How can Bluetooth services and devices be effectively secured?

Computer Fraud & Security · 2006

The fashionable and easy to use Bluetooth standard means that mobile phones, PDAs and laptops can all communicate with gadgets within 10 metres. Security managers need to be wary of snoopers tapping into their organization's data through Bluetooth. A host of hacking tools have sprung up on the Internet to take advantage of the wide use of Bluetooth. Weak spots in the protocol's inbuilt security can leave devices susceptible to impersonation, spoofing and brute force attacks. The risk is compounded as the default security configuration on most devices doesn't have security switched on. Simple steps like ensuring that devices are set to undiscoverable mode will stop spies and opportunists from getting their hands on corporate secrets. Losing devices is also bad news because there is no user authentication within Bluetooth specifications only device authentication. In addition, the lack of integrity checking on Bluetooth packets means that Man-in-the-middle and packet modification attacks are hard to stop. Certain basic security measures should be taken in order to reduce the impact caused by the inherent flaws in the standard. Simple steps to stop the security blues slipping in through Bluetooth Insight Consulting Bluetooth is a convenient and dynamic technology but can be easily compromised with serious conseqences. Laptop thefts have been widespead recently where thieves are using Bluetooth scanning to seek out and steal laptops.

Read the paper · More papers on PaperTik