COSIC Seminar on WhisperPair: "One Tap to Hijack Them All:..." (Nikola Antonijević & Seppe Wyns)
COSIC Seminar - One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair Protocol - Nikola Antonijević (COSIC) + Seppe Wyns (DistriNet) WhisperPair attack: https://whisperpair.eu/ Google’s Fast Pair Service (GFPS) extends Bluetooth pairing with one-tap setup and account synchronisation. This paper presents the first comprehensive security analysis of GFPS. By examining 25 commercial accessories from 16 vendors across 17 unique Bluetooth chipsets, we uncover systemic enforcement failures of the specification’s core security requirements. Moreover, we show that the security failures we have identified in the pairing protocol can be further cascaded, amplifying their impact across the device ecosystem. Although GFPS and Google’s Find Hub network are often treated as distinct services within the broader Google ecosystem, we show that failures in one can produce severe consequences in the other. We demonstrate WhisperPair, a family of practical attacks that enables unauthorised pairing, silent hijacking of audio devices, and covert account binding that registers a victim’s accessory to an attacker’s account, thereby enabling persistent location tracking and stalking via Google Find Hub. These vulnerabilities are not isolated incidents but symptoms of systemic, ecosystem-wide gaps in implementation, validation, and certification. Our analysis exposes that the source of these flaws lies in GFPS’s reliance on fallible, application-layer state checks rather than on cryptographic enforcement, allowing them to propagate across vendors to the end users. To address the root cause, we propose IntentPair, a lightweight protocol modification that cryptographically binds the user’s pairing intent into the key schedule, eliminating the vulnerability by design. Our findings show how a small usability “add-on” can introduce large-scale security and privacy risks for hundreds of millions of users.

COSIC Seminar "Identity-Privacy Paradox: How to Identify Friend or Foe...?" ( Ema Šujster, TU Delft)

PQCSA Post-Quantum Cryptographic Protocols - PQC & the Quantum Threat Landscape (Bart Preneel)

Lidia Giuliano - The Accidental Security Architect (and why that needs to change)

COSIC Seminar "Multi-Verifier Keyed-Verification Anonymous Credentials" (Omid Mirzamohammadi, COSIC)

PQCSA Post-Quantum Cryptographic Protocols - Migrating Protocols to PQ... (Thom Wiggers, PQ Shield)

Tom Chothia, "Formal Verification of EMV Payments", VeTSS Annual Conference 2026
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Is This DIY EMP Device Actually Dangerous?

Attacking AI - Jason Haddix - NDC Security 2026

Palantir and Switzerland – Between Data and Power | Reporter | SRF

Telecom Insider Explains What Your Carrier Actually Sees (Cape Interview)

How ASML Makes Chips Faster With Its New $400 Million High NA Machine

Your Headphones Can Be Hacked Easily

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Passkeys Explained: Are They Actually Better Than Passwords?

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

Your Bluetooth devices Are Vulnerable (WhisperPair Attack) #whisperpair,

COSIC Seminar "Attacks and Remedies for Randomness in AI: Cryptanalysis..." (Yevhen Perehuda, RUB)

What Google Is Really Doing With Your Data (DuckDuckGo Interview)

