Nov 22, 2009

Bluetooth : Primer & Security Issues

free web hosting
Open Discussion & Free Web Hosting > Computers & Tech > Networking

Bluetooth : Primer & Security Issues

sparx
QUOTE
Initially touted as the technology that would finally free us from the horrors of multiple tangled cables and cords, Bluetooth didn’t catch on as quickly as expected. Until recently, there just weren’t that many useful (with the emphasis on “useful”) Bluetooth devices available – at least, not for desktop computing. Users of handheld computers (such as my Palm Zire 72) adopted the technology more quickly, as it allowed us to easily attach portable keyboards, headsets, printers, etc. to our portable devices Bluetooth-enabled cell phones allow me to connect my PDA to the Internet through them.

Bluetooth was designed to be the basis of the Personal Area Network (PAN) – a way for devices within relatively close proximity to communicate wirelessly with one another. The range for Bluetooth transmissions varies from about 1 meter up to 100 meters, depending on the power class of the device. Thus, the most powerful (Class 1) can communicate over a distance of more than 300 feet, similar to a typical wi-fi network.

Like 802.11b and g, Bluetooth transmits over the 2.4 GHz radio frequency. Its speed is limited to about 1 Mbps (far slower than wi-fi, but still roughly equivalent to a typical broadband Internet connection). It uses LMP (Link Manager Protocol) to handle the connections between devices.

Bluetooth Security Issues

Bluetooth can operate in one of three security models:

Mode 1 is non security.
Mode 2 provides security at the service level, after the channel is established.
Mode 3 provides security at the link level, before the channel is established.
Each Bluetooth device has a unique 48-bit device address. The authentication scheme is challenge-response, using symmetric keys, and encryption is done with a key that can be up to 128 bits (negotiated by the communicating devices, with each device having a maximum key length defined). A 128 bit random link key handles security transactions between two or more devices.

When two Bluetooth devices establish a communications channel, they both create an initialization key. A passkey or Personal Identification Number is input and the inititalization key is created, and the link key is calculated using it. Then the link key is used for authentication.

The first security concern is the passkey or PIN. As with any key, long keys are more secure than short ones. If a hacker is able to discover the passkey, he can calculate possible initiation keys, and then from that, calculate the link key. Making the passkey long will make it much harder to accomplish the first step.

The initial key exchange takes place over an unencrypted link, so it is especially vulnerable. It’s best if this part of the BT device pairing process takes place in a more physically secure location (that is, where there are not likely to be any lurkers with BT devices who could intercept the communications). A hacker could record transmissions sent over the BT frequency and use them to recreate the PIN.

Rather than using the same fixed passkey all the time, it should be changed frequently


Why Does Bluetooth Security Matter?

Many Bluetooth users only use the technology to connect a wireless headset or similar device to their portable computers, and they may wonder why security is a big deal. Implementing security, even for these types of device pairings, can prevent an unauthorized user from using the headset.

However, another use of Bluetooth is to create a temporary computer network. For example, several people in a meeting room can connect their Bluetooth-enabled laptops to each other to share files during the meeting.

When you use Bluetooth to create a temporary network, it is usually an ad hoc network; that is, computers communicate directly with each other rather than going through a wireless access point (WAP). This means you have no centralized point of security control, as you do with a WAP (for example, you can configure a WAP to use MAC address filtering and other built-in security mechanisms). Thus, security becomes a major concern because you can be exposing important data stored on your laptop to others on the Bluetooth network. Remember that the range for class 1 Bluetooth devices can be more than 300 feet – far enough so that in some locations, the BT equivalent of the wi-fi “war driver” may be able to establish a link with your computer even though not within your sight.

Another special concern is the security of Bluetooth mobile phones. These phones may have information stored on them such as the addresses and phone numbers of contacts, calendar information and other PDA-type data. Hacking into these phones using Bluetooth is called bluesnarfing. Newer mobile phones and software upgrades for older phones can patch this vulnerability.

