Widespread security risk identified in phones and Bluetooth devices
spectrum.ieee.org
spectrum.ieee.org
This is a lot less powerful than I expected from the title but perhaps I'm not thinking big enough. A powerful adversary could set up sniffers all over the city and track the population, I guess, but I imagine the value of this method goes down the more phones that are being distinguished (variability among millions of phones probably means a lot of overlap, especially considering it doesn't seem that variation in signal is consistent).
You may be able to achieve the same goal without exploiting this security weakness.
A few years back I built a "people counter" app - it was mostly a learning exercise to see what I could do with the Android Bluetooth API, but I was also curious to see how useful a signal Bluetooth might be in finding the least crowded car on a packed commuter train. After a week of testing it on the ride home I had data to suggest that it was. I also found that based on MAC addresses and device names I was among the same group of strangers most nights of the week. And this was despite MAC address randomization which IIRC was already implemented in iDevices.
I feel this extends to surveillance of this type: the threat seems much less important if it can only be conducted when access to the individual is already required.
Say we’ve followed some chap around and identified this issue with his phone or watch etc - and we can then keep tracking this chap on the proviso that we are nearby to confirm an ID, he has those items with him and we have our sensors ready and waiting.
Like… why not just follow the guy then.
What about an encrypted partition, unlocked at boot. If I give you my laptop, how is the data accessible ?
Is your laptop on or suspended-to-ram/to-disk?
How strong is your passphrase?
Do you have IOMMU/VT-d ?
Laptop I am thinking about has VT-d but I haven't enabled it in years (not needed).
I give an encrypted laptop/ machine and I want the other party to prove that having access to the device = no security and so they can read data out of it.
No if, no but: I give the machine, show me that having it=no security.
Now if you don't get the laptop back, your data is as secure as the encryption implementation of your OS.
I'd bet it's secure enough against anything that is not the NSA / equivalent foreign agencies. Now would I bet against those big players? Certainly not.
Which is another shortcut that boils down to saying "nothing is secure".
I have a beef with broad statements like that :].
Even if the math is bulletproof, are you sure the software implementation is bulletproof too?
Even then, maybe there's something in your hardware that defeat the whole thing, who knows?
When the stakes are so high that this kind of agencies are trying to get your data, that would be a risky bet to assume they won't be able to crack your encrypted partition.
I'm pretty sure if you ask them nicely to give you a few of their old encrypted hard drives they wouldn't comply. Why not?
> When the stakes are so high that this kind of agencies are trying to get your data, that would be a risky bet to assume they won't be able to crack your encrypted partition.
I do agree. Even if I knew the NSA was after me and I knew how to secure my laptop with custom Libreboot and other things I strongly believe the laptop should not be used to discuss matters or store data related to activities that got the agency on my back. I will do an humane error and compromise myself before they need to use strong tech against my laptop.
In most cases the adversary would choose to use their physical access at a time when you will use it again afterwards, so they could install a hardware keylogger. Cases where you will never use the machine again are more the exception than the rule.
I dare say that the comment has merely been used as a vehicle for a facile pedant.
https://en.m.wikipedia.org/wiki/Intel_Management_Engine
>The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off. This issue can be mitigated with deployment of a hardware device, which is able to disconnect mains power.
>The Intel ME is an attractive target for hackers, since it has top level access to all devices and completely bypasses the operating system. The Electronic Frontier Foundation has voiced concern about Intel ME and some security researchers have voiced concern that it is a backdoor.
> Intel's main competitor AMD has incorporated the equivalent AMD Secure Technology (formally called Platform Security Processor) in virtually all of its post-2013 CPUs.
You can buy boards with it disabled, some Dell devices have the option to disable it, some flashing can be done on mobos to clear ME unofficially, but assume everything has it unless you only otherwise.
It changes the scope from "access to device = no security" to "access to device by NSA people with a very specific set of skills and most likely some prep work = no security" and I won't fight it, it's right. Not possible for the random HN user though and it still means some very specific circumstances.
Circumstances that need someone to compromise my laptop at some point after it got out of the factory. From reading the Wikipedia article it's not clear ME leaves a backdoor or store user passwords or keys somewhere on the computer in case an NSA agent needs to access data.
I think my encrypted devices are safe, unless the NSA or a nation state wants its data.
