<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bluetooth on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/bluetooth/</link>
    <description>Recent content in Bluetooth on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/bluetooth/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your Android Bluetooth Traffic Captures Should Be Live</title>
      <link>https://insinuator.net/2026/07/your-android-bluetooth-traffic-captures-should-be-live/</link>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/07/your-android-bluetooth-traffic-captures-should-be-live/</guid>
      <description>&lt;p&gt;In this post I want to talk about a very essential part of my workflow when dealing with Bluetooth devices, particularly IoT devices with a corresponding mobile app: Live capture of Android Bluetooth traffic with Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;Before you stop reading because you think you know how to do this already, the method does not involve pulling bug reports off your phone, and it does not require root. And most importantly it gives you a &lt;strong&gt;live&lt;/strong&gt; packet log in Wireshark.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking a Bluetooth Printer Server: GATT to UART Adapter?</title>
      <link>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</link>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</guid>
      <description>&lt;p&gt;This blog post describes the journey of how we discovered an interesting&#xA;Bluetooth SoC within the Datong NP330, a&#xA;&lt;a href=&#34;https://www.dtprinter.cn/upload/doc/NP330_NP332UserManual_en.pdf&#34;&gt;Printer Server IoT device&lt;/a&gt;.&#xA;Our initial goal was to reverse-engineer and analyze the Bluetooth controller&#xA;that is included in the device. So we wanted to be able to dump the firmware or,&#xA;if possible, get shell access on the printer server. During that journey we&#xA;found a few vulnerabilities that ultimately let an attacker fully compromise the&#xA;device. This is possible over Bluetooth or network via unauthenticated remote&#xA;code execution with root privileges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Airoha-based Bluetooth Headphones and Earbuds</title>
      <link>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</link>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Important note:&lt;/strong&gt; Some media coverage on this topic falsely or inaccurately&#xA;depicts the attack conditions. To be clear: Any vulnerable device can be&#xA;compromised if the attacker is in Bluetooth range. That is the only&#xA;precondition.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;During our research on Bluetooth headphones and earbuds, we identified several&#xA;vulnerabilities in devices that incorporate Airoha Systems on a Chip (SoCs). In&#xA;this blog post, we briefly want to describe the vulnerabilities, point out their&#xA;impact and provide some context to currently running patch delivery processes as&#xA;described at this year’s&#xA;&lt;a href=&#34;https://troopers.de/troopers25/talks/fbnb8y/&#34;&gt;TROOPERS Conference&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using the Raspberry Pi Pico W as a Bluetooth Dongle</title>
      <link>https://insinuator.net/2025/06/using-the-raspberry-pi-pico-w-as-a-bluetooth-dongle/</link>
      <pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/using-the-raspberry-pi-pico-w-as-a-bluetooth-dongle/</guid>
      <description>&lt;p&gt;During our recent research, we experimented with different Bluetooth USB&#xA;dongles. There are tons of options, and sometimes, it’s challenging to determine&#xA;what chipset a dongle actually contains, what Bluetooth features it supports,&#xA;and whether it works on Linux. Inspired by the recent&#xA;&lt;a href=&#34;https://www.tarlogic.com/blog/esp32-hidden-hci-vendor-commands/&#34;&gt;ESP32 Bluetooth research&lt;/a&gt;,&#xA;we wondered whether we could turn our Raspberry Pi Pico Ws into a functioning&#xA;Bluetooth dongle. We had a few lying around, and the advantage here is that we&#xA;know exactly which&#xA;&lt;a href=&#34;https://www.raspberrypi.com/documentation/microcontrollers/pico-series.html&#34;&gt;Bluetooth controller it uses&lt;/a&gt;&#xA;– the Infineon CYW43439. It’s also very easy to get one. You can just buy the&#xA;Pico W for a few bucks, even cheaper than some Bluetooth dongles. You also have&#xA;a controller family that has been researched quite a bit in the&#xA;&lt;a href=&#34;https://github.com/seemoo-lab/internalblue/&#34;&gt;internalblue project&lt;/a&gt;. However,&#xA;there was one disadvantage. We did not find any code that exposes the CYW43439’s&#xA;HCI interface via USB. So we had to write that on our own.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2025-20908: Use of insufficiently random values in Samsung&#39;s Auracast implementation</title>
      <link>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</link>
      <pubDate>Thu, 13 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</guid>
