Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Bluetooth hack shakes mobile security

Masquerade crypto attack developed

Published Wednesday 8th June 2005 16:26 GMT

Cryptographers have discovered a security flaw in implementations of Bluetooth which allows hackers to pair their devices with prospective victims. The approach creates a means for hackers to hijack Bluetooth-enabled devices. It's not all just theory either, unlike most cryptographic attacks.

The researchers - Yaniv Shaked and Avishai Wool of Tel Aviv University in Israel - have come up with an exploit which allows hackers to pair with devices without alerting their owner. The approach gets around limitations of a security attack first described by Ollie Whitehouse of security firm @Stake last year. This earlier method meant an attacker needed to eavesdrop the initial connection process (pairing) between two Bluetooth devices, which only occurs infrequently.

Shaked and Wool have worked out a way to force this pairing process by masquerading as a device, already paired with a target, that has supposedly forgotten a link key used to secure communications. This initiates a fresh pairing session which a hacker can exploit to snaffle the link key and thereby establish a pairing without needed to know PIN details. Once a connection is set up, an attacker could make eavesdrop on data transmitted between a target devices and a PC or (at least potentially) take control of someone's Bluetooth device. "Once an attacker has forced two devices to pair, they can work out the link key in just 0.06 seconds on a Pentium IV-enabled computer," New Scientist reports.

Shaked and Wool are scheduled to outline their research at the MobiSys conference in Seattle this week. ®

Related stories

Porn, Dubai and Bluetooth phone hacking...
Car virus myth debunked
Security researchers nibble at Bluetooth
Wi-Fi honeypots a new hacker trap

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

How IT Management Can "Green" the Data Center

This Gartner research provides managers with an outline of the trends affecting datacenters and offers strategies with which to address these changes..
whitepaper title

Gartner Paper: US Data Centers

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
Whitepapers

Top 20 storiesAll The Week’s HeadlinesArchiveSearch