Would have been nicer of Apple to just contribute a generic improvement back to the Bluetooth Standard, instead of solving a problem by creating "AirPods Bluetooth" and split the market.
Using that course, Google went and made Google-custom enhancements to Bluetooth as well, to apply nearly the same improvements to the user experience as Apple did.
And now here we are, with a universal standard that should work across different products and industries, but for good user experience you now have to brand-match your Bluetooth devices...
Really sad to watch common standards die. With all its flaws aside, I wonder if anything like Bluetooth would even be possible to happen today...
Interesting to hear that Apple managed to solve the issues within their closed ecosystem. So at least a solution DOES exists. The world could be so much better! Agree that it would be nice it thos solutions could penetrate the non-Apple world also.
Ironically, this method of tracking is one of the conter-arguments I've heard to the "Facebook is recording my conversations" theory.
I don't know enough about it to understand how this attack is different than in-store phone tracking.
[1] https://www.vox.com/platform/amp/recode/2019/12/19/21011527/...
If you're building up profiles, wouldn't you build them up enough to be able to later disambiguate phones with identical signatures that got too close to each other? The devices are probably each going to more-or-less continue in their long-established habits after they part. I guess that adds a bit of irregular latency, because you'd often have to label some device/location pairs retrospectively.
I've found that it is not reliable, and I try to turn it off myself.
I guess any wireless channel will have the same vulnerability, but your phone already identifies itself on a huge variety of ways with much more standard interfaces.
By the way, you are already tracked countrywards. The only questions are if your phone operator is allowed to keep the data and whether it does.
If I really needed this kind of discretion, I would still put the phone in a Faraday cage.
I don't know how good this is, can anyone comment?
It's supposed to mitigate that leak.
And why? It isn’t necessary, the access points broadcast their SSID so you just need to listen to the radio to know what’s around you.
I have looked for information on this but not found it. If this issue really exists, please provide a link to a description.
And yet they keep using their phones to spread lies and hate on Facebook.
Perhaps we on HN need to start this by changing such submission titles, or marking them as misleading. There's a bit of this already in the form of comments. I've made a habit of checking them out before even clicking the article for this exact reason.
I probably would have clicked through if it was krebsonsecurity or some other security research team's blog.
IEEE used to be the accountability termination for an entire set of professions. Or, well, they still are. They are on the position where they just can't be wrong. They shouldn't wander on low-credibility activities.
Everybody run around in panic!
Commercial tools have been available to do just this for a decade. Cities commonly use bluetooth sniffers to gather LAPs from passing cars to estimate travel times and detect traffic jams. I'd bet good money that the device used in this article was an ubertooth, a basic tool that I have had in my wifi tricks box for nearly ten years. Such basic sniffers are integrated into any many of commercial solutions. If you are running with your bluetooth system powered on you have effectively opted into every such system.
"Our advanced queue warning systems use Bluetooth and WiFi to collect information from and about vehicles. If it’s taking longer than normal for vehicles to travel a certain distance, you can alert drivers to change their plans."
Here's an article from 10 years ago talking about tracking people in airports. https://www.futuretravelexperience.com/2011/04/bluetooth-pro...
I wouldn’t think that it is a massive problem as most of the “I want to know how fast people move” level of information is simply independent of being able to actually identify the specific person. But maybe I’m underestimating the willingness to grab data or overestimating how sensitive the equipment needs to be to be reliable
Which you could argue is kind of obvious too I guess cause you can fingerprint anything from someone’s writing style to someone’s installed fonts
The frequency of a device will drift over time, no matter how hard to try not to let it happen.
The IQ mismatch could be tweaked if it turned out to be an actual problem.
Together, these are about as unique as noting your temperature, and the length of your hair.
It's interesting to be able to track a single device in a room, for a while, until conditions drift. It's not something to panic about, in my opinion.
If the Apple AirTag things are as affected that could be a huge problem.
It's not quite clickbait... it's interesting research.
You should definitely use randomized MAC addresses though.. that helps a lot.
> However, an attackers ability to track a particular target is essentially a matter of luck.
That being said, their proposed solution seems elegant enough:
> a random time-varying extra frequency offset could be added to devices, which would alter the signal frequency periodically and make it difficult for an attacker to distinguish the device's unique signature
This gave me an idea, I scanned for nearby Bluetooth devices while walking in the office. Turns out, there were lots of people in the building each thinking they were alone.
