Slashdot Mirror


Nokia Admits Multiple Bluetooth Security Holes

An anonymous reader writes "Nokia has admitted that four of its handsets (6310, 6310i, 8910 and 8910i) have multiple security vulnerabilities that can allow an attacker to read, edit and copy the contacts and calendar entries using Bluetooth. This admission comes after a ZDNet UK article published earlier today. the spokesperson advises customers to switch off Bluetooth in public places!" For more information, see the bluesnarfing site pointed out by reader profet.

16 of 136 comments (clear)

  1. No big deal by cwernli · · Score: 4, Insightful

    What's happening with Bluetooth happened with wireless networks.

    What happened with wireless networks happened with anonymous ftp servers.

    What happened with anon ftp servers happened with telnet access (you remember the "guest" login provided by most hosts ?).

    Every time a new technology is used there are some flaws with it. No big deal.

    1. Re:No big deal by pesc · · Score: 5, Insightful

      What's happening with Bluetooth happened with wireless networks.
      What happened with wireless networks happened with anonymous ftp servers.
      What happened with anon ftp servers happened with telnet access (you remember the "guest" login provided by most hosts ?).
      Every time a new technology is used there are some flaws with it. No big deal.


      BIG DEAL!

      You could expect that someone that designs a new communication protocol today builds on past experience. It's not like viruses, spam, malware and and crackers are something unknown. Instead, you should make the security requirements absolutely central in your new protocols. With the bluetooth technology becoming the most widespread wireless communications protocol (if you believe its proponents) not having security as a top priority is absofuckinglutely brainlessly idiotical.

      --

      )9TSS
    2. Re:No big deal by infiniti99 · · Score: 5, Insightful

      Just to clarify, this article is about a problem in Nokia's implementation of Bluetooth, not necessarily a problem in the actual Bluetooth protocol/specification. As an analogy, we hear about security holes in IIS, Apache, OpenSSL, etc, but these do not necessarily indicate problems in the relevant RFC documents. At least, we can hope so ...

  2. Is Bluetooth upgradeable? by Anonymous Coward · · Score: 2, Insightful

    Is Bluetooth upgradeable and How?

    1. Re:Is Bluetooth upgradeable? by DJPenguin · · Score: 4, Insightful

      I had the firmware upgraded on my 6310i to resolve some bluetooth connection issues, and I imagine the whole stack is upgradeable in this manner.

      I don't think the bluetooth protocol is broken - just the implementation.

    2. Re:Is Bluetooth upgradeable? by marcello_dl · · Score: 2, Insightful

      Saying it all worked well for you doesn't mean it always work.

      Always do backups before firmware updates!

      --
      ---- MISSING MISCELLANEOUS DATA SEGMENT --- [sigdash] trolololol
  3. Social science wonder? by orzetto · · Score: 5, Insightful

    These days we have all possible material about encryption available publicly. We have RSA, we have digital signatures, we have freely available software which can create perfectly encrypted material which would give bad headaches to the NSA if they had to crack it, even I can encode anything with gpg.
    Yet, a mobile-phone giant does this. Are they just plain stupid, or is this another example of the wonders of social science? I can't help thinking how intelligent an ant nest can be though ants singularly are so stupid, and how an organization with some of the brightest engineers on the planet can act so carelessly.

    --
    Victims of 9/11: <3000. Traffic in the US: >30,000/y
    1. Re:Social science wonder? by Dogers · · Score: 2, Insightful

      stupid, definitely stupid.. look at the NGage, 3200, 7200, 7600, 7700 - Nokia are losing their marbles rapidly!

      They havent even got a fully functional 3G phone yet..

      Its that evil virus, whats it called again? Oh yeah, mismanagement.

      --
      I am a viral sig. Please copy me and help me spread. Thank you.
    2. Re:Social science wonder? by c13v3rm0nk3y · · Score: 2, Insightful

      The problem with any encryption method is that it reduces (to some extent) convenience. Since convenience is the keyword mobile phone manufacturers depend on to sell their products, and any level of extra "complexity" is seen as a hindrance.

      The mobile phone market is so tight that any possible hindrance (whether it is reasonable or not) is seen as a liability to sales.

      Well, that and featching creeperism: Hey, we said we wanted Bluetooth phones. Nokia, et al, just gave them to us. We didn't say we wanted safe or well-designed Bluetooth phones, did we? Outside of a few troublemakers (like us), the market is perfectly happy with what it has been getting so far.

      Security needs to be designed into products, and we are still getting prototypes out the door and tacking on security as it the last consideration, or adding features w/o considering the security implications.

