| https://twitter.com/_mattata | |
| Personal Blog | https://remyhax.xyz |
| Professional Blog | https://www.greynoise.io/blog |
| Pronouns | He/Him |
| https://twitter.com/_mattata | |
| Personal Blog | https://remyhax.xyz |
| Professional Blog | https://www.greynoise.io/blog |
| Pronouns | He/Him |
New BTLE build collected more device fingerprints in 2 hours than I did on an 11 day road trip across the NE US with 10-12 hours of drive time per day with the old build.
This thing SLAPS.
It’s the most Bluetooth day of the year!
Ignore the terrible wiring, the mesh is live and self managing. Time to take a drive and survey some Christmas lights and bring some of my own!
The integration of BTLE and other radios in health devices needs scrutiny.
As of Friday my wife has a BTLE heart monitor. I’m quite motivated to care about doing things the right way and ethically collect data to empower people to build things the right way.
As another wave of "suspected Flipper zero disrupting BTLE devices" is trending:
I probably qualify as an expert and I have DATA.
When you do BTLE connection spamming you are not only messing with phones, you're messing with health devices and Point-of-Sale terminals.
As someone who has spent the past ~1.5y of my life researching this exact topic:
If you're going to initiate connections with a radio (BTLE) the first and highest priority task is rate-limiting.
Connection spamming with a Flipper Zero (or other device) is objectively dangerous.
"But you're doing similar BTLE research, how can you say that?"
Because I took the time to understand the risks, mitigate them in a controlled environment for months, and collect data to make informed decisions. I also *broke* MY devices. But they were scoped to MY devices.
All of this to say, If you've written or using code for BTLE connection *spamming*:
You're a dangerous shitstain who is gonna get people hurt.
You're making the lives of people who are actually trying to collect data to enable informed decisions worse.
Log off. Touch grass.
I'm prepping for a 2024 conference talk on BTLE.
Please don't willingly get yourself include in the slide about "unethical conduct" ffs.