Nokia Admits Multiple Bluetooth Security Holes 136
An anonymous reader writes "Nokia has admitted that four of its handsets (6310, 6310i, 8910 and 8910i) have multiple security vulnerabilities that can allow an attacker to read, edit and copy the contacts and calendar entries using Bluetooth. This admission comes after a ZDNet UK article published earlier today. the spokesperson advises customers to switch off Bluetooth in public places!" For more information, see the bluesnarfing site pointed out by reader profet.
Great ! (Score:5, Funny)
Re:Great ! (Score:4, Informative)
Re:Great ! (Score:3, Informative)
It's a shame - this is something the Sony/Ericsson phones do very well, but I still prefer Nokias overall (mainly because of their interface.)
Try this (Score:3, Informative)
Re:Try this (Score:1)
It doesn't seem to greatly like my BT dongle, but I'll keep fiddling as it does exactly what I need.
Thanks
bluejacking (Score:1, Interesting)
But I guess Nokia finally admitting they have an issue is interesting. I wonder what the other Bluetooth capable device manufacturers do about this???
Re:bluejacking (Score:5, Informative)
Re:bluejacking (Score:2, Informative)
Re:bluejacking (Score:2)
*gnashing of teeth*
Re:bluejacking (Score:1)
No big deal (Score:4, Insightful)
What happened with wireless networks happened with anonymous ftp servers.
What happened with anon ftp servers happened with telnet access (you remember the "guest" login provided by most hosts ?).
Every time a new technology is used there are some flaws with it. No big deal.
Re:No big deal (Score:5, Insightful)
What happened with wireless networks happened with anonymous ftp servers.
What happened with anon ftp servers happened with telnet access (you remember the "guest" login provided by most hosts ?).
Every time a new technology is used there are some flaws with it. No big deal.
BIG DEAL!
You could expect that someone that designs a new communication protocol today builds on past experience. It's not like viruses, spam, malware and and crackers are something unknown. Instead, you should make the security requirements absolutely central in your new protocols. With the bluetooth technology becoming the most widespread wireless communications protocol (if you believe its proponents) not having security as a top priority is absofuckinglutely brainlessly idiotical.
Re:No big deal (Score:5, Insightful)
Re:No big deal (Score:5, Informative)
It isn't like this hasn't come up before, Schneier predicted that Bluetooth would be a security nightmare three and a half years ago [schneier.com] ! Quoting:
What amazes me is the dearth of information about the security of this protocol. I'm sure someone has thought about it, a team designed some security into Bluetooth, and that those designers believe it to be secure. But has anyone reputable examined the protocol? Is the implementation known to be correct? Are there any programming errors? If Bluetooth is secure, it will be the first time ever that a major protocol has been released without any security flaws. I'm not optimistic.
And what about privacy? Bluetooth devices regularly broadcast a unique ID. Can that be used to track someone's movements?
The stampede towards Bluetooth continues unawares. Expect all sorts of vulnerabilities, patches, workarounds, spin control, and the like. And treat Bluetooth as a broadcast protocol, because that's what it is.
Re:No big deal (Score:2, Informative)
What's important, though, is that a shared key is negotiated without being sent over the wire. It may be possible to brute-force the pin with data captured from the initial authentication run, or there might be an attack against the key generation or encryption, but the "physical connection" you claim is required is only one way of ensuring that a
Re:No big deal (Score:2)
Re:No big deal (Score:2)
Oh, in that case, I know this one: it's the users' fault for not constantly monitoring the problems discovered in every software package they use and failing to update their systems, right?
At least that seems to be the typical slashdot attitude - we love keeping track of s
Re:No big deal (Score:2)
I never said anything about users. A little cranky this morning?
Security holes are the fault of the developer. However, more often than not, software has security holes that are fixed in later revisions, and the user will need to update. This need to update cannot be blamed on the user, it is just an unfortunate
What's a non-software product these days? (Score:2)
Like a cell phone, or something. (Which, of course, was probably your point.)
Hey, do you want.... (Score:4, Funny)
K.I.S.S (Score:3, Interesting)
Re:K.I.S.S (Score:2)
in these companies marketing departments where
the mantra "complexity = good" is chanted on a daily basis.
