Post #137938
2026-01-16 18:39 UTC
Replies (13)
-
@aramis87@fedia.io 2026-01-16 20:10
security researchers [...] are revealing a collection of vulnerabilities they found in 17 audio accessories that use Google’s Fast Pair protocol and are sold by 10 different companies: Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, and Google itself.
-
@HakunaHafada@lemmy.dbzer0.com 2026-01-16 20:04
Laughs in the archaic technology of the 3.5mm audio jack
-
@Truscape@lemmy.blahaj.zone 2026-01-16 19:21
Placing a bet now: under 10% of vulnerable units will be patched within a year's time.
-
@bridgeenjoyer@sh.itjust.works 2026-01-16 23:34
My wired headphones dont have this issue, likely sound far better, require no batteries, and are user serviceable. Guys, we peaked in 2012 (potentially earlier) as a race technologically, stop trying to create new grifts for billionaires.
-
@fort_burp@feddit.nl 2026-01-17 13:53
> GOOGLE DESIGNED THE wireless protocol known as Fast Pair to optimize for ultra-convenient connections: It lets users connect their Bluetooth gadgets with Android and ChromeOS devices in a single tap. Bluetooth pairing is not a difficult process, imagine creating a whole new attack vector for that. And of course security was an afterthought. Capitalism is amazing for wasting resources and getting bad results for it.
-
@einkorn@feddit.org 2026-01-16 19:03
[Link to the original talk at 39C3](https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone)
-
@Bluegrass_Addict@lemmy.ca 2026-01-16 23:50
laughs in 3.5mm
-
@PierceTheBubble@lemmy.ml 2026-01-16 21:39
But you need to be in close proximity (~15m max) to *stalk* a victim? You might as well just follow them around physically then. Perhaps when the victim is in a private location, eavesdrop on their conversation or locating their position within there, might be a possibility. But ear raping would, of course, constitute the most significant danger of all. Also WhisperPair, not WhisPair?
-
@northernlights@lemmy.today 2026-01-16 21:10
Nothing from Samsung in the list, now I don't feel so bad about owning a Galaxy :D
-
@ExLisper@lemmy.curiana.net 2026-01-17 20:59
Meh. So realistic attack would be that you know someone you want to track has one of those 17 models (which is hard to tell by just looking at the headphones) and never paired it with Android and he carries them everywhere. You force-pair and now you can track them. It's pretty silly as a random attack because why would you track a random person. It's silly to use it to record conversations because from 15 m there are easier methods to do it. I would say the risk that this will be used to actually track/record someone is low.
-
@Professorozone@lemmy.world 2026-01-18 04:21
Did anyone else get a "page not found" error when trying to see the list of affected headphones? Edit: spelling.
-
@rob_t_firefly@lemmy.world 2026-01-17 14:01
Is that you, Abby Normal? 🧠
-
@fort_burp@feddit.nl 2026-01-18 17:57
I mean, how do you think they got to be a trillion dollar company, ***R&D***? 