Welcome to WiFi-Forum

Go Back   WiFi-Forum - Wi-Fi Discussion Forum > Bluetooth Discussion Forums > alt.cellular.bluetooth
Reply
 
Thread Tools Display Modes
  #1  
Old 05-17-2004, 10:04 AM
Daniel Brose
 
Posts: n/a
Default bluetooth and security

Hi all!

Lately I've heard a lot about security leaks in bluetooth phones like
the SonyEricsson T610 e.g.. I've been told that without obvious pairing
people can use your phone for making calls or sending SMS or "download"
your addressbook. Of course I use "hidden mode" for BT, but that just
makes it more difficult yet not impossible.
What do you guys think about that? Do you switch of BT?


Thanks in advance
Daniel

Reply With Quote
  #2  
Old 05-18-2004, 02:22 AM
Michael Schmidt
 
Posts: n/a
Default Re: bluetooth and security

Hi Daniel,

Daniel Brose schrieb:

> Hi all!
>
> Lately I've heard a lot about security leaks in bluetooth phones like
> the SonyEricsson T610 e.g.. I've been told that without obvious pairing
> people can use your phone for making calls or sending SMS or "download"
> your addressbook. Of course I use "hidden mode" for BT, but that just
> makes it more difficult yet not impossible.
> What do you guys think about that? Do you switch of BT?


From my understanding, running your BT phone in "non-discoverable mode"
(this is probably what you call "hidden mode") is sufficient. Guessing
the BT address (with "Redfang" or sth. comparable") takes (based on my
tests) about 20 secs per probed address. However, there is an address
space of (at least) 256 ^ 3 addresses (given the manufacturer of your
phone is known to the attacker). So you averagely need 256 ^ 3 * 20 secs
/ 2 = 5 years to find the address of a non-discoverable phone. This is
totally unrealistic.

I'm wondering whether anybody here has made other experiences with
"Redfang" that would make this tool appear more realistic.

Without knowing your device address an attacker is not able to attack
your non-discoverable BT phone.


Michael

--
Michael Schmidt
University of Siegen, Germany
http: www.nue.et-inf.uni-siegen.de/~schmidt/
e-mail: schmidt _at_ nue.et-inf.uni-siegen.de
Reply With Quote
  #3  
Old 05-18-2004, 07:28 AM
Collin R. Mulliner
 
Posts: n/a
Default Re: bluetooth and security

Hello,

> From my understanding, running your BT phone in "non-discoverable
> mode"
> (this is probably what you call "hidden mode") is sufficient. Guessing


yes, "hidden mode" should be ok.

> I'm wondering whether anybody here has made other experiences with
> "Redfang" that would make this tool appear more realistic.


not really

> Without knowing your device address an attacker is not able to attack
> your non-discoverable BT phone.


exactly!


.... Collin

--
Collin R. Mulliner <collin@betaversion.net>
bluetooth device security database - http://betaversion.net/btdsd/


Reply With Quote
  #4  
Old 05-18-2004, 08:09 AM
Daniel Brose
 
Posts: n/a
Default Re: bluetooth and security

Hi all,

Collin R. Mulliner schrieb:
>>Without knowing your device address an attacker is not able to attack
>>your non-discoverable BT phone.

>
> exactly!


thanks a lot for your answers! I feel relieved now... :-)


Regards
Daniel

Reply With Quote
  #5  
Old 05-21-2004, 02:43 AM
Nosve
 
Posts: n/a
Default Re: bluetooth and security

There is a firmware version that correct the t610 behaviour, since the
weakness is in the implementation anche not intrinsic in the bluetooth
protocols.

In italy formware update is free under warranty
Regards.


"Daniel Brose" <Daniel.Brose@bur-kg.de> ha scritto nel messaggio
news:2gs64vF652t0U1@uni-berlin.de...
> Hi all!
>
> Lately I've heard a lot about security leaks in bluetooth phones like
> the SonyEricsson T610 e.g.. I've been told that without obvious pairing
> people can use your phone for making calls or sending SMS or "download"
> your addressbook. Of course I use "hidden mode" for BT, but that just
> makes it more difficult yet not impossible.
> What do you guys think about that? Do you switch of BT?
>
>
> Thanks in advance
> Daniel
>



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bluetooth security Rlaf BlueTooth Forum 0 08-30-2004 11:09 PM
WiFi Security, what are the issues you face ? ? ocassim@informationexchan WiFi Forum 1 08-18-2004 03:31 AM
programming MSI pc2pc bluetooth key in Windows XP Eero Lehtinen alt.cellular.bluetooth 0 06-03-2004 12:33 AM
security mdb BlueTooth Forum 3 01-12-2004 12:42 PM




All times are GMT -7. The time now is 09:45 PM.

vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd. All Contents Copyright © Wifi-Forum.com