Cookie Consent by Free Privacy Policy Generator 📌 37C3 - BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 37C3 - BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses


💡 Newskategorie: IT Security Video
🔗 Quelle: youtube.com

Author: media.ccc.de - Bewertung: 1x - Views:21

https://media.ccc.de/v/37c3-12342-bluffs_bluetooth_forward_and_future_secrecy_attacks_and_defenses Breaking and fixing the Bluetooth standard. One More Time. Ciao! We present the BLUFFS attacks (CVE-2023-24023), six novel attacks breaking Bluetooth's forward and future secrecy. Our attacks enable device impersonation and machine-in-the-middle across sessions by compromising and re-using one session key. We discuss the four vulnerabilities in the Bluetooth specification enabling the attacks, two of which are new and related to unilateral and repeatable session key derivation. We describe the toolkit we developed and open-sourced to test our attacks via firmware binary patching, our experiments where we exploited 18 heterogeneous Bluetooth devices, and the practical and backward-compliant session key derivation protocol we built to fix the attacks by design. We also cover related work like KNOB, BIAS, and BLUR, and educational Bluetooth security tips and tricks. Bluetooth is a pervasive technology for wireless communication. Billions of devices use it in sensitive applications and to exchange private data. The security of Bluetooth depends on the Bluetooth standard and its two security mechanisms: pairing and session establishment. No prior work, including the standard itself, analyzed the future and forward secrecy guarantees of these mechanisms, e.g., if Bluetooth pairing and session establishment defend past and future sessions when the adversary compromises the current. To address this gap, we present six novel attacks, defined as the BLUFFS attacks, breaking Bluetooth sessions’ forward and future secrecy. Our attacks enable device impersonation and machine-in-the-middle across sessions by only compromising one session key. The attacks exploit two novel vulnerabilities that we uncover in the Bluetooth standard related to unilateral and repeatable session key derivation. As the attacks affect Bluetooth at the architectural level, they are effective regardless of the victim’s hardware and software details (e.g., chip, stack, version, and security mode). We also release BLUFFS, a low-cost toolkit to perform and automatically check the effectiveness of our attacks. The toolkit employs seven original patches to manipulate and monitor Bluetooth session key derivation by dynamically patching a closed-source Bluetooth firmware that we reverse-engineered. We show that our attacks have a critical and large-scale impact on the Bluetooth ecosystem, by evaluating them on seventeen diverse Bluetooth chips (eighteen devices) from popular hardware and software vendors and supporting the most popular Bluetooth versions. Motivated by our empirical findings, we develop and successfully test an enhanced key derivation function for Bluetooth that stops by-design our six attacks and their four root causes. We show how to effectively integrate our fix into the Bluetooth standard and discuss alternative implementation-level mitigations. We responsibly disclosed our contributions to the Bluetooth SIG. Daniele Antonioli https://events.ccc.de/congress/2023/hub/event/bluffs_bluetooth_forward_and_future_secrecy_attacks_and_defenses/ #37c3 #Security

...



📌 Internet-Telefonie: Datenschützer raten zu Perfect Forward Secrecy


📈 33.84 Punkte

📌 Internet-Telefonie: Datenschützer raten zu Perfect Forward Secrecy


📈 33.84 Punkte

📌 Was ist Perfect Forward Secrecy (PFS)?


📈 33.84 Punkte

📌 TLS-Check: Qualys bestraft fehlendes Forward Secrecy


📈 33.84 Punkte

📌 TLS-Check: Qualys bestraft fehlendes Forward Secrecy


📈 33.84 Punkte

📌 Fitting Forward Secrecy into Today's Security Architecture


📈 33.84 Punkte

📌 eTLS hebelt Forward Secrecy von TLS 1.3 wieder aus


📈 33.84 Punkte

📌 Threema 5.0 bringt Gruppenanrufe, mehr Perfect Forward Secrecy


📈 33.84 Punkte

📌 Threema 5.0 bringt Gruppenanrufe, mehr Perfect Forward Secrecy


📈 33.84 Punkte

📌 Ibex-Protokoll: Threema bekommt Forward Secrecy für Nachrichten


📈 33.84 Punkte

📌 Mitigating Session Data Exposure: Perfect Forward Secrecy Explained


📈 33.84 Punkte

📌 Threema: Perfect Forward Secrecy für Nachrichten nun auch in iOS


📈 33.84 Punkte

📌 37C3 - 37C3: Feierliche Eröffnung


📈 33.02 Punkte

📌 37C3 - Decentralized energy production: green future or cybersecurity nightmare?


📈 24.17 Punkte

📌 Former CIA and NSA Director Says there's Too Much Secrecy Around Cyberattacks (January 13 and 14, 2016)


📈 23.23 Punkte

📌 Former CIA and NSA Director Says there's Too Much Secrecy Around Cyberattacks (January 13 and 14, 2016)


📈 23.23 Punkte

📌 It’s time to bolster defenses for an AI / Quantum Future


📈 23.22 Punkte

📌 New Spectre variants + Systematic Evaluation of Transient Execution Attacks and Defenses


📈 22.18 Punkte

📌 How to Improve Your Email Defenses and Block Spear Phishing Attacks


📈 22.18 Punkte

📌 How to Improve Your Email Defenses and Block Spear Phishing Attacks


📈 22.18 Punkte

📌 How to Improve Your Email Defenses and Block Spear Phishing Attacks


📈 22.18 Punkte

📌 Strengthening defenses against nation-state and for-profit cyber attacks


📈 22.18 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 HITB2011KUL - Privacy, Secrecy, Freedom and Power


📈 22.16 Punkte

📌 American Civil Liberties Union Sues FBI, DEA, and Justice Department Over Facial Recognition Secrecy 100% 24


📈 22.16 Punkte

📌 Mueller’s Findings: Why DOJ Non-Disclosure Policy and Grand Jury Secrecy May Not Apply


📈 22.16 Punkte

📌 Mueller’s Findings: Why DOJ Non-Disclosure Policy and Grand Jury Secrecy May Not Apply


📈 22.16 Punkte

📌 How Secrecy Undermines Mueller and the Defense of Democracy


📈 22.16 Punkte











matomo