Re:K.I.S.S (Score:2, Insightful)
Re:K.I.S.S (Score:5, Insightful)
Your comparison with "their machines" and the phone firmware (essentially this is the phone "OS"), makes me think you believe that Windows Update can defeat MyDoom.
Actually, MyDoom has fuck all to do with keeping your Windows PC up to date. It is about keeping your _virus_ scanning up to date, and not running attachments that make it through to you. I could have just run and completed Windows Update, but still be infected with MyDoom via the very next email I received and (stupidly) ran the attachment of. Remember, virus scanning is NOT part of the Windows OS, it is something that must be loaded and configured and paid for (usually, unless you go with grisoft or similar).
Your point would be a lot better made if you referred to something like the Blaster or Nachi worm, where the fix was available via Windows Update for several weeks.
Re:K.I.S.S (Score:1)
Re:K.I.S.S (Score:3, Informative)
Application platform, misc. servers & UI apps (UIQ, Series 60, ...)
Symbian OS (kernel, middleware)
Some sort of Manufacturer RTOS for running a GSM stack, for which Symbian doesn't quite cut it.
These devices are far from simple. Given what you can do on this size of device, I wonder why someone doesn't make a solid state PC, with a few seconds boot time, and no noise. Wireless keyboard,
Re:K.I.S.S (Score:2)
Re:K.I.S.S (Score:1)
Re:K.I.S.S (Score:1)
Re:K.I.S.S (Score:1)
These are European, so they might not be available in the Americas.
Re:K.I.S.S (Score:1)
Re:K.I.S.S (Score:1)
Phone are phones. Anything else you care to say about them, in terms of what they should/could or shouldn't do are just your opinions. My phone lets me do a number of things in addition to making and receiving phone calls, but it could do more. People like you remind me of people making predictions that `text messaging will never take off - why type a message on a fiddly keyboard when you can just phone them?`. How many millions of text messages are sent a day now?
Re:K.I.S.S (Score:2, Insightful)
That's as foolish as saying that PCs are just tools. They're for wordprocessing, administration and some games. That's how it was when I got my first PC. Why go connect with other computers, with all those evil hackers and expose your PC with your sensitive data? Why play and record music on your computer when you have specialized devices like CD-players and tape recorders? Because more features are better.
Within ten years,
Re:K.I.S.S (Score:3, Interesting)
---
Dman luddites. Just because you would rather have a device that gives up freedom for security does not mean
Re:K.I.S.S (Score:2)
In other news, I don't need emacs, because the MS-DOS editor has all the features anyone should want from a word processor.
OMG, not another flamewar! [Was: Re:K.I.S.S] (Score:1)
Re:K.I.S.S (Score:1)
Re:K.I.S.S (Score:1)
Re:MOD PARENT DOWN (Score:1)
Is Bluetooth upgradeable? (Score:2, Insightful)
Re:Is Bluetooth upgradeable? (Score:5, Insightful)
I don't think the bluetooth protocol is broken - just the implementation.
Re:Is Bluetooth upgradeable? (Score:2)
Re:Is Bluetooth upgradeable? (Score:2, Informative)
Re:Is Bluetooth upgradeable? (Score:2, Insightful)
Always do backups before firmware updates!
Re:Is Bluetooth upgradeable? (Score:1)
How is your 6310? (Score:2)
Social science wonder? (Score:5, Insightful)
Yet, a mobile-phone giant does this. Are they just plain stupid, or is this another example of the wonders of social science? I can't help thinking how intelligent an ant nest can be though ants singularly are so stupid, and how an organization with some of the brightest engineers on the planet can act so carelessly.
Re:Social science wonder? (Score:2, Insightful)
They havent even got a fully functional 3G phone yet..
Its that evil virus, whats it called again? Oh yeah, mismanagement.
Re:Social science wonder? (Score:1)
I keep it enabled on mine for my BT handsfree unit, but it's set hidden. It's not perfect, but should make me less likely to get hit by it.
(I was amazed when I did a scan in a cinema recently how many phones were advertising their presence.)
I still use my older Motorola L7089 and T280 - neither of which have Bluetooth. But neither of the modems in the
Re:Social science wonder? (Score:3, Insightful)
The problem with any encryption method is that it reduces (to some extent) convenience. Since convenience is the keyword mobile phone manufacturers depend on to sell their products, and any level of extra "complexity" is seen as a hindrance.