A related hacking technique is called bluebugging, and it involves accessing the phone’s commands so that the hacker can actually make phone calls, add or delete contact info, or eavesdrop on the phone owner’s conversations. This vulnerability, too, is being addressed by phone manufacturers. Thus, if you own a BT-enabled phone, it’s important to keep the software updated or upgrade to the latest phone models frequently.

Bluetooth devices can also be targets of Denial of Service (DoS) attacks, typically by bombarding the device with requests to the point that it causes the battery to degrade.

Finally, there are “cell phone worms” such as Cabir that can use the Bluetooth technology to propagate to other BT devices. Cabir targets phones that use the Symbian OS.

The relatively short range of most Bluetooth devices helps to ameliorate the risk of most of these security issues. For example, to practice bluesnarfing or bluebugging against a BT phone, the hacker would typically need to be within about 10 meters (a little less than 33 feet) of the target phone.


In conclusion, keep Bluetooth on only when required and that too preferably when you're in a decently secure area (which again is extemely relative). Use longer passkeys when pairing devices and upgrade if a security alert is issued by the manufacturer of your device.

 

 

 


Comment/Reply (w/o sign-up)

spacewaste
http://64.233.161.104/search?q=cache:nuULQ...lient=firefox-a

Don't tempt the gods mate...

It was a good little summary, and you did change a few things...But alot is still just copy pasted.

I warned you for now, and I have disabled your posting abilities for 12hours...But I will give them back to you in hopes that you've learnt a lesson smile.gif.

Alternate the post to take into consideration of the copy/pasting (Use quotes).

On the topic of the article...Good work, I've really been looking into getting a bluetooth device...
Maybe you should talk about PSP's usage on it smile.gif

 

 

 


Comment/Reply (w/o sign-up)

sparx
Apologies, old chap!

I was in a bit of a hurry and wanted to improve my credit ratings. Still an informative piece none-the-less.

Credit for the piece goes to Debra Shinder from www.windowssecurity.com

Comment/Reply (w/o sign-up)

spacewaste
QUOTE (sparx @ Aug 22 2005, 03:50 AM)
Apologies, old chap!

I was in a bit of a hurry and wanted to improve my credit ratings. Still an informative piece none-the-less.

Credit for the piece goes to Debra Shinder from www.windowssecurity.com
*


Notice from SpaceWaste:

No need to double post, just edit your original wink.gif.

Since you are a first time offender, and had a very calm reaction, I will let you off with a warning...But next time I might not be so nice...OR the other mods wink.gif.

Comment/Reply (w/o sign-up)


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Similar Topics

Keywords : bluetooth, primer, and, security, issues

  1. Connect Sony W810i To Laptop Via Bluetooth
    how to connect sony w810i to laptop via bluetooth (2)
  2. Issues With Accessing The Internet
    web addresses vs. ip addresses (11)
    My ISP is quite special. I have a cable 512k connection from them, but it's shared between 10
    users and in addition they won't troubleshoot it for me if i have more than one computer
    connected. No wonder the IT infrastructure is 4th rate here. Anyways, my problem is that I
    can't open any web page whatsoever. It just returns a page not found. But if i type in the IP
    address, the page loads fine. This is something I don't understand much about, and I'm not
    getting any help from my service provider for the above mentioned reasons. Is this a software pro....
  3. Having Network Card Issues On A Dual Boot Laptop
    (4)
    I have just installed a dual boot setup with Windows XP Professional SP2 and Ubuntu 7.04 on a DELL
    Inspiron 1501. While I did the installation no cable was plugged into the NIC. After plugging a
    network cable into the NIC I'm having the problem that Ubuntu recognizes and can work with the
    NIC without any problems, but in Windows XP I can't get the LAN connection to show up in Network
    Connections. So I have therefore narrowed down the problem as not being on the hardware side. I
    tried running the Add Hardware wizard with the installation CD inside and instructed ....
  4. [info] Security
    (4)
    Hi i was watching a program on T.V it was on channel 5 and it was like a crimewatch program and it
    had a bit on computers so here is some of it that i remember. Basically it was about security on
    routers so if you havent got a router then no point in reading this so here goes people can hack in
    to your network on a WEP code on certain program that they have got and they can get stuff like:
    What site you were on, Passwords, Personal infomation like Banks etc So when the professional
    security advisor came on he said that the best way of trying to stop this is to insert ....
  5. Streaming Audio Via Bluetooth™
    Desktop to Cell Phone (5)
    Its a world of wireless connectivity, and a hoard of I/O devices to choose from! And all of it
    applies to music needs! When it comes to listening to songz all day, I'd prefer the headphones,
    rather than the sound-system making the society aware of it just for the bass! Now there's an
    online radio station that I'd like to listen to all day ~ but I'm roaming around my place
    all day - you know its not possible to be in the same room forever! But I'd like to have it
    uninterrupted! So instead of using the sound system on my PC, I'd use the headpho....
  6. Best Free Software Security
    (10)
    Hey guys, Over the years i have gone through paid and free security software, yet i could never
    satisfy myself with certain elemts of a particular program. Thats why my master system uses linux.
    Over the years i have found that the best software is sometimes free. Its not bundled and does not
    use lots of system resources. Some of my favorites include Comod Personal Firewall, AVG Free,
    Ad-Aware SE Personal and Spyware Blaster. Do you agree that the following solutions can provide
    better protection then Norton or McAfree? Or do u guys use something basic. Remember that the....
  7. Disable NetBios (Windows) And Increase Security
    Increase your computer security (4)
    Disable NetBIOS Increase your security If NetBIOS is enabled Your Files and Folders , Work
    Group-name , Computer name , Loging- name will be shared in Internet in Windows 2000 1- open
    Windows Explorer 2- Right click on My Network places and select properties 3- Click Internet
    protocol TCP/IP and select properties 4- Click on Advanced and then WINS 5- Select Disable NetBIOS
    over TCP/IP and click ok 6- Restart your computer If Windows displays “This connection has an empty
    … " message, ignore it and click ok In Windows 95/98/ME 1- open Windows Explorer 2- ....
  8. Wan Security Question
    Question about WAN/Local security. (1)
    I have a question to ask about WAN/Local security. There is a WAN I am registered on that has a
    server (maybe more than one, or one with multiple partitions or something, I don't know) hosting
    files that are to be accessed in the following ways: one drive contains your personal files and only
    you should be able to access them and another contains read-only communal files. This works fine,
    but the problem is that to access any of these drives, the local username and password are an
    administrator login, meaning that any user can access Control Panel etc. There is no p....
  9. Help With Bluetooth,infrared
    (3)
    Hello guys I need to know wot exactly is bluetooth My father has it but doesnt know wot it is. I
    tried connecting my comp to my Nokia 8210 ifrared ports.But it didnt work .It never detected
    anything. /mellow.gif" style="vertical-align:middle" emoid=":mellow:" border="0" alt="mellow.gif"
    /> btw wots LAN and PAN? Wots wireless LAN? Is bluetooth used to share files?If so Whats the
    speed? Besides in my Computer When ever it boots up a 'Add New Hardware' keeps poping up
    even when i havent put any new device.What should i do to dsolve it?It gets very annoying! ....
  10. Wireless Security
    (10)
    Right now my home network is really simple, mainly because I have just one computer. I have it
    plugged into the cable modem with ethernet, and that's it. However, in a month I'm getting
    married. My fiancee has her own computer so I'm going to have to upgrade my network to get her
    on. I thought about just getting a traditional router, but since a wireless one is only $10 more
    I'll probably get a wireless one. I'll still connect our two desktops with cable since they
    will be in the same room. I have a PDA I'll use wirelessly and I may be gett....
  11. Windows Security
    security (20)
    Windows XP iis not secure in internet nowadays. I would like you to tell me the reasons for that.....

    1. Looking for bluetooth, primer, and, security, issues

See Also,

*SIMILAR VIDEOS*
Searching Video's for bluetooth, primer, and, security, issues
advertisement



Bluetooth : Primer & Security Issues

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com