Live data from Hacker News

Bluetooth Headphone Jacking: A Key to Your Phone [video]

media.ccc.de

221–228 of 228 posts

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#222

Earlier quoted context omitted.

Your opinion is valid, but irrelevant. The above comment said that you’re a minority and that they’ve never met a person irl that shares your opinion. I can say I’ve also never met anyone who shares that opinion. Also of note is that I used to care a lot about sound quality, and owned very expensive wired IEMs until 2 years ago. I was annoyed when I switched to a phone without a jack, but now I’m used to it and don’t…

> The above comment said that you’re a minority If we're going to pick nits, no it didn't. And the fact that I'm in a minority (which I definitely am) is what's irrelevant. The comment seemed to be doubting the existence of this preference, and I gave an example of its existence.

We don’t need to nitpick. I think it’s obvious that saying I don’t know anyone with this opinion != nobody has this opinion.

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#223

Earlier quoted context omitted.

Why would you make a keyboard with one more letter when everyone is buying ones without? Would you buy a keyboard with a ™ key? If not, why not?

Because a large number of “everyone” is buying keyboards from your competitors. If you make a keyboard with all the letters, you’ll get more of those sales. No, I wouldn’t but a keyboard with a tm key because I don’t care about having such a key. Pretty much nobody would. That’s why such keyboards aren’t made. You’re making my argument for me here.

Counterpoint: if, instead of differentiating yourself, you copy Apple, nobody will fire you for that decision, even if it sucks.

Bonus: now that neither you nor Apple are including the jack, consumers resign themselves to a worse user experience and just buy your product (or theirs).

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#224

Earlier quoted context omitted.

>I doubt this was ever classified information. The classified part would be the intelligence that the wireless protocol is compromised. I don't see that in your document.

That's not intelligence, just a precaution.

A precaution presumably based on intelligence. The (presumed) intelligence that the wireless protocol is compromised. As I said before.

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#225
post #13

Glad this submission is finally receiving upvotes. This was just shown at the 39C3 in Hamburg, few days back. Common (unpached) Bluetooth headsets using Airoha's SoCs can be completely taken over by any unauthenticated bystander with a Linux laptop. (CVE-2025-20700, CVE-2025-20701, CVE-2025-20702) This includes firmware dumps, user preferences, Bluetooth Classic session keys, current playing track, ... > Examples of…

Kamala Harris, citing seemingly classified intelligence, famously raised the alarm on Bluetooth earphones to Stephen Colbert: “I know I've been teased about this, but I like these kinds of earpods that have the thing [pointing to the wire] because I served on the Senate Intelligence Committee. I have been in classified briefings, and I'm telling you, don't be on the train using your earpods thinking somebody can't li…

Literally common sense since the beginning of wireless communications and coms in general.

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#226
post #160

Earlier quoted context omitted.

Is this an unintentional vulnerability or is it one of those "we left it open because it's easier and we hoped nobody would notice" kind of things. I mean can you just send a "update to this firmware" command completely unauthenticated and it's like "yep sure"? No signing or anything?

According to the details in their whitepaper, firmware is signed, but the management protocol allows reading arbitrary memory, so you can read out the keys and sign your own payload. I'm not sure anyone intentionally did this, but there were several poor decisions involved. It sounds like the upstream vendor shipped sample code without auth, assuming implementers would know they needed to secure a privileged device m…

I haven't read the whitepaper, but surely the ROM wouldn't include its own private signing keys. Is it maybe encrypted instead of signed?

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#227

Earlier quoted context omitted.

Get a set of wired headphones without a built-in cord. Then you can use any USB-C to 3.5 male cord like normal.

You can't use a passive cable for this - there may be a USB-to-audio standard, but it's not widely implemented anymore. You need a DAC.

Thanks! You probably saved me $15 a year from now :)

Re: Bluetooth Headphone Jacking: A Key to Your Phone [video]

#228
post #68

Earlier quoted context omitted.

They also demonstrated how this could be used to silently find out someone’s phone number and then hijack a TFA validation call from an app like WhatsApp to take over their account with no user interaction.

This attack was not silent, it was noisy. They specifically pointed that out in their talk.

Right, but isn't it noisy ... at the headphone level? (i.e. not heard when not wearing them?).

What I'm getting at is that I think the risk varies depending on how often you leave the headset paired; for example, if the headphones are over-ear, those are more prone to not be turned off --- and remain connected; thus, a greater chance of success for establishing a BlueTooth classic connection without getting noticed and performing the WhatsApp account take-over until they listen to "I'm gonna take a shower, honey!" in the distance.

Post reply on HN