You are here: silicon.com > Networks > Mobile & Wireless

Mobile & Wireless

PIN security would make Bluetooth safer

Industry group says long numbers the way forward...

Tags: sig, pin, bluetooth

By Peter Judge

Published: 28 June 2005 08:35 BST

Bluetooth, the wireless connection used on PDAs and phones, is not safe unless you use an eight-digit PIN to secure devices, an industry group has warned.

The Bluetooth Special Interest Group (SIG) has told people to set eight-digit PINs when pairing two devices and to take other precautions, after a report described a way for hackers to crack the security codes on Bluetooth devices and seize control of them.

For security, Bluetooth devices will not communicate until they have "paired" - a one-off process in which both devices must enter the same PIN, or personal identification number. A hacker that listens in on the pairing process can decode the PIN and then take control of the link, siphon off data or, potentially, take control of either of the devices.

Because Bluetooth has a short range, and pairing is a one-off process between any two devices, most users were considered safe - until an extension of the attack was described this month by Yaniv Shaked and Avishai Wool of Tel Aviv University in Israel.

The new attack can force two Bluetooth devices to come "unpaired", the researchers said. When the user pairs them again, the hacker can listen to the pairing process and crack the PIN.

The simplest way to force Bluetooth devices to re-pair is to send a message that purports to come from one of them, claiming to have lost the key. Three ways to force re-pairing are described in "Cracking the Bluetooth PIN", presented by Avishai Wool and Yaniv Shaked of Tel Aviv University, at the Mobisys conference in Seattle.

The Bluetooth SIG's advice is don't re-pair in a public place, where someone else might eavesdrop, and use a longer PIN.

The SIG advised in a statement last week: "When you pair devices for the first time, do this in private - at home or in the office. If your devices become unpaired while you are in public, wait until you are in a private, secure location before re-pairing your devices, if possible."

"Always use an eight character alphanumeric PIN code as the minimum," the SIG said. "You only have to enter this once, so [a longer code] is not a hardship given the security benefits."

The group agrees with the researchers that a PC can crack a four-digit code in a tenth of a second but reckons an eight-digit PIN would take 100 years to break, making this crack "nearly impossible". Some devices, such as headsets, include a factory-set four-digit PIN but most devices like phones allow users to set the PIN they want.

The SIG is also at pains to assure people the hack is only an academic paper at present. "The equipment needed for this process is very expensive and primarily used by developers only," its advice reads. "It is highly unlikely that a normal user would ever encounter such an attack."

As ever, knowledge is important. "The attack also relies on a degree of user gullibility, so understanding the Bluetooth pairing process is an important defence," the SIG said.

Peter Judge writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Read and write about internet access at the airports of the world at atlarge.com.

Rob Bamforth Seeking memorable mobile apps Quocirca's Straight Talking: Why are there so few?

Stewart Baines How much SEO is too much? Net Effect: Plus 10 tips on boosting your site's profile


  • Jobs
EXECUTIVE MANAGER, BUSINESS DEVELOPMENT MANAGER, SENIOR MANAGER

Successful candidates will not only have the benefit of working with a forward thinking company, which is totally geared up to working at the ...

Linux Systems Engineer

Troubleshooting of critical 1st-tier systems issues during high-impact events, including management & participation in conference calls ...

Director - Management Consulting

Tefen is headquartered in Tel Aviv, Israel and is publicly traded on the Tel Aviv Stock Exchange (TASE). Do you want to take control of your career ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: