Live data from Hacker News

Blueborne – A new attack vector endangering major operating systems

armis.com

31–34 of 34 posts

Re: Blueborne – A new attack vector endangering major operating systems

#31
post #4
post #2

This looks very scary, especially given how many Android devices are out there that receive few or no security updates.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

On other hand. My MiBox 3 suddenly received update.

Re: Blueborne – A new attack vector endangering major operating systems

#32
post #4
post #2

This looks very scary, especially given how many Android devices are out there that receive few or no security updates.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

At this point in time buying Samsung is just a bad decision. Have you checked out custom ROMs?

Re: Blueborne – A new attack vector endangering major operating systems

#33

Google has issued a patch and notified its partners. It will be available for: Nougat (7.0) Marshmallow (6.0) Google has issued a security update patch and notified its partners. It was available to Android partners on August 7th, 2017, and made available as part of the September Security Update and Bulletin. We recommend that users check that Bulletin for the latest most accurate information. Android users should ve…

I recommend you switch to Lineage OS. Once the manufacturer drops the device you're SoL.

Re: Blueborne – A new attack vector endangering major operating systems

#34
post #23

Earlier quoted context omitted.

I have the same question -- I turned off the Bluetooth radio on my phone the day I got it, and I've never turned it back on. But does that mean the radio is actually powered down, or is the phone blocking Bluetooth at a higher level? Similarly, or possibly the same question, is an rfkill soft block adequate for a laptop with bluetooth?

On a laptop, if you want to be sure, you can at least do `sudo modprobe -r btusb` (or whatever your particular chipset's BT driver is called).

A very good point -- that's definitely better than rfkill.
Post reply on HN