Live data from Hacker News

Bluetooth keystroke-injection in Android, Linux, macOS and iOS

github.com

31–40 of 265 posts

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#31
post #11
post #6

Earlier quoted context omitted.

I read the original article to find the narrow range of conditions. It states "iOS and macOS are vulnerable when Bluetooth is enabled and a Magic Keyboard has been paired with the phone or computer" so does this mean if a computer has ever paired with a Magic Keyboard, it would allow itself to be paired with additional keyboards that the user did not want to pair? As someone who has bought multiple Magic Keyboards, t…

I’m sort of assuming the Magic Keyboard has to be present, but we don’t know that based on the write up. It’s a great question though. All desktop Macs come pre-paired with a Magic Keyboard even if you never use it. so if the keyboard doesn’t have to be actively connected at the time that would make them all vulnerable unless someone had unpaired them. The other thing that wasn’t clear to me is if the vulnerability e…

Apple's "Magic Keyboard" is supposed to exchange Bluetooth keys with a MacOS host over its USB/Lightning cable the first time it gets plugged in.

Perhaps default pairing is left open to allow smoother pairing with iOS/iPadOS, as pairing otherwise would have required a cable with Lightning connector in both ends — which I don't think exists.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#32
post #27
post #20

Earlier quoted context omitted.

Doesn't Android Auto carry audio over Bluetooth? That would be consistent with how unreliable the audio is.

I don't know. What's the wire for? Needing both the USB cable and Bluetooth has always struck me as pretty dumb.

The bluetooth connection is for phone calls. The rest of functionality works over the wire. As for the why does it need bluetooth at all, no idea.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#33
post #9

Honestly, I'm not surprised. Bluetooth is an unsecured microcontroller that does not run an open source firmware (and yes, I'm aware, the CVE is partially enabled by the software stack as well). By definition, that is a security nightmare. I don't generally use Bluetooth devices in my house. Between the security nightmare aspect and the fact that it's always a worse end user experience than just going wired (no dropp…

Wireless keyboard generally seem like a totally terrible idea, just waiting for hacks. The author mentions not going after wireless gaming keyboards because they were the “wrong kind of mess,” I assume, security through abstrusity :)

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#35
post #20
post #12

Earlier quoted context omitted.

For some reason Bluetooth has to be enabled for Android Auto to work, even though it's wired, so I leave it enabled. But there should be a way to just disable keyboards categorically, for phones.

Doesn't Android Auto carry audio over Bluetooth? That would be consistent with how unreliable the audio is.

Hey don’t knock it until you’ve tried Apple’s equivalent (wireless CarPlay) which has a 3 second buffer since they decided to use Wi-Fi for audio. Imagine if every time you play or pause or change tracks you have to count to three in your head before it responds.

Yes, I’m bitter. Somehow the video and touch are lag-free 1 but the audio is on a delay. I’d love to have regular Bluetooth audio be used.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#39

>Once the attacker has paired with the target phone or computer A small detail, though, the target device has to accept the connection. Once someone lets you in his house, you can steal his silver, yes.

Yes, i am reading the title which says 'Bluetooth keystroke-injection' which is concerning on one level, but in fact the article talks about authenticating a device without user interaction which seems way more serious to me.

however, it also mentions > stay tuned for Part 2: More Vulnerabilities

so I guess we'll see

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#40

>Once the attacker has paired with the target phone or computer A small detail, though, the target device has to accept the connection. Once someone lets you in his house, you can steal his silver, yes.

How in the world is this a CVSS 8.8 if this is the case? What a waste of everyone's time if this is true.
Post reply on HN