Bluetooth pairing establishes trust on first use between two devices by creating a shared key. Similar to certificate warnings in TLS, the Bluetooth specification requires warning users upon issues with this key, because this can indicate ongoing Machine-in-the-Middle (MitM) attacks. This paper uncovers that none of the major Bluetooth stacks warns users, which violates the specification. Clear warnings would protect users from recently published and potential future security issues in Bluetooth authentication and encryption.
翻译:蓝牙配对通过创建共享密钥来建立对两个设备首次使用的信任。 与 TLS 中的证书警告类似, 蓝牙规格要求提醒用户注意此密钥的问题, 因为这可以显示正在发生的中程机器( MitM) 攻击。 本文揭示出, 主要的蓝牙堆叠都没有警告用户, 这违反了该密钥的规格。 清晰的警告可以保护用户免受最近公布的、 以及蓝牙认证和加密中可能的未来安全问题的影响 。