Full-band De-anonymization of Bluetooth Classic Devices
Even Black Cats Cannot Stay Hidden in the Dark: Full-band De-anonymization of Bluetooth Classic Devices—Marco Cominelli, Francesco Gringoli, Margus Lind, Paul Patras, Guevara Noubir Bluetooth Classic (BT) remains the de facto connectivity technology in car stereo systems, wireless headsets, laptops, and a plethora of wearables, especially for applications that require high data rates, such as audio streaming, voice calling, tethering, etc. Unlike in Bluetooth Low Energy (BLE), where address randomization is a feature available to manufactures, BT addresses are not randomized because they are largely believed to be immune to tracking attacks. We analyze the design of BT and devise a robust de-anonymization technique that hinges on the apparently benign information leaking from frame encoding, to infer a piconet’s clock, hopping sequence, and ultimately the Upper Address Part (UAP) of the master device’s physical address, which are never exchanged in clear. Used together with the Lower Address Part (LAP), which is present in all frames transmitted, this enables tracking of the piconet master, thereby debunking the privacy guarantees of BT. We validate this attack by developing the first Software-defined Radio (SDR) based sniffer that allows full BT spectrum analysis (79 MHz) and implements the proposed de-anonymization technique. We study the feasibility of privacy attacks with multiple testbeds, considering different numbers of devices, traffic regimes, and communication ranges. We demonstrate that it is possible to track BT devices up to 85 meters from the sniffer, and achieve more than 80% device identification accuracy within less than 1 second of sniffing and 100% detection within less than 4 seconds. Lastly, we study the identified privacy attack in the wild, capturing BT traffic at a road junction over 5 days, demonstrating that our system can re-identify hundreds of users and infer their commuting patterns.

BIAS: Bluetooth Impersonation AttackS

$20K BLE Sniffer in Action: Demystifying Advertising Packets Like a Pro!

Ellisys Bluetooth Video 9: Bluetooth 5 & IoT

Understanding Bluetooth Low Energy (BLE) - Theoretical Overview

Something is jamming GPS over Europe. Here's what we found

BREAKING: Trump’s Epstein problem returns with blockbuster testimony

Why The Russian Accent Terrifies Everyone

The Insane Genius of a Formula 1 Gearbox

But what is quantum computing? (Grover's Algorithm)

SSP 2020 Opening Remarks

Trump Ruins NBA Finals Vibes, Crashes Out on Meet the Press After CA Election Lies: A Closer Look

My Thoughts On The Fender Controversy

I Hacked This Temu Router. What I Found Should Be Illegal.

Ellisys Bluetooth Video 7: Security Part 1

World Cup COLLAPSES DAYS BEFORE KICK OFF!

DIY Bluetooth Low Energy (BLE) Sniffing: Debug Your Projects Like a Pro!

TOP 5 Software Defined Radio Receivers

Ellisys Bluetooth Video #14: Bluetooth Direction Finding

My Golden Retriever Heals a Terrified Rescue Kitten in Just 3 Meetings!

