Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

Bluetooth pairing has a security hole. Get ready for updates-gctid260879

Started by Ajamu, Jul 24, 2018, 09:04 PM

Previous topic - Next topic
https://www.cnet.com/news/bluetooth-pairing-has-a-security-hole-get-ready-for-updates/

?

Bluetooth pairing has a security hole. Get ready for updates
A validation flaw opens the door for a nearby miscreant to monitor or manipulate the Bluetooth communication between devices.

BY 
LORI GRUNIN
[/list]JULY 24, 2018 10:05 AM PDT

?

?

 

Bluetooth SIG
When you pair a couple of Bluetooth devices, like your phone and computer, they exchange encryption keys. But it turns out the Bluetooth specification didn't require that both of them completely validate those keys. Well, it does now. 

This comes after it was revealed Tuesday that an attacker within wireless reach could insert themselves into communications between the two devices if both failed to properly validate the keys. That's according to the Bluetooth SIG and Carnegie Mellon's CERT, with some updates catalogued by ZDNet

Luckily, it doesn't work if at least one of the devices does its due diligence validating all the elliptic curve parameters during the  Diffie-Hellman (ECDH) key exchange (CVE-2018-5383), and a lot of manufacturers have already patched their devices.  Apple updated MacOS for El Capitan and later, plus the fix is in iOS 11.4 Intel has provided updated Bluetooth drivers for Windows 7 , 8.1 and 10. However, some patches need to come from your device's manufacturer -- Broadcom released a patch in June, for example, but those updates need to trickle down. Dell's already released Qualcomm's patch, as has Lenovo.

If you're not on an autoupdate cycle, you should probably check for updates with your phone or system manufacturer. 

The security flaw won't matter if you're, say, connecting your Xbox controller to your PC, or your camera to your phone, and the Bluetooth SIG says it's unaware of any actual incidents related to the flaw. But Bluetooth file transfers are becoming more popular and tools like Apple's Handoff use Bluetooth for the connection while transferring files over Wi-Fi. You may be typing sensitive information on your Bluetooth keyboard. And while it requires proximity for someone to fool with the data connection, given how many Bluetooth devices frustratingly require repeated re-pairings, the probability of that rises.

We've reached out to Apple and Google  for comment but didn't immediately hear back. Broadcom and Qualcomm confirmed they've issued patches.