ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

New Bluetooth Attack

mediumVulnerabilityimportance 30
Full article130 words · extracted from schneier.com · click to collapse

New attack breaks forward secrecy in Bluetooth.

Three news articles:

BLUFFS is a series of exploits targeting Bluetooth, aiming to break Bluetooth sessions’ forward and future secrecy, compromising the confidentiality of past and future communications between devices.

This is achieved by exploiting four flaws in the session key derivation process, two of which are new, to force the derivation of a short, thus weak and predictable session key (SKC).

Next, the attacker brute-forces the key, enabling them to decrypt past communication and decrypt or manipulate future communications.

The vulnerability has been around for at least a decade.

Tags: authentication, Bluetooth, cyberattack, man-in-the-middle attacks, secrecy, vulnerabilities

Posted on December 8, 2023 at 7:05 AM7 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2023/12/new-bluetooth-attack.html