Live data from Hacker News

Bluetooth keystroke-injection in Android, Linux, macOS and iOS

github.com

211–220 of 265 posts

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#211

Earlier quoted context omitted.

I've experienced Bluetooth issues like that before on Windows. 100% of the time it's been solved by using a better Bluetooth adapter. I don't have any issues after using actually good Bluetooth adapters, such as modern Intel ones.

I could do that, but I’m using the built in Bluetooth on my desktop. Honestly, I’m just annoyed with Bluetooth and windows. Everything else not based on Windows work completely fine, from macOS to my multiple linux desktops

That's like arguing graphics suck in Linux compared to Windows because your 4090 in Windows works great but your CGA adapter you use on your one Linux desktop isn't that great. You're not doing a real comparison of like hardware, you're comparing different adapters across different OSes.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#213

Earlier quoted context omitted.

The Xbox is a popular controller so its Bluetooth connection issues on windows should be well documented online by multiple users by now if it's a known issue. Or is it just you and a handful of unlucky users due to some buggy Bluetooth card-driver combo? There are a lot of short straws you can pull in the Bluetooth stack lottery that don't necessarily stem from the OS.

A few of friends also have this experience with the controller. Nobody bothers to say anything though and they all told me that I’d just be better off plugging it in. Which is what they do and what I ended up doing

I've used an original Xbox One Bluetooth controller on Windows with about a dozen different Bluetooth adapters. I've never had problems. I also used a Bluetooth Xbox 360 controller before and once again didn't have issues. I also use a GuliKit Zen Pro controller without issues across close to half a dozen different Bluetooth adapters without issue. All in Windows.

I'd be interested in knowing what version of Windows you're using. Bluetooth has had a lot of updates in the past few generations of Windows.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#214
post #117
post #73

Earlier quoted context omitted.

Notice the difference in color when you do that. As the other comment pointed out, it only disconnects devices. Apple makes it hard for their users to disable bluetooth (or gps) so features like airtag work well. You are sacrificing your battery life (and I guess privacy and security) for the ecosystem to work.

Google won't let you use GPS for maps without also turning on wifi for similar reasons I guess. It does make it more accurate but shouldn't be required.

That's nonsense, Maps works perfectly fine with wifi off

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#215
post #145

By the way, USB is similar. If you connect a keyboard to "charging only" port, it works. Tried myself on Android. Was told off here it's supposedly not practically exploitable.

What Android device are you using that has a physical "charging only" port?

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#216

Can someone walk me through the process of exploiting Android or iOS with this? I never attached a keyboard to my phones. How do I get to the app store and download an app using just the keyboard? On iOS it requires the fingerprint if I remember correctly, at least on mine. But it's for work and I do mostly very basic stuff with it, so I could be wrong.

the author says they can't do anything that requires further authentication. you'd need to chain this with another attack.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#217

Earlier quoted context omitted.

Seems like the flag defaults to true since December 7 (Fedora 38) with bluez v5.70-4: $ rpm -q --changelog bluez | grep CVE-2023-45866 -C1 * Thu Dec 07 2023 Peter Robinson - 5.70-4 - Add mitigation for CVE-2023-45866

This seems correct, however 'ClassicBondedOnly=true' is commented out in '/etc/bluetooth/input.conf' in Fedora 39 with bluez v5.70-4 anyways.

Generally commented out lines are defaults, right?

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#218
post #140

Earlier quoted context omitted.

That’s considerably worse than most people experience - keyboard latency is normally under 15ms - and I think that’s part of the problem there: if you live somewhere with a lot of congestion from other devices, poorly shielded microwave ovens, etc. you have a legitimately terrible experience but it’s not common enough for it to actually get fixed since it doesn’t impact sales.

Pretty sure you have forgotten or never experienced the awful bt devices from 15 years ago. Or maybe latency is not a big issue for you.

Latency is something I notice, but having used Bluetooth since it first came out, 500+ms is either a very noisy radio environment or defective hardware. It’s freakishly outside of normal for the technology - if you were seeing 5ms, maybe 10ms, that’d be within expectations but not even 50ms.

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#219
post #46

I had to dig a little to figure this out, so, to keep yourself safe: Android: disable Bluetooth when you're not using it (but you'll be vulnerable while you are). My Pixel just got the 12/5/2023 security update, which fixes the issue; not sure about non-Pixel phones. Linux: Open up /etc/bluetooth/input.conf and set ClassicBondedOnly=true (in my case I just had to uncomment this, not add anything). The next version of…

>disable Bluetooth when you're not using it (but you'll be vulnerable while you are

As someone with bluetooth devices (Smartwatch, buds, headphones, glasses etc) this is...difficult lol

Re: Bluetooth keystroke-injection in Android, Linux, macOS and iOS

#220
I use a UBPorts Pinephone as my daily driver. Sometimes I wonder about the security implications of that decision. I imagine there are WAY more vulnerabilities for a phone like mine, compared to iOS/Android. It's buggy enough from a user perspective, let alone a security one. Does anyone have any knowledge or thoughts in this regard?
Post reply on HN