Actually, since the CAC is a deterministic function of the BD_ADDR, we can exhaustively search all possible mappings (in a matter of seconds); therefore, and since the CAC is transmitted in each message, you can determine (with a very high probability) the BD_ADDR of a device you are eavesdropping on.
Actually, since the CAC is a deterministic function of the BD_ADDR, we can exhaustively search all possible mappings (in a matter of seconds); therefore, and since the CAC is transmitted in each message, you can determine (with a very high probability) the BD_ADDR of a device you are eavesdropping on.
Cheers,
Markus
http://www.markus-jakobsson.com