Live data from Hacker News

What your Bluetooth devices reveal

blog.dmcc.io

161–170 of 204 posts

Re: What your Bluetooth devices reveal

#161
post #95
post #16

Earlier quoted context omitted.

There’s a middle ground here. There is no technical reason a pacemaker constantly broadcasts itself - there is ways to allow communication to such devices without yelling your name all the time. And there is definitely no reason for such a name to be a unique identifier.

There are technical reasons, though. Let's suppose we have a pacemaker, and it has data that is beneficial to read -- maybe even in real-time on their pocket computer, or opportunistically as the patient walks by their reader-device, or however that is done. So we want this data, and we want it over RF. It probably seems obvious that it should only transmit when it is told to do so, right? So how do we tell the pacem…

> In terms of power, it's often less costly to intermittently transmit a string of data than to continuously operate a radio receiver.

The fair comparison would be intermittently transmitting a string of data versus intermittently operating a radio receiver, wouldn't it?

Maybe it's still less costly to transmit, that I don't know. But I am interested about it :-).

> And maybe it's a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway.

This part resonates more with me.

Re: What your Bluetooth devices reveal

#162
post #2

Tangential, sort of: in the early days of mobile phones for the masses, when there was no WiFi/3G in the underground, I will often enable Bluetooth in my phone, look for nearby devices and try to match names and looks. That was before everyone had their "John's IPhone" or "Samsung A55" boring names everywhere and some of us cared to personalise our device's name. Anyone else played this game?

When I set up my iPhone and it asked who's iPhone it is, I thought it would be funny to put in Kim Jong Un. Now it shows up as "Kim Jong Un's iPhone" when I enable my hotspot. Or even better, it says it out loud when I connect to some Bluetooth speakers.

Re: What your Bluetooth devices reveal

#163

Introducing the „are they home“ device to assist burglars. Just slap that miniature device somewhere non-suspicious on the place of your potential marks and let it run for the battery life of 7 days. Afterwards you collect it and know movements patterns. Features automatic notifications if no movement detected for more than two days.

To be fair, that's basically a variation of techniques that have existed long before Bluetooth

I don't disagree, nothing new to see here. I just thought that this would be a nifty device to sell via nefarious shops. Include some more passive tracking of WiFi and bob's your uncle. Maybe add mesh functionality via LoRaWAN and track the whole neighborhood.

Re: What your Bluetooth devices reveal

#165

Earlier quoted context omitted.

It’s actually even easier, your car has a plate on the front with a unique ID that a camera scans, often to automatically track your park time for ticketing. I can’t really care about obscure Bluetooth tracking when every business has CCTV doing facial recognition.

Yeah exactly, with a car I would no longer be expecting any type of privacy, sadly. Here in Holland we must even have a mobile phone module in every car so it can call the emergencies in case of a crash.

I'm in two minds about this. Yes, there are severe privacy implications.

But also this happened, just a couple of hour's drive from where I live, about ten years ago:

https://www.bbc.co.uk/news/uk-scotland-tayside-central-33505...

and similar things have happened about once a year ever since. Now in the news article I linked to a huge part of the problem was that the police didn't follow it up correctly, went to where the accident had been reported rather than where it had occurred, didn't see anything, and then gave up.

But if the car had rung from where it had actually crashed then the incident would have EISEC[1] data tagged to it, which would have given them actual co-ordinates to hit.

[1] https://www.derbyshire.police.uk/SysSiteAssets/foi-media/der... (first hit on google)

Re: What your Bluetooth devices reveal

#166
Parisians Métro 's ads screen are equiped with BT scanner, with a hidden sticker on the side to link you with a qrcode to a RGPD output website, where you have to log your private data to register your devices to be not scanned...

What a world to be alive..

Re: What your Bluetooth devices reveal

#168
post #78
post #9

> We’ve normalised the idea that Bluetooth is always on. Phones, laptops, smartwatches, headphones, cars, and even medical devices constantly broadcast their presence. The standard response to privacy concerns is usually “nothing to hide, nothing to fear.” I guess anything you send out can be used to profile you. Some of my friends live on a farm near a semi busy road, however far enough from other farms to not be ab…

You can do this for much cheaper - all four of your tires are broadcasting a unique ID to report tire pressure, the radio to pick it up is cheap (because cars), and TPMS has no facility to randomize or otherwise secure this.

I believe that every morning someone in the tech industry wakes up and devises a new place to cram some sort of radio. And it's appealing enough the the unwashed masses such that it becomes widely adopted and then unavoidable. I don't want TPMS in my tires. It's not as if checking tire pressure is difficult. No one will consider moving away from TPMS. You'll only hear technologists say "yes, but we could improve the standard! Perhaps encrypt it." They only know how to solve technological problems with more technology.

Re: What your Bluetooth devices reveal

#170
post #78

Earlier quoted context omitted.

You can do this for much cheaper - all four of your tires are broadcasting a unique ID to report tire pressure, the radio to pick it up is cheap (because cars), and TPMS has no facility to randomize or otherwise secure this.

It’s actually even easier, your car has a plate on the front with a unique ID that a camera scans, often to automatically track your park time for ticketing. I can’t really care about obscure Bluetooth tracking when every business has CCTV doing facial recognition.

The plate is pretty trivial to fake though. For one thing you can just remove it, but it's trivial to alter with just spray paint. Or using an outdated plate, or someone else's plate, etc. it's identifying sort of how an phone number is supposed to be identifying: nominal, but not secure and trivially abused for fraud
Post reply on HN