Interviews

Watch out for wearables

by Mark Rowe

It’s easy to monitor and record Bluetooth Low Energy signals transmitted by many mobile phones, wearable devices and iBeacons, including the iPhone and fitness monitors, according to an infosec company. This raises concerns about privacy and confidentiality, according to Context Information Security. Their researchers have even developed an Android app that scans, detects and logs wearable devices.

The app can be downloaded along with a blog detailing the research at: www.contextis.co.uk/resources/blog/emergence-bluetooth-low-energy

The Context findings follow recent reports that soldiers in the People’s Liberation Army of China have been warned against using wearables to restrict the possibility of cyber-security loopholes.

Scott Lester, a senior researcher at Context, said: “Many people wearing fitness devices don’t realise that they are broadcasting constantly and that these broadcasts can often be attributed to a unique device. Using cheap hardware or a smartphone, it could be possible to identify and locate a particular device – that may belong to a celebrity, politician or senior business executive – within 100 metres in the open air. This information could be used for social engineering as part of a planned cyber attack or for physical crime by knowing peoples’ movements.”

Bluetooth Low Energy (BLE) was released in 2010 for a range of new applications that rely on constantly transmitting signals without draining the battery. Like other network protocols it relies on identifying devices by their MAC addresses; but while most BLE devices have a random MAC address, Context says that it found that in most cases the MAC address doesn’t change. Lester said: “My own fitness tracker has had the same MAC address since we started the investigation, even though it’s completely run out of battery once.”

Sometimes the transmitted packets also contain the device name, which may be unique, such as the ‘Garmin Vivosmart #12345678’, or even give the name of the user, such as ‘Scott’s Watch’.

BLE is also increasingly used in mobile phones and is supported by iOS 5 and later, Windows Phone 8.1, Windows 8, Android 4.3 and later, as well as the BlackBerry 10. The Bluetooth Special Interest Group (SIG) has predicted that by 2018, more than 90 percent of Bluetooth enabled smartphones are expected to be Smart Ready devices, supporting BLE; while the number of Bluetooth enabled passengers cars is also predicted to grow over to 50 million by 2016.

iBeacons, which also transmit BLE packets to identify a location, are already used in Apple Stores to tailor notifications to visiting customers, while BA and Virgin use iBeacons with their boarding pass apps to welcome passengers walking into the lounge with the WiFi password. House of Fraser is also trialling iBeacons on dummies to allow customers to look at the clothes and their prices on their phones. The current model for iBeacons is that they should not be invasive; you have to be running the application already, for it to detect and respond to a beacon. But the researchers have concerns. Lester said: “It doesn’t take much imagination to think of a phone manufacturer providing handsets with an iBeacon application already installed, so your phone alerts you with sales notifications when you walk past certain shops.”

The current version 4.2 of the Bluetooth Core Specification makes it possible for BLE to implement public key encryption and keep packet sizes down, while also supporting different authentication schemes, says the firm. Lester said: “Many BLE devices simply can’t support authentication and many of the products we have looked at don’t implement encryption, as this would significantly reduce battery life and increase the complexity of the application. It is clear that BLE is a powerful technology, which is increasingly being put to a wide range of uses. While the ability to detect and track devices may not present a serious risk in itself, it certainly has the potential to compromise privacy and could be part of a wider social engineering threat. It is also yet another demonstration of the lack of thought that goes into security when companies are in a rush to get new technology products to market.”

Visit: www.contextis.co.uk/resources/blog/emergence-bluetooth-low-energy.

Related News

  • Interviews

    ASC near 25th anniversary

    by Mark Rowe

    The Association of Security Consultants (ASC) enjoyed their annual dinner at the House of Lords on December 11, pictured. Their host was…

  • Interviews

    Cyber Reserve Unit

    by Mark Rowe

    An IT security and compliance company has commented on the news that the Ministry of Defence is to start recruiting former members…

  • Interviews

    Power of paper

    by Mark Rowe

    Phil Greenwood, Director, pictured, Information Management and Business Outsourcing at Iron Mountain, writes of the power of paper in an age of…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing