Post #1334488
2025-12-28 20:14 UTC
Replies (2)
-
@oots@infosec.exchange 2025-12-28 22:07
@deborahh Firstly, I don't know. I didn't do the research myself, I just saw the talk. So take my answer with a big pinch of salt. My *guess* is: *If* your Bluetooth speaker uses the same chipset, it's probably vulnerable to *this* attack, too. However, your PC *probably* exposes less attack surface (from the speaker's perspective), since (for example) most likely it can't accept phone calls like an actual phone. Though whether the Bluetooth chipset in your PC, the Bluetooth driver on your PC, and the Bluetooth chipset in your speaker are secure is an entirely different question. Most likely they're just vulnerable to different bugs, which we don't know about, yet.
-
@joelh@infosec.exchange 2025-12-28 23:49
@deborahh @oots If someone is close enough to be in Bluetooth range and knows your account details to trigger a phone call for 2FA, they could use a hammer to get you to cough up your AWS password too. It’s an interesting PoC, but unlikely to be the way you are compromised imo. It’s more concerning for MITM attacks where they sit in between eavesdropped silently.