New Bluetooth Low Energy flaw puts millions of connected devices at risk

hackers can unlock your phone, smart locks and even your car by exploiting this vulnerability

(Image credit: Sebastian Scholz (Nuki)/Unsplash)

A new vulnerability in the Bluetooth Low Energy (BLE) protocol has been discovered that can be exploited by an attacker to remotely gain access to mobile phones, smart watches, laptops, smart locks, cars and more.

The flaw itself was discovered by the NCC Group, which successfully exploited it to conduct the world’s first link layer relay attack. The firm created a relay attack tool for devices communicating over BLE and used it to unlock and even drive a Tesla Model 3 when its key fob was out of range.

The reason this vulnerability is cause for concern is due to how Bluetooth proximity authentication mechanisms (that are used to unlock devices within a certain range) can be easily broken using cheap off-the-shelf hardware. In fact, an attacker doesn’t even need to know how to code to exploit it as they can use a Bluetooth developer board and ready-made programs to do so.

Principal security consultant and researcher at the NCC Group, Sultan Qasim Khan provided further insight on the research he conducted into this new BLE vulnerability and how it can even bypass encryption in a press release, saying:

“What makes this powerful is not only that we can convince a Bluetooth device that we are near it—even from hundreds of miles away—but that we can do it even when the vendor has taken defensive mitigations like encryption and latency bounding to theoretically protect these communications from attackers at a distance. All it takes is 10 seconds—and these exploits can be repeated endlessly. This research circumvents typical countermeasures against remote adversarial vehicle unlocking, and changes the way engineers and consumers alike need to think about the security of Bluetooth Low Energy communications.”

A huge potential attack surface

As Bluetooth Low Energy has become increasingly common in both consumer and business devices, the potential attack surface for this vulnerability is massive.

In addition to the Tesla Model 3 and Y, other cars with automotive keyless entry are also vulnerable and an attacker could leverage this flaw to unlock, start and drive someone else’s vehicle. At the same time, laptops with a Bluetooth proximity unlock feature enabled are affected as well as smartphones.

Even your own home could be broken into if you’ve upgraded from a traditional lock to a smart lock. In fact, the NCC Group successfully exploited smart locks from Kwikset/Weiser Kevo and already disclosed this information to the company. Likewise, access control systems used in both enterprise and small businesses can be unlocked and an attacker could enter a company’s office pretending to be an employee.

hackers can unlock your phone, smart locks and even your car by exploiting this vulnerability

(Image credit: BublikHaus/Shutterstock)

Not intended for critical systems

Originally developed by Nokia back in 2006 as Wibree, Bluetooth Low Energy was originally intended to provide reduced power consumption and cost with a similar range to that of existing Bluetooth devices. For instance, headphones with BLE could last longer without needing to be recharged.

As the NCC Group points out though, BLE-based proximity authentication was not originally designed to be used in critical systems such as locking mechanisms in cars or smart locks.

Unfortunately, this new vulnerability isn’t a traditional bug that can be fixed with a software patch nor an error in the Bluetooth specification itself.

Protecting yourself from attacks on devices with BLE

In order to protect yourself from attackers leveraging this flaw in the wild, the NCC Group recommends that you disable passive unlock functionality on your devices as well as turn off their Bluetooth functionality when it’s not needed.

Meanwhile, manufacturers can reduce the risk to their products by disabling key functionality when a user’s phone or key fob has been stationary for some time by using data from its accelerometer. System makers should also provide their customers with the option to add a second factor for authentication or user presence attestation where you need to to tap an unlock button in an app on the phone being used as a key fob for cars with BLE support.

Tom’s Guide reached out to the Bluetooth Special Interest Group (SIG) that oversees the development of Bluetooth standards which provided the following statement on the matter:

“The Bluetooth Special Interest Group (SIG) prioritizes security and Bluetooth specifications include a collection of features that provide developers the tools they need to secure communications between Bluetooth devices and implement the appropriate level of security for their products. All Bluetooth specifications are subject to security reviews during the development process.

In addition, Bluetooth technology is an open, global standard, and the Bluetooth SIG encourages active review of the specifications by the security research community. The SIG also provides educational resources to the developer community to help them implement the appropriate level of security within their Bluetooth products, as well as a vulnerability response program that works with the security research community to address vulnerabilities identified within Bluetooth specifications in a responsible manner. The Bluetooth LE Security Study Guide and Bluetooth Security and Privacy Best Practices Guide are designed to help developers make the appropriate security choices for their Bluetooth enabled products and solutions.”

