmware, I do all the schematic capture / PCB layout. Good luck though!
- 8mo ago
- moontear 8mo agoIntroducing the „are they home“ device to assist burglars. Just slap that miniature device somewhere non-suspicious on the place of your potential marks and let it run for the battery life of 7 days. Afterwards you collect it and know movements patterns. Features automatic notifications if no movement detected for more than two days.
- KolibriFly 8mo agoTo be fair, that's basically a variation of techniques that have existed long before Bluetooth
- moontear 8mo agoI don't disagree, nothing new to see here. I just thought that this would be a nifty device to sell via nefarious shops. Include some more passive tracking of WiFi and bob's your uncle. Maybe add mesh functionality via LoRaWAN and track the whole neighborhood.
- dwedge 8mo agoSomething about them saying they use Proton pass so they don't need to have secrets in pipelines as an example of being into privacy rubbed me the wrong way
- dncornholio 8mo agoFYI WiFi leaks the same metadata, so turn that off too if you disable BT.
- KolibriFly 8mo agoBluetooth, Wi-Fi, even things like tire pressure sensors... they were designed primarily for convenience and interoperability, not adversarial environments. Now we're retrofitting privacy onto systems that were never really built with that as a first principle
- keraf 8mo agoOver a decade ago, I already saw a music festival using Bluetooth tracking to monitor crowd movements [0]. There's an assumption that people just leave their Bluetooth on out of convenience. [0] https://actu.epfl.ch/news/using-bluetooth-to-track-crowds-at-the-paleo-music/ https://actu.epfl.ch/news/using-bluetooth-to-track-crowds-at...
- cm-t 8mo agoParisians Métro 's ads screen are equiped with BT scanner, with a hidden sticker on the side to link you with a qrcode to a RGPD output website, where you have to log your private data to register your devices to be not scanned... What a world to be alive..
- deleted 8mo ago[deleted]
- electrosphere 8mo agoThis gives me a homebrew project idea - to create something portable that would allow me to sniff Bluetooth devices on my daily train commute into the office. Has anyone done this or can give me ideas where to start?
- kittbuilds 8mo ago[dead]
- NoSalt 8mo ago> "The standard response to privacy concerns is usually 'nothing to hide, nothing to fear.'" > "But here’s the thing: even if you have nothing to hide, you’re still giving away information you probably don’t intend to." Whenever I see talk like this, I always like to post this quote that not only still rings true, but rings even louder today. > "If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him." ~ Cardinal Richelieu (Cardinal and former Secretary of State for Foreign Affairs of France)
- SUDEEPSD25 8mo agoWeirdly intriguing!