Just for fun, I set up a raspberry pi that constantly track Bluetooth near by and record their mac address. Every time a new device shows up, it pings me. And when they disappear it also tells me.
Everyone has Bluetooth turned on now because of wireless earbuds. You can easily track people like that.
The language in the article is a bit loose. Says 40% of phones are compromised, when they mean 40% of phones may be trackable. This doesn't compromise the phone. It might compromise the owners location.
The a lot of cities in my country already have WiFi access points on almost every street crossroads, making it trivial to implement WiFi MAC tracking surveillance. Apart from that, we also recently received APs on trains and one might argue they are used for statistics of train passengers.
Does anyone know of any proven IRL example of this?
On linux machines you've been able to change ethernet mac addresses for something like two decades. MacOS X has easily accessed MAC address configuration, also been possible for many many years. Ditto for wifi cards.
iOS 14 and above uses a randomized wifi mac address on a network unless you specifically turn it off. iOS 8 or 9 introduced MAC address randomization for broadcast stuff like network probes.
Android 10 does the same (it was available in 9 under dev options.)
For Bluetooth, it sounds like BTLE allows for some forms of mac address randomization that was intended to improve privacy, but it's been defeated: https://9to5mac.com/2019/07/18/bluetooth-flaw/
Bluetooth smart watches, headphones, car audio, sports sensors (heartrate, running gait sensors) have made it completely trivial to track someone's whereabouts. Assume that almost any major retailer has long since associated MAC addresses with a customer profile on you. There's a reason Amazon makes it impossible to use Prime at Whole Foods without your cell phone running the app or having the website up with a live connection; the QR codes are valid for barely a few minutes.
> iOS 14, iPadOS 14, and watchOS 7 introduce a new Wi-Fi privacy feature: When an iPhone, iPad, iPod touch, or Apple Watch connects to a Wi-Fi network, it identifies itself with a unique (random) MAC address per network.
Edit: Upon reading the cited paper, the final sentence in the conclusion states that being able to track a target is "essentially a matter of luck", so that's somewhat relieving.
well not really, all that means is that the surveillance company would need to augment the dataset with other features to get an accurate result. Also, I doubt they actually care about tracking you on a minute to minute basis. Knowing that you went to the pet store with 30% certainty, 4 times this year, is enough to pin you as a pet owner and send you pet-related ads. the same applies for an oppressive government. knowing that you went to a protest 5 times this month, with 30% certainly, is enough for you to get sent to a reeducation camp, or at least send some officers to surveil you and catch you in the act.
They need to be manually re-disabled after each iOS update.
Bonus points for a physical switch to disable all radios (Bluetooth, UWB, Wi-Fi, cellular).
>High-quality wired headphones can create a business incentive for headphone jacks.
Why do you think they removed it? They made it to sell more expensive BT headphones; they made a lot more money after removing the headphone jack. You can't even disable wireless in the control center so why would they want to make a physical switch?
There's some crazy-expensive wired headphones out there, which don't stop anyone from buying pricy BT headphones. If they want to maximize rent-seeking, create a new proprietary wired port.
> why would they want to make a physical switch?
Charge a premium for a new tier of phone? Reclaim some credibility lost from the push for on-device content scanning?
Apple Touch Bars were once inevitable, but are now gone. Touch ID, functional keyboards and Mag Safe have returned. Framework is shipping a well-received laptop with modular ports. GPD Pocket 3 has an HDMI input port which would be welcome on an iPad Pro. Former leaders of the Apple Silicon team are now at Qualcomm-ex-Nuvia and will influence future PC OEM Arm laptop designs. Never say never.
Because they needed BT to work on the new phones. By that logic, the lightning connector are wired headphones you want that already exist.
>Charge a premium for a new tier of phone? Reclaim some credibility lost from the push for on-device content scanning?
Who decides its premium? If people cared, they'd make a bigger deal about the control center not disabling the radios, nobody they are selling to cares. Where is the evidence it will be a selling point or give any credibility against on device scanning? I have never heard anyone who wants a new iPhone care about that, and they have never retracted their iPhone changes. The average person buying an iPhone will care more about the camera megapixels than any of these features.