Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Thursday, August 8, 2019

Bluetooth Security Issue Could Affect Most Devices

Recently, researchers from Boston University published a paper called "Tracking Anonymized Bluetooth Devices". The paper detailed a flaw in the ubiquitous Bluetooth communication protocol that could expose device users to tracking and even leak their IDs. As explained in the paper, many Bluetooth devices announce their presence by using their MAC addresses as the basis to generate a random number in order to prevent long-term tracking.

The team discovered a flaw in the system, and identified tokens that exist alongside MAC addresses. The researchers created what they're calling an address-carryover algorithm that is able to "exploit the asynchronous nature of payload and address changes to achieve tracking beyond the address randomization of a device. The algorithm does not require message decryption or breaking Bluetooth security in any way, as it is based entirely on public, unencrypted advertising traffic."

At the center of this flaw is Bluetooth BLE, which stands for Low Energy Specification).  Introduced in 2010, it really came to the fore with the release of Bluetooth 5.  The research team discovered it when they began investigating BLE advertising channels and "advertising events" within standard Bluetooth proximities.

"Most computer and smartphone operating systems do implement address randomizations by default as a means to prevent long-term passive tracking, as permanent identifiers are not broadcasted.  However, we identified that devices running Windows 10, iOS or mac OS regularly transmit advertising events containing custom data structures which are used to enable certain platform-specific interaction with other devices within BLE range."

Although this technique works on any Windows, iOS, and macOS system, Android devices are completely immune. That is because the Android OS doesn't continually send out advertising messages, and instead takes the approach of scanning for advertising messages being transmitted nearby.

If all of that makes your head spin, consider this:  The number of Bluetooth devices is projected to grow from 4.2 to 5.2 billion between 2019 and 2022. So this is a significant issue, deserving of attention.

Call SpartanTec, Inc. if you would like to reduce the vulnerabilities of your bluetooth devices and to make sure that your computer network is safe from the most common online threats.


SpartanTec, Inc. Columbia, SC 29201 (803) 408-7166 http://manageditservicescolumbia.com/

cities served:
Columbia, West Columbia, Cayce, St Andrews, Lexington, Oak Grove

Wednesday, July 31, 2019

Google Home Device Recordings May Not Be Private

Do you own a Google Home?  If so, you probably find it to be indispensable.  It's a powerful, genuinely helpful piece of technology, but there's a catch.  It's so good and so useful because it listens constantly for voice commands from you.  Those commands get recorded. Recently, Google acknowledged that it hires third-party contractors to listen to and transcribe recordings made by the devices.

The stated purpose of the transcription is to help the company improve Google Home's speech recognition.  That's certainly valid, but the company found itself in hot water when a whistle-blower who works for a Dutch subcontractor came forward with some disturbing information.

According to the whistle blower, he heard a wide range of things on the recordings, including a variety of personal information including addresses, bedroom talk, business calls, domestic violence and conversations between parents and children.

Even worse, in a survey of a thousand recordings, it was discovered that 153 of them should never have been recorded at all because the "Ok Google" prefix command was never spoken.

Google has responded to the revelation, saying that only about 0.2 percent of all audio clips recorded by Google Home's smart speakers are reviewed by third party partners. They also added:

"We partner with language experts around the world to improve speech technology by transcribing a small set of queries.  This work is critical to developing technology that powers products like Google Assistant.

We just learned that one of these reviewers had violated our data security policies by leaking confidential Dutch audio data.  Our Security and Privacy Response teams have been activated on this issue, are investigating, and we will take action.  We are conducting a full review of our safeguards in this space to prevent misconduct like this from happening again."

Blaming the whistle blower is a curious response, but this is an admittedly thorny issue with multiple angles to consider.  Perhaps the most straightforward approach would be to keep such analysis in-house, and get to the bottom of why more than 150 recordings that weren't triggered by the "Okay Google activation phrase" were made in the first place.

In any case, if you use the technology, be aware.  Someone is or may be listening.

Find out if your information security is at risk. Call SpartanTec, Inc. now.


SpartanTec, Inc. Columbia, SC 29201 (803) 408-7166 http://manageditservicescolumbia.com/

cities served:
Columbia, West Columbia, Cayce, St Andrews, Lexington, Oak Grove