Bluetooth security 'crisis' looming

Class 1 standard easy for hackers to exploit, says security firm

Written by Robert Jaques

Security experts have warned of the need to take care as new Bluetooth devices with a transmission range of up to 100 metres arrive.

Security consultant @stake believes that devices conforming to the latest Bluetooth standard represent a potential crisis similar to the introduction of wireless local area networks based on the 802.11b Wi-Fi standard.

The firm expects that Class 1 Bluetooth will appear on everything from laptops to mobile phones, allowing hackers to gain access to sensitive information.

Ollie Whitehouse, director of security architecture at @stake, said in a statement: "With this class of device, wireless transmission of information leaves the office environment and travels anywhere an employee does.

"This means that third parties can access information without penetrating the physical security of an office or dealing with the problems of circumventing existing network security.

"The onus really is on vendors to ensure that all devices are optimised for security before they are put in the hands of customers."

In a recent white paper, @stake warned that even non-discoverable devices still respond to direct name and service enquiries and are therefore open to detection and attack.

Other common problems identified include Windows 2000 hosts configured to connect to all Bluetooth devices, and Windows registries that retain details of all devices to which they have been connected.

Another potentially serious problem centres on mobile phones that retain pairing information details when Sim cards are swapped.

This means that a third party that has access to a phone for even a few minutes can place a bond on it and use it as a platform for future attacks.

"The very real risks of Bluetooth will only multiply as adoption increases and the drivers vary from their default configurations," said Whitehouse.

"Many vendors release Bluetooth products with a best effort approach to security that can only compromise the integrity of the information held on those devices.

"Vendors should understand these issues and risks and develop mechanisms for delivering security out of the box. While it is not a time to panic, it is certainly a time to act."

Tags:

Further reading

No wireless at Westminster, MPs told

Threat of 'bluesnarfing' attacks prompts wireless ban until security can be guaranteed   More...

Wireless gaming set for mass market

Lara Croft in hot phone action   More...

2004 is crunch time for wireless data

Content and apps developers face make or break year, warns analyst   More...

Happy new year in store for wireless

Developers set to cash in on expanded market, predicts analyst   More...

Related articles

High-speed Bluetooth integrates Wi-Fi

Technology promises large multimedia file transfers in a jiffy   More...

Bluetooth and Wi-Fi go their separate ways

Market developments pushing technologies in different directions   More...

802.11n Wi-Fi heads for the big time

But security worries will still slow roll outs   More...

HTC adds GPS to latest Touch smartphone

Touch Cruise features HSDPA 3.5G, Wi-Fi and Bluetooth   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement