Millions of devices are affected by the Bluetooth gap



[ad_1]
<div innerhtml = "

An error in Bluetooth protocol implementation allows hackers to plug two devices and read or manipulate data, reports Heise, including
Apple
Broadcom Intel and Qualcomm . The mistake that Israeli security researchers have found lies in the matching mechanism in which a cryptographic key is exchanged. By negligence implementation the requirements for secure exchange are not sufficiently discussed with the manufacturers concerned.

Complicated Attacks

This can exploit attackers and indulge in man-in-the-middle attacks in the Connect the connection. But this only works if both connection partners are affected by the vulnerability. The attacker must also be within range of the Bluetooth connection and attack during
Twinning
happens to happen. Pairing is only necessary when connecting two devices for the first time. Driver Updates May Solve the Problem for Concerned Manufacturers

Apple has already done so with MacOS High Sierra 10.13.5, iOS 11.4 updates, watchOS 4.3.1 and tvOS 11.4,
Intel
also offers patch drivers for Windows and Linux and has released a new driver for Chrome OS on Google . The group of special interest of the Bluetooth consortium responded and adapted the specifications of the implementation .

">

An error in the implementation of the Bluetooth protocol allows attackers to plug two devices and read data or manipulate, Heise reports. There are several manufacturers, including
Apple
Broadcom Intel and Qualcomm . The mistake that Israeli security researchers have found lies in the matching mechanism in which a cryptographic key is exchanged. By negligence implementation the requirements for secure exchange are not sufficiently discussed with the manufacturers concerned.

Complicated Attacks

This can exploit attackers and indulge in man-in-the-middle attacks in the Connect the connection. But this only works if both connection partners are affected by the vulnerability. The attacker must also be within range of the Bluetooth connection and attack during
Twinning
happens to happen. Pairing is only necessary when connecting two devices for the first time. Driver Updates May Solve the Problem for Concerned Manufacturers

Apple has already done so with MacOS High Sierra 10.13.5, iOS 11.4 updates, watchOS 4.3.1 and tvOS 11.4,
Intel
also offers patch drivers for Windows and Linux and has released a new driver for Chrome OS on Google . The group of special interest of the Bluetooth consortium responded and adapted the specifications of the implementation . Now, it's exactly defined how the crypto handshake should be checked.

[ad_2]
Source link