Now that the NCC Group has successfully carried out a link layer relay attack on BLE, automakers and device makers will likely begin coming up with ways to protect their products from this novel new attack type. In the meantime though, you should probably disable Bluetooth when you’re not using it to protect your devices from any potential attacks leveraging this vulnerability.

Keyword: Hackers can unlock your phone, smart locks and even your car by exploiting this vulnerability

CAR'S NEWS RELATED

Nissan, Researchers Working To End Traffic Jams With Smart Highways

Using specially equipped 100 Nissan Rogues, the experiment was done on an open road.

View more: Nissan, Researchers Working To End Traffic Jams With Smart Highways

Everything you need to know about the Smart ForFour

Is the smart forfour a good car?  Who is the smart forfour a good car for? Is the smart forfour a good first car? Is the smart forfour a good family car? Is there a Hybrid smart forfour? What’s it like to drive?  Reviewer’s opinion What does it look ...

View more: Everything you need to know about the Smart ForFour

Elon Musk to make alternative smartphone if Apple or Google bans Twitter

The idea of an Elon Musk-led company creating a smartphone has caught the imagination of many over the years, so much so that some YouTube channels continue to peddle the alleged release of products like the “Tesla Pi Phone” that’s supposedly poised to compete with Apple’s iPhone and other ...

View more: Elon Musk to make alternative smartphone if Apple or Google bans Twitter

Grab the all-new Insignia 32-inch Smart TV for under $100 for Black Friday

Autoblog may receive a share from purchases made via links on this page. Pricing and availability are subject to change. If a Fire Stick is just one step too far down the road of “extra devices I definitely don’t need,” but you’re still looking to get into the smart ...

View more: Grab the all-new Insignia 32-inch Smart TV for under $100 for Black Friday

Geely is making a clone of the smart#1

Geely making a smart move by making a Zeekr EV that's exactly like the smart#1? Looks like the smart#1 will have some family rivalry soon as carnewschina.com has spotted the new Zeekr compact EV SUV, which looks to be the same size as the smart#1. Codenamed BX1E, the EV apparently ...

View more: Geely is making a clone of the smart#1

Grizzl-E Smart Commercial Bundle Offers Charging Solutions For Condo And Apartment Dwellers

Over 70 million Americans live in condominiums, rental apartments and other multi-resident homes with shared parking.

View more: Grizzl-E Smart Commercial Bundle Offers Charging Solutions For Condo And Apartment Dwellers

The New Smart #1 Happens To Be Surprisingly Safe: Euro NCAP Results

The Smart #1 gets not only 5 stars overall, but also 96% for Adult Occupant protection.

View more: The New Smart #1 Happens To Be Surprisingly Safe: Euro NCAP Results

First images revealed of the Smart #3

A registration application in China has revealed the first pictures and data on the second model of the Smart brand. Next to a modified body, the model will also have an all-wheel drive with a second electric motor, and at least one more battery option. The second model after ...

View more: First images revealed of the Smart #3

Smart #3 leaked in China, the electric coupe-SUV that will likely arrive in Malaysia

Smart rolls out a slightly larger electric SUV

New 2023 Smart #3 SUV leaked in Chinese homologation filings

Smart #1 scores 5-star Euro NCAP rating – Malaysia-launch in Q4 2023

Terowong SMART berfungsi Baik – Hujan lebat 6 jam, tiada banjir

2022 Honda Civic RS e:HEV hybrid launched in Malaysia; priced from RM 167k, 315 Nm, Smart Key

What New Smart Technology Does the 2023 Honda Pilot SUV Offer?

Can smart charging technology help to alleviate EV grid demand?

