Bluetooth 5
link.bluetooth.com
link.bluetooth.com
Bluetooth 5 seems to increase the range of LE communications, but since I'm almost sure we're going to have some horrible public hack of one of the platforms at some point, I hope there is increased focus on the security of devices that use it!
It's also terrible that people, and their clothing, are so detectable in the visible light spectrum. Where's the 'tarnkappe' when you need it?
( https://en.wikipedia.org/wiki/Cloak_of_invisibility )
Also appreciate the "will be marketed as 'Bluetooth 5.' [no dot zero]". Sounds like a band name, or a gang. Good thinking there - the Bluetooth 5 are now taking over the neighborhood ...
I wasn't completely clear above, but there are a couple of differences:
- Your clothing doesn't contain unique identifiers (yet!) :)
- The devices seem to often be happy to broadcast their information in the clear. Your clothes don't advertise your position or heart rate to the whole world either!
But your face does...
I'm also one of the authors of RaMBLE, another BLE app (https://play.google.com/store/apps/details?id=com.contextis....). It can run in the background, and can export logged BLE advertising packets and geolocation data to a SQLite DB.
I've implemented a UI hint to make this more obvious, which will be in the next version of RaMBLE.
Another thing I just realised is the number of new devices in the notification label. Let's say I put ramble in the background. After 10 minutes it tells me that there are n_1 new devices. I click on the notification in order to check them out. If I then put ramble in the background and it finds n_2 new devices then the notification says that there are now n_1 + n_2 new devices. I would expect that it says n_2 devices.
If you export the database you can pull some more interesting numbers out, e.g. http://www.contextis.com/resources/blog/bluetooth-le-increas...
I have no idea if it's particularly good in comparison to others, but I downloaded it to debug a Bluetooth LE device I was building and it was a pretty straightforward UI.
Perhaps you would like to explain what the problem with this is? Broadcasting presence in itself is not a security hole - unless you think "Do not broadcast SSID" is a WiFi AP security feature (it's not). If WiFi can be secured (with devices that "scream data about themselves"), why would Bluetooth be any different?
I suspect the GP is just referring to the stuff they happen to be transmitting in the clear right now because they weren't thinking about the risks. Basically like early days 802.11 when you needed to pay big money for something like wireshark.
Well, there are a couple of reasons I think this is different:
1. APs are static and not mobile, versus Bluetooth devices – which can move, and are more importantly personally associated with a person. That inherently provides opportunities for more leakage on information, since device addresses can now be used to track people.
2. Devices aren't just advertising their existence. They're also advertising their services, and in some cases actually just sending whatever data a client asks for. There's a particular brand of iPad stylus which seems to just open up and send it's accelerometer readings to any device which connects. There seem to be heart-rate monitors that do the same.
For me, it's much more worrying that devices happily broadcast personal information without authentication – I don't actually think device advertisement is a big deal in comparison!
You could track people around a fairly good area, like a shopping mall, using off-the-shelf, inexpensive Bluetooth hardware and just keeping track of where various IDs turn up. Indoors, that's probably much more accurate tracking than you could perform using cellular triangulation. It's more like the kind of tracking you do using RFID tokens in a warehouse.
I don't know if it's a problem per se, but it's something people should be aware of; many devices are constantly broadcasting a unique identifier almost all the time unless they take steps to turn it off.
I can't tell whether you're referring to Bluetooth, WiFi, or both. WiFi is worse (longer range) and I suspect more widely used and likely to be left on on phones.
My bet is that indoor positioning is gonna be the game changer in the coming years (not robotics, not AI, not voice recognition, not yet, at least). So, I'm particularly looking forwards to see what's in store on the Bluetooth roadmap in that respect. The only thing I wish is that they would be faster in rolling out mesh functionality...
Ubertooth had to be custom built to sniff bluetooth traffic, while just about any old dongle will do for wifi.
And IMO, a big advantage with bluetooth is that it has profiles for common usage scenarios. Meaning that you have defined standards for how to do things like file transfers over bluetooth, while it is wild west when it comes to wifi.
reusing proprietary library is as close as you can get without paying Qualcomm tax
Tongue-in-cheek, well mostly but not entirely .. I do appreciate e.g. accurate travel times, yet refuse to believe they won't take it to the next step. http://www.theage.com.au/victoria/how-vicroads-tracks-your-e...
Instead, they use private resolvable keys for all handshakes with devices around them. A new key is generated every few minutes, and only a device which you have previously bonded with is able to resolve your key through data exchanged in the bonding process.
Seems to be getting better though; a quick look at the local price comparison site gave 419 wireless keyboards, 296 of which are using Bluetooth.
It's a solved problem I believe since BT LE (low energy) I believe. Now it's just a matter of market adoption.
I've also found that many proprietary dongle keyboards work over USB-OTG on Android phones.
[1] https://www.microsoft.com/accessories/en-us/products/mice/sc... ($20 on Amazon)
That's what my initial thought was too. Sounds like severe 2.4GHz pollution.
So no, it's not a defensible position as it renders the $3000 machine useless, similarly to how a $3000 car whose steering wheel steers randomly would render it useless.
This is laughable wrong. You clearly have either a) issues with your peripherals or b) an incredibly saturated wireless signal environment.
OSX is practically the gold standard of BT integration - it's seamless for almost every application.