Post #98176
2025-12-27 23:18 UTC
The "Bluetooth Headphone Jacking" talk at #39c3 was awesome, too. They reversed a popular SOC that powers Bluetooth earbuds and headphones.
They found that (even without being paired to the headphone), they could dump flash and RAM from the device. Then they dumped a bunch of info from the device - e.g. the #Bluetooth address and "master" encryption keys used for the communication with paired devices (e.g. a #phone).
Then they impersonated the headphone from their laptop and connected to the phone (pretending to be the headphone).
The headphone (or the laptop impersonating the phone) has permissions to do some things on the phone, e.g. accept calls, increase/decrease volume, etc.
Then they started recovering access a #WhatsApp account via some account recovery mechanisms. That required some one-time security key which would normally be delivered via SMS, but that could be delivered via phone call as a fallback option, too. Since the phone thought it was connected to the Bluetooth headphone, phone call audio would go to the laptop via Bluetooth.
As the cherry on top, they escalated into the victim's #Amazon account.
Scary shit. #YouCannotBeParanoidEnough #security
Replies (6)
-
@sb@metroholografix.ca 2025-12-28 20:09
@oots Here's a link to the video of the talk on yt: https://youtu.be/TK5Tz4Bt94Y
-
@deborahh@cosocial.ca 2025-12-28 20:14
@oots yikew. Q: does this apply, too, to my home PC bluetooth (always on, for connection to speakers)?
-
@praetor@mstdn.social 2025-12-28 21:51
@oots IDK. If someone want to maliciously put a bad ass play list on my headphones, then that would be okay. Unless it's country music. I'll find the little bitch and beat them with a bat.
-
@jef@mastodon.social 2025-12-28 22:02
@oots Never Bluetoothed, never will.
-
@hyde@lazybear.social 2025-12-31 07:00
@oots a link to the talk eventually ?
-
@wilhelm@fedia.social 2025-12-28 20:56
@oots@infosec.exchange great talk! Recording at media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone