Billions of Devices Vulnerable To New 'BLESA' Bluetooth Spoofing Attack

oauccer972

Member
Joined
Sep 17, 2020
Messages
7
Gender
Male
Religious Affiliation
Catholic
Marital Status
Single
Acceptance of the Trinity & Nicene Creed
Yes
" Billions of smartphones, tablets, laptops, and IoT devices are using Bluetooth software stacks that are vulnerable to a new security flaw disclosed over the summer," reports ZDNet. Named BLESA (Bluetooth Low Energy Spoofing Attack), the vulnerability impacts devices running the Bluetooth Low Energy (BLE) protocol, and affects the reconnection process that occurs when a device moves back into range after losing or dropping its pairing. A successful BLESA attack allows bad actors to connect with a device (by getting around reconnection authentication requirements) and send spoofed data to it. In the case of IoT devices, those malicious packets can convince machines to carry out different or new behavior. For humans, attackers could feed a device deceptive information. "

It seems like every day we hear about an issue when it comes to devices, specifically some IoT devices that probably will never be updated to remove or fix such issues. Can you imagine that the IoT camera you have in your house gets hacked using this by someone hiding in your backyard to see if your family is sleeping before breaking in?
 

tango

... and you shall live ...
Valued Contributor
Joined
Jul 13, 2015
Messages
14,695
Location
Realms of chaos
Gender
Male
Religious Affiliation
Christian
Marital Status
Married
Acceptance of the Trinity & Nicene Creed
Yes
Just one reason I refuse to have things recording audio or video left permanently connected in my house.

I'm sure it's really convenient to be able to just say "Device, do this" without having to make any effort but I really don't want to find someone else did it for me.

I read an interesting story about a much lower-tech hack. A guy who lived in a downstairs apartment got back from vacation to find his apartment warmer than he expected it to. Apparently after he left his neighbors from upstairs (who would benefit from his apartment being warmer) pushed his letterbox open and shouted through it "Alexa, set the heat to 78 degrees" and enjoyed the heat that he ended up paying for.

The trouble is that so many people are focused so intently on the benefits of new doodads they seldom if ever consider the potential downsides.
 

Forgiven1

Well-known member
Joined
Jun 23, 2015
Messages
1,027
Location
Texas
Gender
Female
Religious Affiliation
Lutheran
Political Affiliation
Conservative
Marital Status
Married
Acceptance of the Trinity & Nicene Creed
Yes
It is my understanding that Apple put out an update to fix this back in May or June.
 
Top Bottom