Comment on Are BLUFFS attacks still a vulnerability to the average Bluetooth user?

BearOfaTime@lemm.ee ⁨1⁩ ⁨year⁩ ago

Well, since I’ve not seen any updates to the BT stack, I’d go with yes.

Stopping using BT seems a bit extreme. What’s your risk?

I only use BT for listening to music/podcasts. I never allow BT connections to have access to contacts, messages, etc. So the only risk (contacts/messages) is pretty well mitigated.

And IIRC, BLUFFS is a MITM risk (existing connection can be spoofed because of how a key is managed), so only connect to devices you control, don’t allow random connections, leave BT off as much as is reasonable, and perhaps delete/recreate connections occasionally (I think the key gets regenerated on a new connection?).

The most someone would get from my BT is listening to my podcasts.

source
Sort:hotnewtop