      <description>&lt;p&gt;As part of our &lt;a href=&#34;https://insinuator.net/2025/01/auracast-part1/&#34;&gt;research&lt;/a&gt; into&#xA;the Auracast feature set in Bluetooth, we also started looking into vendor&#xA;implementations. At the time we started with our research, there weren’t a lot&#xA;of products on the market yet. But new products are coming out pretty frequently&#xA;now.&lt;/p&gt;&#xA;&lt;p&gt;One of the vendors that had Auracast implemented pretty early was Samsung. At&#xA;the time the Samsung Galaxy S23 and S24 phones were able to broadcast Audio,&#xA;while the Galaxy Buds were able to join these broadcasts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Part I: Bluetooth Auracast from a Security Researcher’s Perspective</title>
      <link>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</link>
      <pubDate>Mon, 27 Jan 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</guid>
      <description>&lt;p&gt;Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity&#xA;in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to&#xA;the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to&#xA;implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a&#xA;potentially unlimited number of devices. It does not require pairing or&#xA;interaction between the sender and the receivers.&lt;/p&gt;&#xA;&lt;p&gt;We also presented this topic&#xA;&lt;a href=&#34;https://media.ccc.de/v/38c3-auracast-breaking-broadcast-le-audio-before-it-hits-the-shelves&#34;&gt;at 38c3&lt;/a&gt;.&#xA;This blog post will contain similar contents albeit with some more details.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Change Your BLE Passkey Like You Change Your Underwear</title>
      <link>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</link>
      <pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</guid>
      <description>&lt;p&gt;Using a static passkey for Bluetooth Low Energy pairing is insecure. Recent&#xA;versions of the Bluetooth specification contain an explicit warning about this.&#xA;However, in practice, we often see static passkeys being used. Moreover, there&#xA;are no public implementations of proofs-of-concept that can practically show why&#xA;using a static passkey is an issue. This is why we implemented one.&lt;/p&gt;&#xA;&lt;p&gt;In a recent assessment, we were testing a device that offered a Bluetooth&#xA;interface for data export and configuration. This device uses Bluetooth Low&#xA;Energy (BLE), and a static passkey (or PIN) is required to pair with it. This&#xA;passkey is displayed for a few seconds when the device is booted and stays the&#xA;same on each reboot. In fact, it is derived from static, device-specific data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2020-0022 an Android 8.0-9.0 Bluetooth Zero-Click RCE – BlueFrag</title>
      <link>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</link>
      <pubDate>Wed, 22 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</guid>
      <description>&lt;p&gt;Nowadays, Bluetooth is an integral part of mobile devices. Smartphones interconnect with smartwatches and wireless headphones. By default, most devices are configured to accept Bluetooth connections from any&lt;br&gt;&#xA;nearby unauthenticated device. Bluetooth packets are processed by the Bluetooth chip (also called a controller), and then passed to the host (Android, Linux, etc.). Both, the firmware on the chip and the host Bluetooth subsystem, are a target for Remote Code Execution (RCE) attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag</title>
      <link>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</guid>
      <description>&lt;p&gt;On November 3rd, 2019, we have reported a critical vulnerability affecting the Android Bluetooth subsystem. This vulnerability has been assigned &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0022&#34;&gt;CVE-2020-0022&lt;/a&gt; and was now patched in the &lt;a href=&#34;https://source.android.com/security/bulletin/2020-02-01.html&#34;&gt;latest security patch&lt;/a&gt; from February 2020. The security impact is as follows:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;On Android 8.0 to 9.0, a remote attacker within proximity can silently execute arbitrary code with the privileges of the Bluetooth daemon as long as Bluetooth is enabled. No user interaction is required and only the Bluetooth MAC address of the target devices has to be known. For some devices, the Bluetooth MAC address can be deduced from the WiFi MAC address. This vulnerability can lead to theft of personal data and could potentially be used to spread malware (Short-Distance Worm).&lt;/li&gt;&#xA;&lt;li&gt;On Android 10, this vulnerability is not exploitable for technical reasons and only results in a crash of the Bluetooth daemon.&lt;/li&gt;&#xA;&lt;li&gt;Android versions even older than 8.0 might also be affected but we have not evaluated the impact.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Users are strongly advised to install the latest available security patch from February 2020. If you have no patch available yet or your device is not supported anymore, you can try to mitigate the impact by some generic behavior rules:&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</link>
