Live data from Hacker News

Bluetooth keystroke-injection in Android, Linux, macOS and iOS

github.com

1–10 of 265 posts

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#5

Oh snap, here we go again, convenience vs security, zero sum game.

Maybe lazy convenience vs security? Apple has a rather nice, convenient way to pair a keyboard that ought to resist unauthenticated injection.

The issues here appear to just be bugs.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#6
post #4

Well iOS and macOS are only vulnerable in a very narrow range of conditions. On the other hand Android is a field day. And I believe these were patched in the current versions of iOS and macOS.

I read the original article to find the narrow range of conditions. It states "iOS and macOS are vulnerable when Bluetooth is enabled and a Magic Keyboard has been paired with the phone or computer" so does this mean if a computer has ever paired with a Magic Keyboard, it would allow itself to be paired with additional keyboards that the user did not want to pair?

As someone who has bought multiple Magic Keyboards, this definitely concerns me.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#7
post #5

Oh snap, here we go again, convenience vs security, zero sum game.

Maybe lazy convenience vs security? Apple has a rather nice, convenient way to pair a keyboard that ought to resist unauthenticated injection. The issues here appear to just be bugs.

According to the write-up, the vulnerability itself was fixed years ago in BlueZ, but left disabled by default for compatibility. I'm not sure about the macOS vulnerability, but at least on the Linux side, usability beat security.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#9
Honestly, I'm not surprised. Bluetooth is an unsecured microcontroller that does not run an open source firmware (and yes, I'm aware, the CVE is partially enabled by the software stack as well). By definition, that is a security nightmare.

I don't generally use Bluetooth devices in my house. Between the security nightmare aspect and the fact that it's always a worse end user experience than just going wired (no dropped packets, no failure to pair after being paired fine for months, no batteries slowly dying and then becoming spicy pillows; just 100% pure glorious wire).

Post reply on HN