Because even background features need to be scrutinized.
Bluetooth enables all kinds of conveniences, from hands-free calls to wireless headphones. However, few technological conveniences can come without drawbacks, and Bluetooth is no exception. At a time when personal data is a hot commodity, it is best to exercise caution.
Although Bluetooth requires user consent before pairing with another device, that doesn’t mean hackers can’t slip through the cracks. One notable case was the discovery of a Bluetooth vulnerability in Fitbits in particular, as well as other hardware using this technology. These vulnerabilities, based on open source algorithms that can allow malicious actors to decode a user’s location, are just the tip of the iceberg.
Recent research by Insinuator reportedly discovered a vulnerability in Airoha-based hardware that would allow attackers within Bluetooth range to, among other things, listen in on conversations and siphon personal data (including phone numbers, contacts and call history).
Best practices for Bluetooth security
Fortunately, there are simple steps users can take for better protection, starting with turning off Bluetooth when not in use. This will limit the window in which your device is vulnerable, making all sorts of hacker attacks (such as “bluebugging” or “bluesnarfing”, both of which take advantage of a nearby connection to gain access to a device) less likely. Additionally, users should set Bluetooth to “hidden” mode as opposed to “discoverable” mode, which will keep unknown devices away.
Additionally, users who connect their phone to a rental car (or plan to sell their current car) should remember to unpair their phone and erase all personal data from the vehicle before handing it over. It’s also worth remembering that using Bluetooth in conjunction with automotive systems like Android Auto wireless requires both Bluetooth and Wi-Fi, which opens up further points of vulnerability. One solution is to forgo this wireless convenience altogether, and you can prevent it from turning on automatically by setting your phone’s “Start Android Auto automatically” setting to “Never.”
iPhone users will also want to keep an eye out for the model’s Live Listen feature, which allows users to stream audio from their phone’s microphone to supported AirPods, hearing aids, or headphones. This setting uses Bluetooth, creating additional vulnerability to bluebugging attacks. If you want to make sure this setting is turned off, simply go to your phone’s accessibility settings and turn Live Listen off.
Bluetooth vulnerabilities continue to surface
It’s important to track vulnerability reports when it comes to hardware that relies on Bluetooth technology, as specific devices may exhibit specific issues. One example of this is a flaw discovered in 17 Google Fast Pair audio devices, where researchers from Belgium’s KU Leuven University (as reported by Wired) found that hackers could potentially track location data and spy on users simply by knowing a device’s model number. The researchers involved have published the WhisperPair.eu tool, which you can use to find out if your device is vulnerable.
Ultimately, simply keeping Bluetooth turned off when not in use, while adhering to other FCC recommendations, can go a long way toward improving personal security and protecting personal data. As the rapidly growing cottage industry around tech privacy continues to grow, the steps above are a good step toward more peace of mind and a good start toward better protection and precaution.
