The Bluetooth chipset installed in popular models from major manufacturers is vulnerable. Hackers could use it to initiate calls and eavesdrop on devices.

Source

  • skisnow@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 months ago

    downvoted for that website’s super illegal “pay us to not track you” policy

    • JuxtaposedJaguar@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      Consent required for free use

      I think that’s explicitly forbidden by the EU, and it’s a German domain.

    • tal@lemmy.today
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      3 months ago

      I mean, there were legitimate technical issues with the standard, especially on smartphones, which is where they really got pushed out. Most other devices do have headphones jacks. If I get a laptop, it’s probably got a headphones jack. Radios will have headphones jacks. Get a mixer, it’s got a headphones jack. I don’t think that the standard is going to vanish anytime soon in general.

      I like headphones jacks. I have a ton of 1/8" and 1/4" devices and headphones that I happily use. But they weren’t doing it for no reason.

      • From what I’ve read, the big, driving one that drove them out on smartphones was that the jack just takes up a lot more physical space in the phone than USB-C or Bluetooth. I’d rather just have a thicker phone, but a lot of people wouldn’t, and if you’re going all over the phone trying to figure out what to eject to buy more space, that’s gonna be a big target. For people who do want a jack on smartphones, which invariably have USB-C, you can get a similar effect to having a headphones jack by just leaving a small USB-C audio interface with a headphones jack on the end of your headphones (one with a passthrough USB-C port if you also want to use the USB-C port for charging).

      • A second issue was that the standard didn’t have a way to provide power (there was a now-dead extension from many years back, IIRC for MD players, that let a small amount of power be provided with an extra ring). That didn’t matter for a long time, as long as your device could put out a strong enough signal to drive headphones of whatever impedance you had. But ANC has started to become popular now, and you need power for ANC. This is really the first time I think that there’s a solid reason to want to power headphones.

      • The connection got shorted when plugging things in and out, which could result in loud sound on the membrane.

      • USB-C is designed so that the springy tensioning stuff that’s there to keep the connection solid is on the (cheap, easy to replace) cord rather than the (expensive, hard to replace) device; I understand from past reading that this was a major reason that micro-USB replaced mini-USB. Instead of your device wearing out, the cord wears out. Not as much of an issue for headphones as mini-USB, but I think that it’s probably fair to say that it’s desirable to have the tensioning on the cord side.

      • On USB-C, the right part breaks. One irritation I have with USB-C is that it is…kind of flimsy. Like, it doesn’t require that much force pushing on a plug sideways to damage a plug. However — and I don’t know if this was a design goal for USB-C, though I suspect it was — my experience has been that if that happens, it’s the plug on the (cheap, easy to replace) cord that gets damaged, not the device. I have a television with a headphones jack that I destroyed by tripping over a headphones cord once, because the headphones jack was nice and durable and let me tear components inside the television off. I’ve damaged several USB-C cables, but I’ve never damaged the device they’re connected to while doing so.

      On an interesting note, the standard is extremely old, probably one of the oldest data standards in general use today; the 1/4" mono standard was from phone switchboards in the 1800s.

      EDIT: Also, one other perk of using USB-C instead of a built-in headphones jack on a smartphone is that if the DAC on your phone sucks, going the USB-C-audio-interface route means that you can use a different DAC. Can’t really change the internal DAC. I don’t know about other people, but last phone I had that did have an audio jack would let through a “wub wub wub” sound when I was charging it on USB off my car’s 12V cigarette lighter adapter — dirty power, but USB power is often really dirty. Was really obnoxious when feeding my car’s stereo via its AUX port. That’s very much avoidable for the manufacturer by putting some filtering on the DAC’s power supply, maybe needs a capacitor on the thing, but the phone manufacturer didn’t do it, maybe to save space or money. That’s not something that I can go fix. I eventually worked around it by getting a battery-powered Bluetooth receiver that had a 1/8" headphones jack, cutting the phone’s DAC out of the equation. The phone’s internal DAC worked fine when the phone wasn’t charging, but I wanted to have the phone plugged in for (battery hungry) navigation stuff when I was driving.

      • Bob Robertson IX @discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        I’d rather just have a thicker phone, but a lot of people wouldn’t

        I think this is a case where the corporations were telling people what they wanted rather than people really asking for thinner phones. Same thing with bezels, I don’t know anyone who asked for the screen to go all the way to the edge (or worse, curve around onto the sides). Apple and Samsung said ‘this is what people want’ when in fact it was what their marketing department wanted because they wouldn’t be able to sell the iGalaxy N+1 if it was slightly thicker or heavier than the iGalaxy N.

        • papertowels@mander.xyz
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          Active noise cancelling - noise cancelling that doesn’t just rely on making a seal between your ears and the earbuds/headphones.

  • MNByChoice@midwest.social
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 months ago

    The site wants to share info with advertisers. I found this to be refreshingly honest.

    We and our up to 185 partners use cookies and tracking technologies. Some cookies and data processing are technically necessary, others help us to improve our offer and operate it economically…

    Anyway, can we get an archive link?

    • trashboat@midwest.social
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      It’s strange to think about how complicit the public has become with this. You mean to tell me that 185 separate connections to other companies are required for me to… read an article?

      • ipkpjersi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        3 months ago

        Well yeah, they have to hoard your advertising data somehow. How else can they advertise things that you don’t need to buy?

  • viking@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    Sounds like the attack scenario is very sophisticated and targeted, and only works within the range of Bluetooth low energy (BLE) connectivity, so 10-15 meters under best circumstances. At that point they might as well eavesdrop on my calls in person.

  • SCmSTR@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    Unchecked consumer-grade RF signals that are broadcast in every direction are insecure??

    Color me shocked!

  • Catoblepas@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    Even if these attacks seem frightening on paper, the ERNW researchers are reassuring: many conditions must be met to carry out an eavesdropping attack. First and foremost, the attacker(s) must be within range of the Bluetooth short-range radio; an attack via the Internet is not possible. They must also carry out several technical steps without attracting attention. And they must have a reason to eavesdrop on the Bluetooth connection, which, according to the discoverers, is only conceivable for a few target people. For example, celebrities, journalists or diplomats, but also political dissidents and employees in security-critical companies are possible targets.

    I guess they didn’t point this out because it’s kind of obvious, but it sounds like they also have to actually be on to be exploited. So it’s not going to turn on and start listening to you at least. Definitely concerning, but I’m still gonna be listening to my audio books and podcasts with my wireless headphones.

  • ashenone@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    Gonna set up my tablet to play Capital over bluetooth 24/7. Enjoy the theory skinwalkers

  • unalivejoy@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 months ago

    There’s lots of money to be made by inserting a hardware back door in your product then later disclosing it as an unfixable vulnerability and force your customers to buy new hardware which has the same but different backdoor. Repeat.

    • viking@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      GDPR. First time opening a European website? German ones like this are particularly transparent (by law, not choice).

    • Almonds@mander.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      The flaws, discovered by German cybersecurity firm ERNW and first reported by Heise Online, affect dozens of headphone models from brands such as Sony, JBL, Bose, and Marshall, with no comprehensive firmware fixes available yet.

      • Sony WH-1000XM4/5/6, WF-1000XM3/4/5, LinkBuds S, ULT Wear, CH-720N, C500, C510-GFP, XB910N
      • Marshall ACTON III, MAJOR V, MINOR IV, MOTIF II, STANMORE III, WOBURN III
      • JBL Live Buds 3, Endurance Race 2
      • Jabra Elite 8 Active
      • Bose QuietComfort Earbuds
      • Beyerdynamic Amiron 300
      • Jlab Epic Air Sport ANC
      • Teufel Airy TWS 2
      • MoerLabs EchoBeatz
      • Xiaomi Redmi Buds 5 Pro
      • earisMax Bluetooth Auracast Sender

      ERNW emphasizes that this is only a partial list.

      Source

      • OberonSwanson@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        Damn that’s pretty big, hopefully they update and give a final list of affected devices. Not to mention, gotta pray the devices will see software updates to try and mitigate it.

  • atlien51@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    This really makes me hate that we don’t have headphone jack anymore

    • underscores@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      3 months ago

      Ive always hated phones without the 3.5mm and won’t stop even if all phone manufacturers remove it

      • atlien51@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        At least you can still get adapters for phones that don’t have it :)

        • ddh@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          2
          ·
          3 months ago

          Indeed, I don’t really see the problem. Instead of a single use port you have a practically universal port. That’s better, surely.

          • Walk_blesseD@piefed.blahaj.zone
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 months ago

            instead of

            Yeah but it was never a matter of “insTeAD Of,” it’s in addition to, meaning you get to use the same favourite set of headpdones you use with literally every other device while keeping the practically universal port free for other purposes at the same time!!! 🤯🤯🤯
            Now isn’t that wizard?

  • Vanilla_PuddinFudge@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    I had a neighbor about 6 years ago that blasted rap at full volume every evening.

    rap booming in the background

    one fine day

    "hmmm, what were these headphones on bt again? wait… soundbar. I don’t have a soundbar.

    hmmm, I wonder"

    device paired

    Jellyfin>Artists>… Meshuggah

    Obzen

    Combustion

    play

    Volume 100%

    “I think I’ll go to the store for a while!”

  • Redex@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Hah, jokes on them, I managed to fuck my earbuds’ microphones so they’re useless now.