* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Monday, December 29, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    SIE Partners with Bad Robot Games to Produce and Publish the Studio’s First Internally Developed Game – sonyinteractive.com

    SIE Joins Forces with Bad Robot Games to Unveil Their First In-House Developed Title

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    Movies and TV shows casting across the US – Wyoming News Now

    Movies and TV shows casting across the US – Wyoming News Now

    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Devices in schools–how much is too much? – Westport Journal

    Are Devices in Schools Enhancing Learning or Creating Distractions?

    Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

    Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

    New technology trialled on £2m Bedford Lock upgrade – BBC

    Revolutionary Technology Breathes New Life into £2 Million Bedford Lock Upgrade

    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    SIE Partners with Bad Robot Games to Produce and Publish the Studio’s First Internally Developed Game – sonyinteractive.com

    SIE Joins Forces with Bad Robot Games to Unveil Their First In-House Developed Title

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    Movies and TV shows casting across the US – Wyoming News Now

    Movies and TV shows casting across the US – Wyoming News Now

    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Devices in schools–how much is too much? – Westport Journal

    Are Devices in Schools Enhancing Learning or Creating Distractions?

    Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

    Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

    New technology trialled on £2m Bedford Lock upgrade – BBC

    Revolutionary Technology Breathes New Life into £2 Million Bedford Lock Upgrade

    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Weak session keys let snoops take a byte out of your Bluetooth traffic

November 30, 2023
in Technology
Weak session keys let snoops take a byte out of your Bluetooth traffic
Share on FacebookShare on Twitter

Multiple Bluetooth chips from major vendors such as Qualcomm, Broadcom, Intel, and Apple are vulnerable to a pair of security flaws that allow a nearby miscreant to impersonate other devices and intercept data.

The weaknesses were identified by Daniele Antonioli, an assistant professor at French graduate school and research center EURECOM’s software and system security group. He detailed the attack vectors by which the flaws could be exploited in a paper [PDF] titled “BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses.”

Antonioli’s explanation states that the flaws exist in versions of the Bluetooth Core Specification from 2014’s version 4.2 to the February 2023 version 5.4.

BLUFFS – for BLUetooth Forward and Future Secrecy – is a set of six distinct attacks. Forward secrecy protects past sessions against key compromise, while future secrecy does the same thing for future sessions.

The attacks force the creation of weak session keys, which are used when paired Bluetooth devices try to establish a secure communication channel. Weak keys can be easily broken, allowing the eavesdropper to hijack sessions and snoop on victims’ conversations, data, and activities carried out over Bluetooth.

“Our attacks enable device impersonation and machine-in-the-middle across sessions by only compromising one session key,” Antonioli explained in his paper. “The attacks exploit two novel vulnerabilities that we uncover in the Bluetooth standard related to unilateral and repeatable session key derivation.”

Antonioli wrote that since the attacks impact Bluetooth at the architectural level, they work regardless of hardware and software variations. The BLUFFS attacks are said to have been tested successfully on 18 Bluetooth devices from Intel, Broadcom, Apple, Google, Microsoft, CSR, Logitech, Infineon, Bose, Dell, and Xiaomi, which use 17 different chips. And they affect both Bluetooth security modes: Secure Connections (SC) and Legacy Secure Connections (LSC).

Devices found to use chips susceptible to BLUFFS include smartphones and wireless earbuds from Apple and Google, and a Lenovo ThinkPad.

A dirty dozen of Bluetooth bugs threaten to reboot, freeze, or hack your trendy gizmos from close range

Billions of Bluetooth gadgets bothered by ‘BLURtooth’ miscreant-in-the-middle bug

BrakTooth vulnerabilities put Bluetooth users at risk – and some devices are going unpatched

Zephyr OS Bluetooth vulnerabilities left smart devices open to attack

“The BLUFFS attacks have a severe impact on Bluetooth’s security and privacy,” Antonioli wrote. “They allow decrypting (sensitive) traffic and injecting authorized messages across sessions by re-using a single session key.”