Lug+Carrie introduces smart journey app to make electric cycling safer for ‘mums and dads’

Smart Money in 1988 Invested in a Mercury Topaz

This Bugatti smartwatch feels like someone’s missed the point

IIHS: Smartphone apps drive gig workers, parents to distraction

OTHER CAR NEWS

; Top List in the World https://www.pinterest.com/newstopcar/pins/
Top Best Sushi Restaurants in SeoulTop Best Caribbean HoneymoonsTop Most Beautiful Islands in PeruTop Best Outdoor Grill BrandsTop Best Global Seafood RestaurantsTop Foods to Boost Your Immune SystemTop Best Foods to Fight HemorrhoidsTop Foods That Pack More Potassium Than a BananaTop Best Healthy Foods to Gain Weight FastTop Best Cosmetic Brands in the U.STop Best Destinations for Food Lovers in EuropeTop Best Foods High in Vitamin ATop Best Foods to Lower Your Blood SugarTop Best Things to Do in LouisianaTop Best Cities to Visit in New YorkTop Best Makeup Addresses In PennsylvaniaTop Reasons to Visit NorwayTop Most Beautiful Islands In The WorldTop Best Law Universities in the WorldTop Richest Sportsmen In The WorldTop Biggest Aquariums In The WorldTop Best Peruvian Restaurants In MiamiTop Best Road Trips From MiamiTop Best Places to Visit in MarylandTop Best Places to Visit in North CarolinaTop Best Electric Cars For KidsTop Best Swedish Brands in The USTop Best Skincare Brands in AmericaTop Best American Lipstick BrandsTop Michelin-starred Restaurants in MiamiTop Best Secluded Getaways From MiamiTop Best Things To Do On A Rainy Day In MiamiTop Most Instagrammable Places In MiamiTop Interesting Facts about FlorenceTop Facts About The First Roman Emperor - AugustusTop Best Japanese FoodsTop Most Beautiful Historical Sites in IsraelTop Best Places To Visit In Holy SeeTop Best Hawaiian IslandsTop Reasons to Visit PortugalTop Best Hotels In L.A. With Free Wi-FiTop Best Scenic Drives in MiamiTop Best Vegan Restaurants in BerlinTop Most Interesting Attractions In WalesTop Health Benefits of a Vegan DietTop Best Thai Restaurant in Las VegasTop Most Beautiful Forests in SwitzerlandTop Best Global Universities in GermanyTop Most Beautiful Lakes in GuyanaTop Best Things To Do in IdahoTop Things to Know Before Traveling to North MacedoniaTop Best German Sunglasses BrandsTop Highest Mountains In FranceTop Biggest Hydroelectric Plants in AmericaTop Best Spa Hotels in NYCTop The World's Scariest BridgeTop Largest Hotels In AmericaTop Most Famous Festivals in JordanTop Best European Restaurants in MunichTop Best Japanese Hiking Boot BrandsTop Best Universities in PolandTop Best Tips for Surfing the Web Safely and AnonymouslyTop Most Valuable Football Clubs in EuropeTop Highest Mountains In ColombiaTop Real-Life Characters of Texas RisingTop Best Beaches in GuatelamaTop Things About DR Congo You Should KnowTop Best Korean Reality & Variety ShowsTop Best RockstarsTop Most Beautiful Waterfalls in GermanyTop Best Fountain Pen Ink BrandsTop Best European Restaurants in ChicagoTop Best Fighter Jets in the WorldTop Best Three-Wheel MotorcyclesTop Most Beautiful Lakes in ManitobaTop Best Dive Sites in VenezuelaTop Best Websites For Art StudentsTop Best Japanese Instant Noodle BrandsTop Best Comedy Manhwa (Webtoons)Top Best Japanese Sunglasses BrandsTop Most Expensive Air Jordan SneakersTop Health Benefits of CucumberTop Famous Universities in SwedenTop Most Popular Films Starring Jo Jung-sukTop Interesting Facts about CougarsTop Best Hospitals for Hip Replacement in the USATop Most Expensive DefendersTop Health Benefits of GooseberriesTop Health Benefits of ParsnipsTop Best Foods and Drinks in LondonTop Health Benefits of Rosehip TeaTop Best Air Fryers for Low-fat CookingTop Most Asked Teacher Interview Questions with AnswersTop Best Shopping Malls in ZurichTop The Most Beautiful Botanical Gardens In L.A.Top Best Mexican Restaurants in Miami for Carb-loading rightTop Best Energy Companies in GermanyTop Best Garage HeatersTop Largest Banks in IrelandTop Leading Provider - Audit and Assurance In The USTop Best Jewelry Brands in IndiaTop Prettiest Streets in the UKTop Best Lakes to Visit in TunisiaTop Highest Mountains in Israel