November 13, 2003

Serious flaws in bluetooth security lead to disclosure of personal data

There was a post on bugtraq that included a paper on some serious flaws in bluetooth's authentication and/or data transfer mechanisms.

Firstly, confidential data can be obtained, anonymously, and without the owner's knowledge or consent, from some bluetooth enabled mobile phones. This data includes, at least, the entire phonebook and calendar.

Secondly, it has been found that the complete memory contents of some mobile phones can be accessed by a previously trusted ("paired") device that has since been removed from the trusted list. This data includes not only the phonebook and calendar, but media files such as pictures and text messages. In essence, the entire device can be "backed up" to an attacker's own system.

If you have a device using bluetooth, you might want to look into this!

Posted by SilverStr at November 13, 2003 01:48 AM | TrackBack