Technology
Bluetooth devices may leak your secrets due to design flaw
New York, Nov 15
Be it a fitness tracker, smartwatch, smart speaker or smart home assistant, the way Bluetooth devices communicate with the mobile apps leaves room for hackers to steal sensitive personal information, new research has found.
An inherent design flaw makes mobile apps that work with Bluetooth Low Energy devices vulnerable to hacking, said the study described at the Association for Computing Machinery's Conference on Computer and Communications Security held in London from November 11-15.
"There is a fundamental flaw that leaves these devices vulnerable -- first when they are initially paired to a mobile app, and then again when they are operating," said Zhiqiang Lin, Associate Professor of Computer Science and Engineering at The Ohio State University in the US.
"While the magnitude of that vulnerability varies, we found it to be a consistent problem among Bluetooth low energy devices when communicating with mobile apps," Lin added.
Consider a wearable health and fitness tracker, smart thermostat, smart speaker or smart home assistant.
Each first communicates with the apps on your mobile device by broadcasting something called a UUID -- a universally unique identifier.
That identifier allows the corresponding apps on your phone to recognise the Bluetooth device, creating a connection that allows your phone and device to talk to one another.
But that identifier itself is also embedded into the mobile app code. Otherwise, mobile apps would not be able to recognise the device. However, such UUIDs in the mobile apps make the devices vulnerable to a fingerprinting attack, the research team found.
"At a minimum, a hacker could determine whether you have a particular Bluetooth device, such as a smart speaker, at your home, by identifying whether or not your smart device is broadcasting the particular UUIDs identified from the corresponding mobile apps," Lin said.
"But in some cases in which no encryption is involved or encryption is used improperly between mobile apps and devices, the attacker would be able to 'listen in' on your conversation and collect that data."
Still, that doesn't mean you should throw your smartwatch away.
"We think the problem should be relatively easy to fix, and we've made recommendations to app developers and to Bluetooth industry groups," he said.
If app developers tightened defences in that initial authentication, the problem could be resolved, Lin said.
The team reported their findings to developers of vulnerable apps and to the Bluetooth Special Interest Group, and created an automated tool to evaluate all of the Bluetooth Low Energy apps in the Google Play Store - 18,166 at the time of their research.
In addition to building the databases directly from mobile apps of the Bluetooth devices in the market, the team's evaluation also identified 1,434 vulnerable apps that allow unauthorised access. Their analysis did not include apps in the Apple Store.
"It was alarming," he said. "The potential for privacy invasion is high."
An inherent design flaw makes mobile apps that work with Bluetooth Low Energy devices vulnerable to hacking, said the study described at the Association for Computing Machinery's Conference on Computer and Communications Security held in London from November 11-15.
"There is a fundamental flaw that leaves these devices vulnerable -- first when they are initially paired to a mobile app, and then again when they are operating," said Zhiqiang Lin, Associate Professor of Computer Science and Engineering at The Ohio State University in the US.
"While the magnitude of that vulnerability varies, we found it to be a consistent problem among Bluetooth low energy devices when communicating with mobile apps," Lin added.
Consider a wearable health and fitness tracker, smart thermostat, smart speaker or smart home assistant.
Each first communicates with the apps on your mobile device by broadcasting something called a UUID -- a universally unique identifier.
That identifier allows the corresponding apps on your phone to recognise the Bluetooth device, creating a connection that allows your phone and device to talk to one another.
But that identifier itself is also embedded into the mobile app code. Otherwise, mobile apps would not be able to recognise the device. However, such UUIDs in the mobile apps make the devices vulnerable to a fingerprinting attack, the research team found.
"At a minimum, a hacker could determine whether you have a particular Bluetooth device, such as a smart speaker, at your home, by identifying whether or not your smart device is broadcasting the particular UUIDs identified from the corresponding mobile apps," Lin said.
"But in some cases in which no encryption is involved or encryption is used improperly between mobile apps and devices, the attacker would be able to 'listen in' on your conversation and collect that data."
Still, that doesn't mean you should throw your smartwatch away.
"We think the problem should be relatively easy to fix, and we've made recommendations to app developers and to Bluetooth industry groups," he said.
If app developers tightened defences in that initial authentication, the problem could be resolved, Lin said.
The team reported their findings to developers of vulnerable apps and to the Bluetooth Special Interest Group, and created an automated tool to evaluate all of the Bluetooth Low Energy apps in the Google Play Store - 18,166 at the time of their research.
In addition to building the databases directly from mobile apps of the Bluetooth devices in the market, the team's evaluation also identified 1,434 vulnerable apps that allow unauthorised access. Their analysis did not include apps in the Apple Store.
"It was alarming," he said. "The potential for privacy invasion is high."

9 hours ago
Governor Brian Kemp Appoints New Director to Georgia Regional Transportation Authority Board

10 hours ago
CPM state conference in Kollam, MLA kept out; Unofficial ban on Mukesh?

11 hours ago
Must marry the survivor within 3 months'; Bail granted to the accused in a rape case with conditions

11 hours ago
Hid the fact that he was married and got into a relationship; Friend arrested in connection with the suicide of Kozhikode Law College student Maus Mehrisi (20) who was in hiding.

13 hours ago
By Heavens, Bangalored, but breathless megapolis

13 hours ago
US likely to bar entry of Pakistanis, impose complete travel ban soon

15 hours ago
'President Trump delivered justice for American heroes killed at Abbey Gate': US Press Secy on detention of Mohammad Sharifullah

15 hours ago
Indian student found dead in US; Consulate in Chicago in touch with family

15 hours ago
Trump administration rejects Gaza reconstruction plan proposed by Arab leaders

17 hours ago
Gave a contract to kill"; Case filed against the driver of late CPI leader P. Raju.

17 hours ago
Went to write the exam but never returned; Plus Two students missing in Malappuram, complaint filed.

17 hours ago
A 12-year-old boy gave MDMA to his 10-year-old sister; stole ₹3 lakh for drug use.

18 hours ago
Maryland Awards $12.4 Million in Opioid Restitution Fund Competitive Grants, Announces Strategic Overdose Response Priorities