The BLUFFS code repo contains Arm code patches and an attack-checking tool that takes packet capture (pcap) files and isolates Bluetooth sessions to calculate session keys and detect BLUFFS attacks. Antonioli has proposed protocol-level countermeasures involving three extra Link Manager Protocol packets and three extra function calls that vendors can implement while awaiting a Bluetooth specification revision that makes session establishment more secure.

According to Antonioli, the vulnerability was responsibly disclosed in October 2022 to the Bluetooth Special Interest Group (SIG), which in turn coordinated the disclosure of CVE-2023-24023 to multiple vendors.

Google has categorized BLUFFS as a high-severity vulnerability – worthy of a bug bounty – and is said to be working on a fix. Intel also awarded a bounty but designated BLUFFS medium severity. Apple and Logitech reportedly are aware of the issue and working on fixes, while Qualcomm hasn’t yet acknowledged the researchers’ disclosure.

The Bluetooth SIG, which oversees the short-range wireless specification, has issued a security notice about the vulnerability. The notification advises those implementing Bluetooth to configure their systems to reject connections with weak keys. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/11/30/bluetooth_bluffs_attacks_are_no/

Tags: Sessionsnoopstechnology
Previous Post

AI offers some novel crystal materials that could form future chips, batteries, more

Next Post

Honda cooks up an electric motorbike menu, with sides of connectivity

Year in review: Trump’s foreign policy – NPR

Year in review: Trump’s foreign policy – NPR

December 29, 2025
“Reimagining an Old Yard as a River Classroom” – The Napa Valley Register

From Forgotten Yard to Lively River Classroom: A Stunning Transformation

December 29, 2025
Mysterious State of Matter Discovered Flowing Inside Earth’s Core – ScienceAlert

Scientists Discover Mysterious New State of Matter Flowing Deep Within Earth’s Core

December 29, 2025
Winter break fun at the Cape Fear Museum of History and Science – Wilmington Star-News

Winter break fun at the Cape Fear Museum of History and Science – Wilmington Star-News

December 29, 2025
12 things people over 60 do that show they were raised to survive, not thrive – VegOut

12 Powerful Habits That Show the Resilience and Strength of People Over 60

December 28, 2025
Devices in schools–how much is too much? – Westport Journal

Are Devices in Schools Enhancing Learning or Creating Distractions?

December 28, 2025
NFL picks for Week 17, exact score predictions, best bets today from self-learning AI – CBS Sports

Week 17 NFL Showdown: Precise Score Predictions and Winning Bets Powered by Advanced AI

December 28, 2025
“The last text I got from Oz said, ‘Zakky, sorry, it was like a madhouse back there. I didn’t see you. Thanks for everything’”: Zakk Wylde looks back on his closer-than-close relationship with Ozzy Osbourne, and their final moments together onstage – Guit

“The last text I got from Oz said, ‘Zakky, sorry, it was like a madhouse back there. I didn’t see you. Thanks for everything’”: Zakk Wylde looks back on his closer-than-close relationship with Ozzy Osbourne, and their final moments together onstage – Guit

December 28, 2025
Last Week at Economy Class and Beyond (27th December) – Economy Class & Beyond –

Top Moments from Economy Class and Beyond: Week Ending December 27th

December 28, 2025
SIE Partners with Bad Robot Games to Produce and Publish the Studio’s First Internally Developed Game – sonyinteractive.com

SIE Joins Forces with Bad Robot Games to Unveil Their First In-House Developed Title

December 28, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (993)
  • Economy (1,011)
  • Entertainment (21,888)
  • General (19,009)
  • Health (10,051)
  • Lifestyle (1,024)
  • News (22,149)
  • People (1,018)
  • Politics (1,026)
  • Science (16,227)
  • Sports (21,512)
  • Technology (15,994)
  • World (1,000)

Recent News

Year in review: Trump’s foreign policy – NPR

Year in review: Trump’s foreign policy – NPR

December 29, 2025
“Reimagining an Old Yard as a River Classroom” – The Napa Valley Register

From Forgotten Yard to Lively River Classroom: A Stunning Transformation

December 29, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version