Kent J. Chen's WebLog

...information technology, internet, and random thoughts

Bluetooth security essentials

Source: Security Administrator Newsletter at March 2005 from WindowsITPro by John Howie, #45210

Bluestumbling, Bluesnarfing, and Bluejacking

Bluestumbling is the process by which you can discover other Bluetooth devices around you, in particular, devices taht are either operating in Security Mode 1 or are flawed and allow access to services without authentication.

Bluesnarfing is the practice of obtaining information from a Bluetooth-enabled device without first pairing with it.

Bluejacking is an abuse of the Object Exchange (OBEX) profile that is intended to be a means of exchanging data between two Bluetooth-enabled devices without requiring authentication.

Securing Bluetooth

A basic security rule is to disable anything you don't need or use from your Bluetooth-equipped devices.

If you must leave Bluetooth enabled, I recommend ensuring that your device isn't discoverable.

If you need to pair Bluetooth devices, I recommend never doing so in a public place. Instead, pick somewhere quiet where there's little chance of someone eavesdropping on Bluetooth radio signals.

When pairing devices, you should use authentication and encryption on the link between devices, where possible.

If you pair mutlple Bluetooth devices, I recommend selecting a unique, random passkey for each pairing.  If a pairing is lost or broken and you need to pair the devices again, I recommend using a different passkey.

Finally, when procuring Bluetooth devices, do some research into the security of the devices you're considering.

see full this useful good article here

Print | posted on Thursday, March 10, 2005 1:51 PM |

Feedback

No comments posted yet.

Post Comment

Title  
Name  
Email
Url
Comment   
Please add 1 and 2 and type the answer here:

Other Links

Follow me @twitter

My Recent Posts