ryukoposting
8 hours ago
As someone who finally recently escaped bluetooth firmware development: yes, Bluetooth is leaking secrets and it doesn't even require any silly RF shenanigans. Almost nothing actually implements LESC. Apple refuses to implement OOB pairing, so no peripherals can force you to use it, so everything is subject to MITM attacks. The entire ecosystem is a mess of consultants and underpaid devs copy-pasting Nordic sample code, with no time or financial incentive to do more than the bare minumum. Never trust any product that moves sensitive data through Bluetooth.
matthewdgreen
7 hours ago
Apple claims to have implemented an entire second security level for their Bluetooth apps based on iMessage, but I trust it not at all.
(To be clear, I trust the iMessage protocol with reasonable confidence. I judge the probability that Apple has applied this extra layer of security uniformly to all sensitive data to be about 8%.)
SXX
4 hours ago
Just curious if it that insecure how does Magic Keyboard with Touch ID works? Does it use some apple proprietary "magic"?
makeitdouble
4 hours ago
> "magic"
They're on an proprietary extension of Bluetooth, standard compatible but closed to their devices. They usually don't talk much about it, Phil Schiller was the most explicit I think (it was about the airpod's W1 but it's the same deal)
https://www.theverge.com/2016/9/7/12829190/apple-w1-chip-iph...
> Apple’s Phil Schiller described Apple’s move to a new wireless chip as “fixing the challenges” of wireless audio