{"id":147167,"date":"2019-08-20T17:01:56","date_gmt":"2019-08-20T17:01:56","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=147167"},"modified":"2025-07-01T21:33:30","modified_gmt":"2025-07-02T04:33:30","slug":"your-bluetooth-devices-could-be-a-handy-backdoor-for-hackers","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/your-bluetooth-devices-could-be-a-handy-backdoor-for-hackers\/","title":{"rendered":"Your Bluetooth devices could be a handy backdoor for hackers"},"content":{"rendered":"<p>A disturbing new Bluetooth vulnerability has been discovered by researchers. It could see our wireless devices leaving us vulnerable to cyber-attack. The problem relates to Bluetooth\u2019s authentication protocols and could see a potential attacker taking up a position between two Bluetooth\u00a0 devices and eavesdropping on all information shared across the connection.<\/p>\n<p>The vulnerability, which is known as KNOB (Key Negotiation of Bluetooth) is so serious that the <a href=\"https:\/\/www.bluetooth.com\/security\/statement-key-negotiation-of-bluetooth\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bluetooth SIG Group has been forced to public a security warning<\/a> detailing the new bug.<\/p>\n<h2>New Bluetooth bug can target Bluetooth devices from versions 1.0 to 5.1<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-147170\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Bluetooth_KNOB_vulnerability_megh8o.jpg\" alt=\"Bluetooth devices\" width=\"700\" height=\"394\" \/><\/p>\n<p>A team of researchers from <a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/918987\/\" target=\"_blank\" rel=\"noopener noreferrer\">Oxford University, the Singapore University of Technology and Design, and CISPA Helmholtz Center for Information Security<\/a> is responsible for the discovery. Known as a KNOB attack, the vulnerability degrades the level of security that Bluetooth connections have to such a level that a Brute Force attack, where a hacker simply cycles through all possible encryption passwords until they stumble upon the correct one, becomes possible.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/09\/new-music-192.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">Beats, Bose, or Sony: who has the best headphones?<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/beats-bose-or-sony-who-has-the-best-headphones\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Read now \u25ba<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/beats-bose-or-sony-who-has-the-best-headphones\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>Once the attacker comes to the correct encryption key, they then have ultimate access to all data being shared across the connection and could even add their own data to the connection. To give an example of what this could mean, I\u2019m writing this report out on a keyboard and thinking about the last time I used my online banking!<\/p>\n<figure id=\"attachment_147172\" aria-describedby=\"caption-attachment-147172\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-147172\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Bluetooth_KNOB_vulnerability_SIG_Group_warning_wix0j6.jpg\" alt=\"Bluetooth Security notice\" width=\"700\" height=\"238\" \/><figcaption id=\"caption-attachment-147172\" class=\"wp-caption-text\">The Bluetooth SIG Group had to release a security notice warning about the vulnerability<\/figcaption><\/figure>\n<p>The other scary thing to note about a <a href=\"https:\/\/knobattack.com\/\">KNOB attack<\/a> is that victims don\u2019t even know they\u2019ve been compromised. It isn\u2019t the easiest exploit, however, which means there is hope. The post explaining the vulnerability says, \u201cFor an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were establishing a BR\/EDR connection. If one of the devices did not have the vulnerability, then the attack would not be successful.\u201d<\/p>\n<p>Fortunately, there are Bluetooth devices out there that aren\u2019t vulnerable to this attack and the attack will only work if the attacker is in close proximity to two vulnerable devices at the same time. This means that the level of effort required to pull this off means it is likely to be businesses that will be targeted rather than individuals. Don\u2019t worry, nobody is going to be hacking into your headphones and telling everybody that you listen Justin Bieber, and not Led Zeppelin like you\u2019ve been telling everybody.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-147173 aligncenter\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Bluetooth_KNOB_vulnerability_bluetooth_logo_pf6j8r.jpg\" alt=\"bluetooth logo\" width=\"235\" height=\"119\" \/><\/p>\n<p>The other good news is that the <a href=\"https:\/\/www.bluetooth.com\/about-us\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bluetooth SIG Group<\/a> that describes itself as, \u201ca global community of over 34,000 companies serving to unify, harmonize and drive innovation in the vast range of connected devices all around us\u201d has already upgraded the minimum security specification that goes out to Bluetooth manufacturers to seven bytes. This means that even if the KNOB attack can degrade the security credentials of a Bluetooth connection, it won\u2019t be able to do so to the extent that a brute force attack will be possible.<\/p>\n<p><em>AAAANNNNDDDD Breath. <\/em>Phew, it took a lot to get through all of that without making a single knob joke. Best knob jokes in the comments please.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">More from Softonic<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to develop perfect pitch for free \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/how-to-develop-perfect-pitch-for-free-with-teoria\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/image\/upload\/q_auto:eco\/v1557952809\/editorial\/piano_192.webp)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to develop perfect pitch for free \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Karaoke in your pocket: sing with your friends on Smule \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/karaoke-in-your-pocket-sing-with-your-friends-on-smule\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/image\/upload\/q_auto:eco\/v1557952809\/editorial\/smule192.webp)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Karaoke in your pocket: sing with your friends on Smule \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to become a DJ, arranger, and composer with Ableton \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/how-to-become-a-dj-arranger-and-composer-with-ableton\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/image\/upload\/q_auto:eco\/v1557952809\/editorial\/ableton_192.webp)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to become a DJ, arranger, and composer with Ableton \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"The top 8 DJ software applications available today \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/the-top-8-dj-software-applications-available-today\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/10\/dj-music-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>The top 8 DJ software applications available today \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>New Bluetooth bug can target Bluetooth devices from versions between 1.0 to 5.1<\/p>\n","protected":false},"author":9073,"featured_media":147171,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[1825,1032,1027],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-147167","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-bluetooth","tag-gadgets","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/147167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=147167"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/147167\/revisions"}],"predecessor-version":[{"id":325548,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/147167\/revisions\/325548"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/147171"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=147167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=147167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=147167"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=147167"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=147167"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=147167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}