The Channel logo


By | John Leyden 8th June 2005 16:26

Bluetooth hack shakes mobile security

Masquerade crypto attack developed

Cryptographers have discovered a security flaw in implementations of Bluetooth which allows hackers to pair their devices with prospective victims. The approach creates a means for hackers to hijack Bluetooth-enabled devices. It's not all just theory either, unlike most cryptographic attacks.

The researchers - Yaniv Shaked and Avishai Wool of Tel Aviv University in Israel - have come up with an exploit which allows hackers to pair with devices without alerting their owner. The approach gets around limitations of a security attack first described by Ollie Whitehouse of security firm @Stake last year. This earlier method meant an attacker needed to eavesdrop the initial connection process (pairing) between two Bluetooth devices, which only occurs infrequently.

Shaked and Wool have worked out a way to force this pairing process by masquerading as a device, already paired with a target, that has supposedly forgotten a link key used to secure communications. This initiates a fresh pairing session which a hacker can exploit to snaffle the link key and thereby establish a pairing without needed to know PIN details. Once a connection is set up, an attacker could make eavesdrop on data transmitted between a target devices and a PC or (at least potentially) take control of someone's Bluetooth device. "Once an attacker has forced two devices to pair, they can work out the link key in just 0.06 seconds on a Pentium IV-enabled computer," New Scientist reports.

Shaked and Wool are scheduled to outline their research at the MobiSys conference in Seattle this week. ®

Related stories

Porn, Dubai and Bluetooth phone hacking...
Car virus myth debunked
Security researchers nibble at Bluetooth
Wi-Fi honeypots a new hacker trap

alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe