Language Selection

English French German Italian Portuguese Spanish

Linux Bluetooth hackers hijack car audio

Filed under
Linux

inux hackers have demonstrated a way to inject or record audio signals from passing cars running insecure Bluetooth hands-free units. The Trifinite group showed how hackers could eavesdrop on passing motorists using a directional antenna and a Linux Laptop running a tool it has developed called Car Whisperer.

The software was demonstrated during a Bluetooth Security talk at last week's What the Hack hacker festival in The Netherlands. Trifinite has developed a specialism in unearthing Bluetooth security shortcomings, the latest of which illustrates implementation problems rather than more deep-seated security concerns with the protocol. Car Whisperer only works because many car manufacturers use standard Bluetooth passkeys such as "0000" or "1234" which are easy to guess. "This is often is the only authentication that is needed to connect," according to Trifinite.

Once connected hackers can interact with other drivers or even eavesdrop conversations from inside other cars by accessing the microphone. And that's just for starters.

"Since the attacker's laptop is fully trusted once it has a valid link key, the laptop could be used in order to access all the services offered on the hands-free unit. Often, phone books are stored in these units. I am quite certain that there will be more issues with the security of these systems due to the use of standard pass keys," Trifinite notes.

By John Leyden
theregister

More in Tux Machines

FreeBSD Delaaays and OpenBSD Founder Theo de Raadt Upset

  • FreeBSD 11.0-RELEASE Needs To Be Respun Due To Security Issues
    The delayed FreeBSD 11.0 release just suffered another last-minute set-back. While "FreeBSD 11.0-RELEASE images" were distributed to FTP mirrors and the official announcement expected today, these images need to be re-spun to contain some security fixes and thus pushing back the official release. Glen Barber noted today on the mailing list, "Although the FreeBSD 11.0-RELEASE has not yet been officially announced, many have found images on the Project FTP mirrors. However, please be aware the final 11.0-RELEASE will be rebuilt and republished on the Project mirrors as a result of a few last-minute security fixes we feel are imperative to include in the final release."
  • FreeBSD 11.0 Operating System Lands October 5 Due to Last-Minute Security Issues
    A few minutes ago, Glen Barber informed the FreeBSD community that they should not hurry and install the ISO images of the FreeBSD 11.0 operating system made available a few days ago on the official FTP mirrors. These images aren't safe to use and contain various security vulnerabilities that need to be fixed before the FreeBSD Project will officially unveil the final release of the FreeBSD 11.0 operating system in the coming days. According to the release schedule, FreeBSD 11.0 should hit the streets later today, September 29, 2016. However, until then the FreeBSD development team is hard at work patching those nasty security issues and rebuilding the final ISO images, which will be made available on the respective FTP mirrors later today as FreeBSD 11.0-RELEASE-p1. If you're already running FreeBSD 11.0-RELEASE, you will soon be provided with instructions to safely update your system
  • OpenBSD Founder Calling For LLVM To Face A Cataclysm Over Its Re-Licensing
    For over one year there's been talk of LLVM pursuing a mass relicensing from its University of Illinois/NCSA Open Source License, which is similar to the three-clause BSD license, to the Apache 2.0 license with explicit mention of GPLv2 compatibility. As mentioned in that aforelinked article, this re-licensing is moving ahead.

Ubuntu Studio 16.10 to Offer an Up-to-Date Multimedia Oriented Linux Distro

We reported earlier today, September 28, 2016, on the availability of the Final Beta (Beta 2) development milestone of the upcoming Ubuntu 16.10 (Yakkety Yak) operating system and its official derivatives. We've already talked here about what's new in the Beta 2 of Ubuntu MATE 16.10, Lubuntu 16.10, and Kubuntu 16.10, and now we would like to tell you a little bit about Ubuntu Studio 16.10, which promises to offer users an up-to-date multimedia oriented Linux-based operating system. That's right, it looks like today's Ubuntu Studio 16.10 (Yakkety Yak) Beta 2 snapshot comes with all the latest software releases and a bunch of new apps that you might need for audio, video, or graphics processing jobs. But first, we need to tell you that Ubuntu Studio 16.10 is powered by a low-latency Linux 4.8 kernel. Read more Also: Ubuntu GNOME 16.10 Beta 2 Released with Many Apps from the GNOME 3.22 Stack

Raspberry Pi Announces PIXEL Desktop Environment

Today the Raspberry Pi Foundation formally announced the Raspberry Pi PIXEL, their own desktop that will be used in future Raspbian spins. PIXEL is short for Pi Improved Xwindows Environment, Lightweight desktop. PIXEL is derived from the LXDE desktop environment but with both appearance and fundamental changes, including some new applications. Read more