      Ain't capitalism great?

      --
      -- clvrmnky
  4. Turn it off! by SpinyManiac · · Score: 2, Insightful

    If you turn Bluetooth off, your're invulnerable and your batteries will last longer.

    --
    It's never too late to have a happy childhood.
  5. Re:K.I.S.S by OlivierB · · Score: 2, Insightful

    Think about the damages on windows PCs. Users are advised to keep their machines up to date and yet a significant proportion of them do not listen (want proof? Mydoom is now in version C and still taking hits at MSFTs website). Now how many of you have updated your phones firmware? Think about all those non PDA phones which don't come with a PC connection Kit. All these Nokia phones WILL remain vulnerable for as long as they will work because hardly anybody hassles to go in a Nokia centre to upgrade their firmware. I stand by my original statement. Commodity electronics are not meant to be upgraded as computers and users will not give them that kind of attention. With the advent of GPRS and other always on Data connection, be prepared for some more trouble as people hack into your phone from miles away. No need to be in bluetooth range.

    --
    Artificial intelligence is no match for natural stupidity
  6. Solution: Employ Hackers by Channard · · Score: 2, Insightful

    Some companies already do, I'd imagine, but surely the solution would be to employ - and pay decently - people who've highlighted vulnerabilities in previous products/systems to go at phones/etc like the clappers, trying to find any vulnerabilities. Granted, few products are going to be 100% secure but surely it'd be better than holes like this cropping up.

  7. Re:K.I.S.S by little_fluffy_clouds · · Score: 4, Insightful

    Think about the damages on windows PCs. Users are advised to keep their machines up to date and yet a significant proportion of them do not listen (want proof? Mydoom is now in version C and still taking hits at MSFTs website).

    Your comparison with "their machines" and the phone firmware (essentially this is the phone "OS"), makes me think you believe that Windows Update can defeat MyDoom.

    Actually, MyDoom has fuck all to do with keeping your Windows PC up to date. It is about keeping your _virus_ scanning up to date, and not running attachments that make it through to you. I could have just run and completed Windows Update, but still be infected with MyDoom via the very next email I received and (stupidly) ran the attachment of. Remember, virus scanning is NOT part of the Windows OS, it is something that must be loaded and configured and paid for (usually, unless you go with grisoft or similar).

    Your point would be a lot better made if you referred to something like the Blaster or Nachi worm, where the fix was available via Windows Update for several weeks.

    --
    What were the skies like when you were young?
  8. Wireless is inherently insecure by ajs318 · · Score: 1, Insightful

    I'm glad I still have my old 3210. As long as it continues to make a noise when someone dials it and transmit my voice and their voice in mutually opposite directions when answered, then I have no reason to replace it.

    When you're sending data over the air, then you have no way of knowing who is listening. That's why my home LAN is wired -- so I at least know if anyone is tapping me, then they must be on the inside. And I wouldn't trust the phone companies to build in any kind of security either; MI5 would never let them get away with it. You should assume any part of the network you can't see is tappable if not actually tapped. The best form of telephone security is to keep all messages short and hope they aren't listening when you're speaking.

    --
    Je fume. Tu fumes. Nous fûmes!
  9. Re:Unbelievable by ebbe11 · · Score: 4, Insightful
    I can't believe this, a company as big as Nokia making mistake as stupid as this ?

    I can. The mobile phone manufactures in general and Nokia in particular is very much focused on time-to-market. That means that their phones are not always finished when they hit the shelves. To be fair, neither was my Ericsson R520m phone when I first got it.

    --

    My opinion? See above.
  10. Re:K.I.S.S by Anonymous Coward · · Score: 2, Insightful
    > Phones are tools. We don't "need" them to be fully featured akin a full OS.

    That's as foolish as saying that PCs are just tools. They're for wordprocessing, administration and some games. That's how it was when I got my first PC. Why go connect with other computers, with all those evil hackers and expose your PC with your sensitive data? Why play and record music on your computer when you have specialized devices like CD-players and tape recorders? Because more features are better.

    Within ten years, phones will become always-carry-with-you wearable mini-PCs. As long as you have your phone with you, you also carry a camera, music/movie player, voice recorder, calender, notebook, game console, ebook reader, remote control, flashlight, and lots of other stuff. Sure, the interface could get a lot better, battery life still sucks now, etc. But we will get there eventually. Not too long ago, people thought 256-colors 320x200 was fantastic quality on a home computer.

    There is no line to cross for a phone to have a "full OS". The OS in your phone today is already more complex than my early home computers.