Student tracks Bluetooth headset wearers by wardriving around Oslo on a bicycle
theregister.com
theregister.com
https://www.houstontranstar.org/faq/traffictech.aspx
On the OEM infotainment center in my vehicle, I can't even find a way to turn off Bluetooth.
I cannot mention the state because their presence is not disclosed publicly.
It’s not any more, but all it did was ping for MAC addresses at both ends of the stretch. I suppose the data could prove your presence, but it’s the presence of your car really. At least with Apple the MAC gets cycled now.
Wow, lots of maps in there. He also recorded WiFi SSIDs and mapped which one were still on WEP, or even unencrypted (although my guess is these are public ones like in a coffee shop)
Even unencrypted? I am biased here having run an open wifi since they were commercially avilable.
In the beginning, there was this huge concern that wifi would hurt the last mile ISP business. Many started outright forbidding guests using the connection in their terms of service. That didn't work out very well. Calling them insecure and having papers write about how to check that other people couldn't connect to work network worked much better.
My concern is that letting the commercial ISPs set the discourse around encryption, which is better suited for the endpoints than the transmission layer, set us back several years of deploying encryption everywhere. It also made for in my opinion unnecessary concerns around real world implementations of mesh networking.
Note that there are security concerns with running unencrypted wifi as compared to having a shared secret publicly available. An SSL-only world mostly mitigates this, and encrypted DNS is a piece to this story. End user systems could easily have had a no plain text-option among their firewall settings to help get this going. Language matters. Commercial interests are obvious here, the lay persons focus on transmission encryption made this transition harder, and every time someone speaks of insecure last mile transmission we are reminded of it.
But the real trouble with this system is that the police aren't going to do anything with this data unless there's a murder. Even if a bluetooth device were stolen and you could locate it, the police will not likely help you recover anything. And this assumes that they even understand what this pissed-off nerd is on about.
Amazon, however, could build a bluetooth sniffer or IMSI catcher into its devices and sell the resulting data to law enforcement, who could then avoid the time and expense of getting a warrant for location data. Assuming that the police care at all about property crime, this would achieve the goal.
I've experienced this reliance on MAC addresses by trying to use Bluetooth headphones in a dual boot system. Every time I switch operating systems, I need to repair. Same with phones that have been factory reset. Peripherals seem to assume that a device (MAC address) uuniquely identifies the other end of the connection (which it actually is supposed to, so fair enough). You can probably use random addresses for scanning for new devices, but for any active use of the protocol you're going to need to stick to a given address. As long as you only use one device at a time, that address can probably be randomised for each device, but that's a hard sell that strongly limits how Bluetooth can be used.
Bluetooth LE, which is used for wearables like smart watches etc, supports address randomization and it has mechanism for finding paired devices even though the address changes. Bluetooth LE devices must advertise for other devices to be able to connect. Many headsets nowadays use classic Bluetooth for audio streaming and handsfree but in addition they use Bluetooth LE for configuring the headset through their app. That is why the headsets are often advertising all the time.
As a side note, contact tracing apps are making our phones also to advertise. Fortunately they are using address randomization properly to ensure phones can't be tracked.
Were the headsets all in "discoverable" mode ? Are headsets announcing their MACs even when not in discoverable mode ? Or do they broadcast their MACs in plain text even during a paired&encrypted connection ?
[0] https://bookdown.org/fede_caruso/bookdown/the-journalistic-e...