The mobile phone market is so tight that any possible hindrance (whether it is reasonable or not) is seen as a liability to sales.
Well, that and featching creeperism: Hey, we said we wanted Bluetooth phones. Nokia, et al, just gave them to us. We didn't say we wante
hmm.. i wonder why????! (Score:2, Funny)
Ingornace? (Score:4, Informative)
I wonder... (Score:1)
What about other models that have Bluetooth? Are they safe from this security hole?
Turn it off! (Score:2, Insightful)
Big Woop. (Score:1)
Looked more like an attempt to get advertising for their hosting company to me.
I was interested to see the Z1010 on the list when the commercial version isn't out yet.
Re:Big Woop. (Score:3, Informative)
Re:Big Woop. (Score:3, Informative)
Re:Big Woop. (Score:1)
If you were stupid enough to buy a Nokia phone, tough luck.
Unbelievable (Score:2, Interesting)
I thought most people would have learned something on the WiFi fiasco by now, especially Nokia (who also make security products such as firewalls by the way)
Now let's see if they're dedicated enough to their customers to fix this problem quickly.
In the meantime, it's good idea to keep this on the headlines of the media.
On another note, I'd be interested about other bluetooth-enabled devices - handsfree headset ? iPAQs? Palm
Re:Unbelievable (Score:5, Insightful)
I can. The mobile phone manufactures in general and Nokia in particular is very much focused on time-to-market. That means that their phones are not always finished when they hit the shelves. To be fair, neither was my Ericsson R520m phone when I first got it.
Re:Unbelievable (Score:1)
Re:Unbelievable (Score:2)
Normally it isn't. It uses too much power if BT is on all the time so I normally keep it on Automatic. That way my BT headset still works but the phone is not discoverable.
Re:Unbelievable (Score:2)
...how did it improve? Firmware update? Curious R520m-owning minds want to know :-)
Re:Unbelievable (Score:2)
Firmware update. Twice.
Solution: Employ Hackers (Score:2, Insightful)
Irony (Score:2, Funny)
Advertising nokia as a business mobility solution. Want to keep your business contacts a secret?
It could be a lot worse... (Score:3, Interesting)
I can't guess their reasons for not including Bluetooth with all their more expensive models, since it can't cost more than one Euro or so, but at least it means that of all the phones out there, relatively few are exploitable.
Re:It could be a lot worse... (Score:4, Interesting)
As an consumer, if you have a bluetooth phone all you are likely to have is the phone number of your friends.
As a geek, you are more than likely to have a PDA for keeping anything more detailed/sensitive.
Business users, executives etc. are more likely to use the advanced functions of there phones and therefore it is they that are most at risk to losing sensitive data.
So, whilst most models dont have bluetooth, the ones that do are the ones that are liekly to have the most valuable information.
Re:It could be a lot worse... (Score:1)
What?!? If someone is trying to exploit this security hole do you really think they'd be bothered to get the phone number of your mate Billy? I think they'd be far more interested in getting the numbers from a coperate exec phone or other information that isn't readily available.
Sure you could ring a company and ask to speak to a CEO but if you had his/her mobile number you could have a lot
Hah, I'm Safe! (Score:2, Funny)
Both ZDNET and Nokia wrong (Score:4, Informative)
Nokia is vunerabile to both having the device detect on and off in the hacks..
according to the bleustumbler.org site..
nokia is not the only one (Score:5, Interesting)
Re:nokia is not the only one (Score:1)
What's the truth? (Score:4, Interesting)
Re:What's the truth? (Score:2)
That's ok, there will always be a job for them here at slashdot.
Is Nokia the mobile Microsoft? (Score:2, Funny)
Doesn't seem smart to me. Admit there is a vulnerability then say you aren't going to fix it. I'm surprised they didn't say the "fix" would be released in the next versions of the affected phones and customers would need to upgrade following their easy and costly upgrade path.
Of course a bulk enterprise lic
Wireless is inherently insecure (Score:1, Insightful)
When you're sending data over the air, then you have no way of knowing who is listening. That's why my home LAN is wired -- so I at least know if anyone is tapping me, then they must be on the inside. And I wouldn't trust the phone companies to build in any kind of security either; MI5 wo
Not true - wires leak like hell (Score:5, Interesting)
This isn't true -- you can pick up (copper) LAN signals from a reasonable distance, which is why the military always uses fiber outside of shielded environments. At least when sensitive data is expected to travel along the pipes.