      <pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;microsoft-it-secure-journey-to-ipv6-only&#34;&gt;Microsoft IT (Secure) Journey to IPv6-Only&lt;/h1&gt;&#xA;&lt;p&gt;Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)&lt;/p&gt;&#xA;&lt;p&gt;The speaker, Veronika McKillop, working at Microsofts network infrastructure services, has given a talk about the process of switching a company network from IPv4 to IPv6-only.&lt;/p&gt;&#xA;&lt;p&gt;Within the talk the following topics were introduced: Dual Stack, Drivers for IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers the reasons why a company would like to switch from IPv4 to IPv6. Technics like NAT64 and DNS64 are introduced. The requirements to software and especially drivers to work in IPv6 environments are described. Also the problems to switch from IPv4 to IPv6-only in heterogeneous networks are addressed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Bluetooth. Part 2</title>
      <link>https://insinuator.net/2016/12/research-diary-bluetooth.-part-2/</link>
      <pubDate>Wed, 07 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/research-diary-bluetooth.-part-2/</guid>
      <description>&lt;p&gt;Recently we posted &lt;a href=&#34;https://insinuator.net/2016/11/research-diary-bluetooth/&#34;&gt;first part&lt;/a&gt; of our Bluetooth research diary. Today, we want to continue on that topic and tell you about Bluetooth proxying and packet replay with a new tool.&lt;/p&gt;&#xA;&lt;p&gt;This time we had a new gadget to play with: our colleague Florian Grunow shared with us a curious IoT device – Bluetooth socks… real socks that you control with an app to heat your feet. The future is here… 😉&lt;br&gt;&#xA;&lt;img src=&#34;IMG_20161129_095613.jpg&#34; alt=&#34;img_20161129_095613&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Bluetooth</title>
      <link>https://insinuator.net/2016/11/research-diary-bluetooth/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-bluetooth/</guid>
      <description>&lt;p&gt;As you probably know we perform research on a regular base at ERNW.&lt;/p&gt;&#xA;&lt;p&gt;We – Olga and Rafael – started with a research project about Bluetooth. Our first goal was to gain some knowledge about the tools used by most Linux systems to communicate with Bluetooth hardware, such as BlueZ. A good help for that was the amazing Bluetooth hacking workshop we had before (check &lt;a href=&#34;https://www.insinuator.net/2016/09/hardware-hacking-week-ernw/&#34;&gt;the link&lt;/a&gt; in our blog!)&lt;/p&gt;&#xA;&lt;p&gt;To get a better understanding of the tools you need some Bluetooth hardware to interact with.&lt;br&gt;&#xA;The hardware we used for our research so far are the very cool TexasInstruments SimpleLink™ Bluetooth low energy/Multi-standard SensorTag (CC2650STK) and a Fitness Wristband found at home.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hardware Hacking Week @ ERNW</title>
      <link>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</link>
      <pubDate>Fri, 09 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</guid>
      <description>&lt;p&gt;Internal workshops are one of the reoccurring events at ERNW, that help us to gain knowledge in areas outside our usual expertise. One of the recent workshops which happened during the week from August 22nd-25th was Hardware Hacking. Held by Brian Butterly (&lt;a href=&#34;https://twitter.com/BadgeWizard&#34;&gt;@BadgeWizard&lt;/a&gt;) and Dominic Spill &lt;a href=&#34;http://@dominicgs&#34;&gt;(@dominicgs),&lt;/a&gt; this workshop took place in two parts. Brian kickstarted the introductory session by guiding us through the fundamental steps of Hardware Hacking. Brian did an excellent job of making things simpler by giving a detailed explanation on the basic concepts. For a beginner in hardware hacking, the topic could be rather intimidating if not handled properly.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Safe is Smart?</title>
      <link>https://insinuator.net/2011/12/how-safe-is-smart/</link>
      <pubDate>Thu, 22 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/how-safe-is-smart/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/12/bt_smart_ready.jpg&#34; alt=&#34;Bluetooth Smart Ready Logo&#34; title=&#34;Bluetooth Smart Ready&#34;&gt;About two months ago the Bluetooth SIG &lt;a href=&#34;http://www.bluetooth.com/Pages/Press-Releases-Detail.aspx?ItemID=138%20&#34;&gt;renamed their latest standard&lt;/a&gt;, which was previously known as “Bluetooth v4.0”. When version numbers get higher and higher marketing likes to interfere and try something new. In this case: Bluetooth Smart.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sounds-smart-but-is-it&#34;&gt;Sounds smart, but is it?&lt;/h2&gt;&#xA;&lt;p&gt;Without getting into too much detail, let me quickly quote Wikipedia to get started:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt; &lt;em&gt;“Cost-reduced single-mode chips, which enable &lt;strong&gt;highly integrated&lt;/strong&gt; and &lt;strong&gt;compact&lt;/strong&gt; devices, feature a &lt;strong&gt;lightweight&lt;/strong&gt; Link Layer providing &lt;strong&gt;ultra-low power&lt;/strong&gt; idle mode operation, &lt;strong&gt;simple&lt;/strong&gt; device discovery, and &lt;strong&gt;reliable&lt;/strong&gt; point-to-multipoint data transfer with &lt;strong&gt;advanced power-save&lt;/strong&gt; and &lt;strong&gt;secure encrypted&lt;/strong&gt; connections at the &lt;strong&gt;lowest possible cost&lt;/strong&gt;.”&lt;/em&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
