Brought to you as a public service of the Open Spectrum Foundation (Stichting Open Spectrum), Amsterdam - Prague

openspectrum.info logo

NEWS

Exploiting Bluetooth security holes in passing cars

From "Linux Bluetooth hackers hijack car audio," by John Leyden, The Register, 2 August:

"Linux hackers have demonstrated a way to inject or record audio signals from passing cars running insecure Bluetooth hands-free units. The Trifinite group showed how hackers could eavesdrop on passing motorists using a directional antenna and a Linux Laptop running a tool it has developed called Car Whisperer.

"The software was demonstrated during a Bluetooth Security talk at last week's 'What the Hack' hacker festival in The Netherlands [click here for video of Martin Herfurt's presentation]. Trifinite has developed a specialism in unearthing Bluetooth security shortcomings... Car Whisperer only works because many car manufacturers use standard Bluetooth passkeys such as '0000' or '1234' which are easy to guess. 'This is often is the only authentication that is needed to connect,' according to Trifinite.

"Once connected hackers can interact with other drivers or even eavesdrop conversations from inside other cars by accessing the microphone. And that's just for starters. 'Since the attacker's laptop is fully trusted once it has a valid link key, the laptop could be used in order to access all the services offered on the hands-free unit. Often, phone books are stored in these units. I am quite certain that there will be more issues with the security of these systems due to the use of standard pass keys,' Trifinite notes..."

[Bluetooth - posted 3 August 2005]

Click here for the LATEST HEADLINES

Recent News...

Mesh booming before WiMAX (2 August)

Bluetooth gives Qataris' social life new dimension (1 August)

Anti-theft RFID clothing (31 July)

208 km: new distance record for unamplified Wi-Fi (31 July)

World's first Wi-Fi internet "radio"? (29 July)

SpymodeX 900-2500 MHz "Professional video camera/bluetooth/WiFi jammer" (27 July)

FCC may create spectrum bureau (27 July)

UK man found guilty of "piggybacking" on Wi-Fi connection (24 July)

"Analysts: The future of cell phones will be Wi-Fi" (22 July)

Hitachi Develops Electronic Paper with WLAN Capability for Signboards (22 July)

British union calls for EU ban on staff-tracking RFID (21 July)

Industry divided over Bluetooth marketing (21 July)

New group in US Congress for unlicensed use of band freed by DTV (20 July)

RFID prevents infant abduction from hospital (20 July)

Open-source SDR development platform released: CalRadio 1.0 (20 July)

IEEE mesh standard still years away (19 July)

"Could broad anti-RFID laws cause problems?" (18 July)

Popular Science: Be Your Own Hot-Spot (18 July)

"Will RFID-guided robots rule the world?" (18 July)

Motorola promotes mesh in wake of London bombings (17 July)

Israel: protests may lead to gov't action on antennas (17 July)

Wireless Technologies for Development in Latin America: new portal (16 July)

EC tells members to authorise 5GHz WLANs (16 July)

Commercial UWB soon in China? (16 July)

One-chip "software-defined radio" demoed in South Korea (15 July)

"Opinion: 'Stealing' Wi-Fi is No Crime" (15 July)

RFID - "Mark of the Beast"? (15 July)

Falling prices encourage "dense deployments" (13 July)

"Boingo, Skype Team for Wireless VoIP" (12 July)

Netherlands: health fears hinder 3G roll-out (12 July)

New vacuum tube technology = cheaper radio nets (12 July)

Newsweek: "How Telcos, Cable Kill Low-Cost Wi-Fi" (11 July)

802.11n: WLANs to 600 Mbit/s (8 July)

Software Radios and unlicensed spectrum (7 July)

Wi-Fi positioning comes to football (7 July)

World Bank memo on spectrum reform (6 July)

New book: RFID - Applications, Security, and Privacy (6 July)

EC consultation on "Wireless Access Platforms for Electronic Communications Services" (4 July)

xMax: UWB variant claims longer range at much lower power (4 July)

De-license WiMax, Indian ISPs tell regulator (4 July)

Armenian cities hotspotted just months after de-licensing (4 July)

CFP: IEEE Communications Magazine issue on "Open Wireless Architectures and Convergence" (24 June)

China's WLAN market "heating up" (24 June)

WPS: new location service uses Wi-Fi database (21 June)

Visit our News Archive for additional stories.

To receive the openspectrum.info newsfeed by email, enter your email address:

(Email subscriptions managed by FeedBurner)