I recalled reading about this at the beginning of this month, I haven’t seen any updates on a fix or anything. Figured I’d ponder it with you folks over here.

I have since stopped using most of my Bluetooth devices as a precaution. How real of a threat is this vulnerability? Thanks and sorry if this kind of post is in the wrong spot.

  • Square Singer@feddit.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 months ago

    Always know your threat scenarios. Depending on your threat scenario, pretty much anything could be a danger or completely harmless.

    Bluetooth is a comparatively low-risk interface, since you hardly ever send anything really confidential over it, and since it’s decentralized (only locallized communication), so an attacker needs to be within close range during the attack.

    So what’s the worst an attacker could do with Bluetooth? They could sniff the packages (mostly the audio that’s being sent over Bluetooth or mouse clicks and keystrokes if you use a Bluetooth mouse or keyboard) or they could inject the same, e.g. to fake-type something on your devices.

    So in reality, there’s nothing special sent over Bluetooth (except maybe contact infos if you actively decide to share them with a Bluetooth device) and the attacker needs to stay within a few meters during the whole attack.

    In almost all scenarios, even a completely unencrypted Bluetooth connection will only cause very limited potential trouble.