arXiv · 2108.07190
Happy MitM: Fun and Toys in Every Bluetooth Device
Abstract
Bluetooth pairing establishes trust on first use between two devices by creating a shared key. Similar to certificate warnings in TLS, the Bluetooth specification requires warning users upon issues with this key, because this can indicate ongoing Machine-in-the-Middle (MitM) attacks. This paper uncovers that none of the major Bluetooth stacks warns users, which violates the specification. Clear warnings would protect users from recently published and potential future security issues in Bluetooth authentication and encryption.
Explore related subjects
Keep this discovery
Jiska Classen, Matthias Hollick. 2021-08-16. Happy MitM: Fun and Toys in Every Bluetooth Device. https://doi.org/10.1145/3448300.3467822
Cite the original work for its findings. Save a collection to share your selection of sources.