ZeroHour
Schneier on Securitypublished ()ingested

Major Bluetooth Vulnerability

mediumVulnerabilityimportance 30
Full article130 words · extracted from schneier.com · click to collapse

Bluetooth has a serious security vulnerability:

In some implementations, the elliptic curve parameters are not all validated by the cryptographic algorithm implementation, which may allow a remote attacker within wireless range to inject an invalid public key to determine the session key with high probability. Such an attacker can then passively intercept and decrypt all device messages, and/or forge and inject malicious messages.

Paper. Website. Three news articles.

This is serious. Update your software now, and try not to think about all of the Bluetooth applications that can’t be updated.

Tags: academic papers, Bluetooth, cryptography, encryption, keys, vulnerabilities, Wi-Fi, wireless

Posted on July 25, 2018 at 2:08 PM25 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2018/07/major_bluetooth.html