Hardware Information

Bluetooth Can Be Cracked!


Nothing is completely safe today. Adobe has recently released a patch for a security hole in different graphical software, so why should Bluetooth be safe?

... and Bluetooth isn't safe off course! ;)

Two researchers of the Tel Aviv University School of Electrical Engineering Systems say they have discovered a technique for taking control of Bluetooth-enabled mobile phones. After you've established a connection with an other cell phone, the attacker can easily make calls with your phone. If there is a Bluetooth connection with a PC, the hacker can even transfer data between his Bluetooth device / cell phone and the hacked computer. Bluetooth can be very dangerous as you can see! Even when the handsets have security features switched on, your cell phone isn't save at all!

Avishai Wool, senior lecturer and Yaniv Shaked, graduate student and both researchers of the Tel Aviv University School of Electrical Engineering Systems have published recently a paper about three methods for forcing a repeat of the pairing process, "Cracking the Bluetooth PIN" ( http://www.eng.tau.ac.il/~yash/shaked-wool-mobisys05/ ).In this paper, a passive attack is described, in which an attacker can find the PIN used during the pairing process.The eye-opening conclusion of these two researchers: "Our results show that using algebraic optimizations, the most common Bluetooth PIN can be cracked within less than 0.06-0.3 seconds. If two Bluetooth devices perform pairing in a hostile area, they are vulnerable to this attack."

A Belgian Master student is making a fresh attempt to keep a list with Bluetooth security links on http://student.vub.ac.be/~sijansse/2e%20lic/BT/welcome.html.

Ollie Whitehousen security researcher of @stake, a digital security consulting firm ( http://www.atstake.com ) has written in October 2003 a paper that "examines methods of assessing the security of Bluetooth devices in relation to the protocol's design and implementation flaws" ( http://www.atstake.com/research/reports/acrobat/atstake_war_nibbling.pdf ).

In general, the most critical point is the 'pairing' - connection procedure of two Bluetooth devices. When a Bluetooth device asks you to re-enter the PIN number for re-pairing, once the two devices are re-connected, the hacker can now easily crack the PIN code.

Links:

- http://www.atstake.com/research/reports/acrobat/atstake_war_nibbling.pdf

- http://student.vub.ac.be/~sijansse/2e%20lic/BT/

- http://www.eng.tau.ac.il/~yash/shaked-wool-mobisys05/

For feedback on this article, please visit http://wallies.info/blog/item/145/index.html

Walter V. is a self-employed internet entrepreneur and founder-webmaster of several websites, including
wallies.info :: A snappy blog about snappy blue things :: blog | wiki | forum | links - http://wallies.info
mblo.gs :: A snappy moblog community - http://mblo.gs


MORE RESOURCES:

Sony expands XPLOD line of in-dash receivers
CNET News, CA - 7 hours ago
Three of Sony's new head units feature Bluetooth technology for simple hands-free phone calls and audio streaming (with a Bluetooth compatible phone). ...


Samsung's 2009 Plan: Green, LED TVs; 240-Hz Tech
PC Magazine - 20 hours ago
Both players connect to 802.11b/g/n wireless networks and incorporate Netflix video and Pandora audio streaming. These devices will upconvert standard DVDs ...


Samsung unveils P3 touch screen MP3 player
CNET News, CA - 19 hours ago
... audio and video playback, photo viewer, FM radio, voice recording, and Bluetooth capabilities such as phone pairing and stereo audio streaming. ...


CNET News

JVC adds seven new CD receivers to 2009 lineup
CNET News, CA - 9 hours ago
The KD-R900 also features hands-free phone calling and A2DP wireless audio streaming capability via an included USB Bluetooth adapter and high-quality ...


MeasurementDevices

Synology® Announces Disk Station Manager 2.1 Beta
MeasurementDevices, PA - Jan 7, 2009
Audio streaming and auto-discovery feature that simplifies IP camera setup prove the Synology Surveillance Station 2 to be a great alternative to ...


Arkados and Freescale Team to Bring Versatile 'Whole-House Audio ...
PR Newswire (press release), NY - 4 hours ago
The platform offers audio streaming from multiple sources such as iPods/iPhones, Internet Radio, DLNA media servers, etc., and audio can be rendered through ...


Earthtimes (press release)

G2 Microsystems Demonstrates Intel My WiFi Personal Area Network ...
Earthtimes (press release), UK - 2 hours ago
“We’re showing how direct Wi-Fi access can transform the audio streaming experience, but we also envision G2 Microsystems’ technology simplifying other ...


Lady Buffs hit road for crossover games
Amarillo.com, TX - 11 hours ago
Radio/Internet: KGNC (710-AM), 6:30 pm; streamed live at www.gobuffsgo.com; audio streaming at www.kgncam.com. Did You Know? WT has won 17 straight games ...


Roxio Toast 10 Titanium Burns Media, Streams to iPhone, Transfers ...
Gizmodo.com - Jan 4, 2009
By Adrian Covert , 12:01 AM on Mon Jan 5 2009, 1039 views Roxio Toast 10 Titanium is the latest refresh to the do-it-all, disc burning and file converting ...


EFF wins request for reexamination of ringtone patent
Register, UK - 23 hours ago
The patent, issued in 1997 to Seer Systems, restricts audio streaming, cell phone ringtones and other electronic distribution of music when they involve the ...

Audio-Streaming - Google News

Generic Club Football UK E-shop  Top of Page home | site map  home Bookmark Us Now ctrl+d 1st 4 Games, shopping via this site cost no more than going direct and can often save you money with special offers.