In 2020 we disclosed the Bluetooth Impersonation AttackS (BIAS), a family of high impact attacks affecting Bluetooth’s authentication protocols. The attacks allow impersonating any Bluetooth device during secure session establishment without knowing the long term pairing key. The BIAS attacks are tracked with CVE-2019-9506
IEEE S&P (Oakland) 2020 Paper Teaser
IEEE S&P (Oakland) 2020 Paper Presentation
BIAS + KNOB attack against Bluetooth IACR Attacks in Crypto
From Bluetooth Standard to Standard Compliant 0-days Hardwear.io
Related
Publications
PDF Cite Code Project Project Slides Video CVE-2019-9506 CVE-2020-10135
PDF Cite Code Project Slides Video Teaser Website CVE-2020-10135
Events
In this talk we will explore recent research on real world wireless security protocols. We will cover standard protocols such as Bluetooth pairing and session establishment and proprietary ones such as IoT application layer protocols used to secure traffic between companion mobile applications and electric scooters and fitness trackers.
Keynote given at ACSW'24 (EuroS&P Workshop) covering Automotive Bluetooth Security and E-Spoofer.