Engadget: Keep Bluetooth Off When Not in Use to Avoid Hacking
Engadget advises turning Bluetooth off when not in use, citing hacking risks in Fitbit and other devices.
The article details vulnerabilities in widely used products. A notable case involved Fitbit hardware and other Bluetooth-enabled devices, where open-source algorithms could allow malicious actors to decode a user's location. Security firm Insinuator reportedly found a flaw in Airoha-based hardware that would permit nearby attackers to eavesdrop on conversations and siphon personal data, including phone numbers, contacts, and call history. Researchers from KU Leuven University in Belgium, as reported by Wired, discovered a flaw in 17 Google Fast Pair audio devices that could allow location tracking and eavesdropping if the attacker knew the device's model number.
Attack methods such as "bluebugging" and "bluesnarfing" exploit nearby Bluetooth connections to gain access to a device. Engadget suggests simple safeguards: keep Bluetooth off when not in use, set devices to hidden mode rather than discoverable mode, and stay alert to vulnerability reports for specific hardware.
Users who connect phones to rental cars or sell their vehicles should unpair their phone and clear personal data from the car before returning or handing it over. Wireless Android Auto requires both Bluetooth and Wi-Fi, which opens further points of vulnerability; setting the phone's "Start Android Auto Automatically" to "Never" can prevent it from switching on by itself. For iPhone owners, the Live Listen feature streams audio from the phone's microphone over Bluetooth to AirPods, hearing devices, or supported headphones, introducing an additional vulnerability to bluebugging; it can be turned off in accessibility settings.
Because specific devices can have specific issues, following vulnerability reports matters. The KU Leuven researchers released the WhisperPair.eu tool that lets users check whether their Bluetooth devices are vulnerable.