Expert Articles
Bluetooth, We Have A Problem
Reported by bastille.net
By Bob Baxley, CTO at Bastille Networks
We love our Bluetooth devices. We use them at home, on the go, and in the office. But despite revolutionizing hands-free communications and offering a new level of productivity and comfort, Bluetooth has a history of vulnerabilities and subsequent attacks that continues to cause major security risks for organizations. The vulnerabilities allow malicious hackers to do everything from read encrypted conversations, disable and/or deadlock devices, and even remotely take over devices.
Most recently in 2020, a team of international security researchers from announced the discovery of a new Bluetooth vulnerability with the potential to expose billions of devices to hackers. Dubbed Bluetooth Impersonation AttackS (BIAS), hackers can create an authenticated Bluetooth connection between two paired devices without needing a key. The attacker is able to take over communication between the two devices by impersonating either end such as a keyboard or a mouse, giving the intruder inside access to the targeted device. Once inside, the impersonating attacker can then carry out various exploits such as stealing or corrupting data.
While the BIAS vulnerability introduced a new attack vector for hackers, it definitely won’t be the last. There have been numerous high-profile Bluetooth vulnerability discoveries in recent years and the sophistication of the attacks continues to evolve. Of particular concern is that Bluetooth hackers no longer need to be in the physical proximity of the devices to carry out their exploits. Bluetooth was designed for short-range communications, but because they contain radios, an attacker may be able to exploit a system remotely and then leverage that system’s Bluetooth interface to actuate an attack. In this way, it is possible for an attacker to run these exploits remotely from the parking lot or much further away using low-cost equipment.
As a result of attackers’ ability to bypass firewalls and physical perimeters and instead conduct attacks remotely by radio, the growing threat from Bluetooth devices to network security is top of mind for security professionals. In addition to BIAS, here are some other recent vulnerability discoveries that organizations have had to address.
The above examples are just a sampling of vulnerabilities. The fact of the matter is that Bluetooth, like all software, will likely never contain zero vulnerabilities. So how can companies protect themselves from falling victim to present and future Bluetooth attacks? Bluetooth devices are getting smaller and smaller and preventing radio-enabled gadgets from entering secure facilities is getting more complicated. As a result, an organization needs to have complete visibility to identify and understand what devices are in their facilities and infrastructure. From there is it paramount to remove unnecessary devices, components and interfaces, and to stay vigilant and continuously patch vulnerable devices and components.