The most obvious way to test this is to place an ordinary FM radio antenna along the network wire and see how much junk you are picking up; you can clearly hear the intensity of the network traffic.
I heard this traffic when sitting in my car in the company parking lot at one of my previous jobs and so knew when the builds were done.
Granted, the equipment is fairly expensive, but don't think for a second that you're safe because you're wired. Wires leak like hell.
Re:Not true - wires leak like hell (Score:2, Interesting)
An ordinary radio set gives only a qualitative estimate. To recover the actual data, you'd need equipment costing more than any of my data is worth {but I wouldn't put it past the M.I.B. to sue me for wasting their time with junk data}.
Re:Not true - wires leak like hell (Score:1, Funny)
Maybe a little, but what do you think the U in UTP stands for?
Re:Not true - wires leak like hell (Score:1)
Re:Not true - wires leak like hell (Score:2)
We had one of our network-connected copiers start sending copious amount of garbage data through the network. When we went to take a look at it we had found that a cleaner had uncovered the network cable and run over it with a vacuum.
The outside cover had been torn completely off and the internal wires were definitely not in "intimate proximity".
Re:Not true - wires leak like hell (Score:1)
Protected 6310 (Score:5, Funny)
This one does not have the vulnerability. You see, if you switch bluetooth on, the whole phone crashes immediately.
But I only just got it! (Score:2, Funny)
Well, I guess it was worth those 48 hours of carefree wireless toying...
Re:But I only just got it! (Score:1)
All OBEX communications (the stuff that is buggy) needs to be accepted by you and this is for the communication to start (not like other phones - do you want to save "exploit"? *BANG*)
So does that make it ... (Score:2)
I wonder how long it takes before people using voice dial find themselves calling Elbonia..
Re:So does that make it ... (Score:1)
It's bad implementation, not specification (Score:4, Informative)
This means that you have to have given the attacker access to privileged services at one point in time, and then deleted him.
If you had not deleted him, he would obviously still have access.
But it is the missing deletion that is the problem.
You should not pair your device with any devices except your own. Your PDA requires to be paired with your Phone, Laptop, and access point, so it can dial up, synch, and have LAN access etc. But you don't have to pair it to send your business card to somebody else. There is no reason to pair with Joe Hackers device. So for most of the cases described by AL Digital it is just a bad implementation which does not affect the majority of users.
For the rest of the cases it is also a bad implementation by Nokia and "possibly other manufacturers", it is not a vulnerability in the protocol.
From the article... (Score:2, Informative)
Well that is just about all of the bluetooth phones out there then?
Bluetooth and the Nokia 6310i (Score:1)
Re:Bluetooth and the Nokia 6310i (Score:1)
that explains why... (Score:1)
A "Microsoft" -like reply from Nokia (Score:1, Funny)
Due to the latest security problems involving our phones and Bluetooh, we recommend you write your complete address book and contacts on a piece of paper and store it in a safe place. Also, since our phones explode [theregister.co.uk] it is best that you stay more than 10 feet away from them at all times. This will ensure both safety of your information on the phone and yourself.
well.... (Score:2)
Winton
(1) Normal -> one with out a 15" color screen, video camera and gamepad attached.
Sony Ericsson models vulnerable, as well as Nokias (Score:1)
http://groups.google.com/groups?&selm=4 0 27ef9a.155 09562%40news.individual.de
AL Digital
http://www.aldigital.co.uk/
announced Nokia 6310, 8910 and 8910i mobiles were found to be at greatest risk to having their data copied without the owner's consent with a crack attack over Bluetooth.
The security papers (links, below) suggest keeping some other mo
OwN3D ??? (Score:1)
U R OwN3D - R00t
This is what my poor Nokia has been displaying for the past four days
nokia has any vulnerabilities? (Score:1)
For all the history all of Nokia hardware, both wireless radiolinks and consumer electronics, was ultracrappy and vulnerable to anything, even failing when not in use
Just avoid buying crappy things, and will be in safety.
To those who want to argue - buy ms windows, get on ms
Re:Important note: (Score:5, Funny)
Re:Important note: (Score:1)
pocket phone book
diary
electronic game
alarm clock
laptop for connecting to the net
any other odds and sods, but if they are all in one thing, its lighter on my pockets.