@nazokiyoubinbou @Viss Exactly
-
@Aprazeth depends on the chipset of the raspi!
Which one? I use multiple Bluetooth adapters (long story, I needed/wanted/desired more range)
I really should check that talk I suppose for the details. Still, interesting. Thanks for pointing this out!
Didn't those Meta AR glasses also have Bluetooth?
... Oh. Oooooh. This'll be "fun". I wonder how much e-waste this will cause (because why patch it if you can just sell a new version?)
-
Which one? I use multiple Bluetooth adapters (long story, I needed/wanted/desired more range)
I really should check that talk I suppose for the details. Still, interesting. Thanks for pointing this out!
Didn't those Meta AR glasses also have Bluetooth?
... Oh. Oooooh. This'll be "fun". I wonder how much e-waste this will cause (because why patch it if you can just sell a new version?)
@Aprazeth i guess we'll hafta wait for the ccc talk to show up on video somewhere
-
@Viss got a tldr on the chipset(s) affected? mostly curious about sena series, will have to watch the talk when im not traveling.
-
@Viss got a tldr on the chipset(s) affected? mostly curious about sena series, will have to watch the talk when im not traveling.
@reverseics sadly no, i guess we hafta wait for the video of the talk to get posted
-
@Aprazeth i guess we'll hafta wait for the ccc talk to show up on video somewhere
@Viss
Oh, absolutely. Though a writeup/paper/blog would be fine as well IMHOIf it's Qualcomm or NXP, that will really hit a lot of devices. Or Texas Instruments from what I suspect
BTW from quick cursory search, the pi models 3,4,5 all seems to use a rendition of BCM43438 (but take that with a grain of salt, am tired and using phone)
-
@Viss
Oh, absolutely. Though a writeup/paper/blog would be fine as well IMHOIf it's Qualcomm or NXP, that will really hit a lot of devices. Or Texas Instruments from what I suspect
BTW from quick cursory search, the pi models 3,4,5 all seems to use a rendition of BCM43438 (but take that with a grain of salt, am tired and using phone)
@Viss
Found the talk:https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone
Will watch tomorrow but figured you'd want to see it as well
-
@Viss if my phone's configured to _not_ use the headset for calls, all's good, though?
-
Wow, I had no idea....
Testing next time I go to a restaraunt lol -
Wow, I had no idea....
Testing next time I go to a restaraunt lol@maddad bring your rf kit, cuz this ones not just git clone skid hax
-
@Viss confirmed
-
-
@Viss @funnymonkey what is the approximate distance? Feet? Inches? I thought badge readers intentionally made it so it had to be close to prevent interference from other cards but with a appropriate reader the distance was farther...
@vrek
As a person who uses those cards on a daily basis, the badge has to be no more than 3mm or so away from the reader to registerYou, as the black hat, would have to literally snatch the card and tap your fancy tech to get the code
With that said, a lot of people do not have positive control of their cards all the time
For a while, our RFID cards were also smart cards, for logging in to our corporate network, and people would forget their cards in their computers all the time, which opens up even more holes, particularly with internal threat actors
We switched to other methods, but the same risks apply—maintain positive control of your 2FA, smart and dumb keys at all times
Bluetooth is a much bigger issue, to be sure, particularly for tracking people
@Viss @funnymonkey -
@vrek
As a person who uses those cards on a daily basis, the badge has to be no more than 3mm or so away from the reader to registerYou, as the black hat, would have to literally snatch the card and tap your fancy tech to get the code
With that said, a lot of people do not have positive control of their cards all the time
For a while, our RFID cards were also smart cards, for logging in to our corporate network, and people would forget their cards in their computers all the time, which opens up even more holes, particularly with internal threat actors
We switched to other methods, but the same risks apply—maintain positive control of your 2FA, smart and dumb keys at all times
Bluetooth is a much bigger issue, to be sure, particularly for tracking people
@Viss @funnymonkey@DelilahTech @Viss @funnymonkey interesting. Yeah people are always the weak link. About 15 years ago there was an incident at an old office I worked in. Every door was locked and you needed a badge to the rfid reader to unlock, but somebody came up right at starting time when everyone was walking through the front doors, somebody held the door open being nice, this person then walked through the cubicles and any wallets he saw people left on their desk he took, then just walked out a side door
-
@DelilahTech @Viss @funnymonkey interesting. Yeah people are always the weak link. About 15 years ago there was an incident at an old office I worked in. Every door was locked and you needed a badge to the rfid reader to unlock, but somebody came up right at starting time when everyone was walking through the front doors, somebody held the door open being nice, this person then walked through the cubicles and any wallets he saw people left on their desk he took, then just walked out a side door
@vrek
Yeah, security at my job really leans on the "don't let people in" thing, and occasionally we'll get a 'where's your badge' troll to see who's paying attentionWith that said, we did have a thief who would regularly come through the office and steal shit off people's desks, particularly iPhone chargers
... and food from the fridges, which really upset one of our second shift people, with dietary restrictions
So, yeah, the thief was called the hamburger, 😂
We suspected a security guard on 2nd shift, but as far as I know, no one was caught, and thievery stopped after about eight months
@Viss @funnymonkey -
@vrek
Yeah, security at my job really leans on the "don't let people in" thing, and occasionally we'll get a 'where's your badge' troll to see who's paying attentionWith that said, we did have a thief who would regularly come through the office and steal shit off people's desks, particularly iPhone chargers
... and food from the fridges, which really upset one of our second shift people, with dietary restrictions
So, yeah, the thief was called the hamburger, 😂
We suspected a security guard on 2nd shift, but as far as I know, no one was caught, and thievery stopped after about eight months
@Viss @funnymonkey@DelilahTech @Viss @funnymonkey yeah, they started enforcing that after the incident. When I was with same company but different location we hired somebody like 3 days before 2 weeks off for Christmas. Due to the calendar that year Jan 2nd was Friday so they gave us that day off. Everyone forgot to tell the new guy. He showed up, his badge works since it was a valid work day. He didn't know there was a security system... He put his stuff in lockers, made a coffee, about to start working, police!
-
@vrek
Yeah, security at my job really leans on the "don't let people in" thing, and occasionally we'll get a 'where's your badge' troll to see who's paying attentionWith that said, we did have a thief who would regularly come through the office and steal shit off people's desks, particularly iPhone chargers
... and food from the fridges, which really upset one of our second shift people, with dietary restrictions
So, yeah, the thief was called the hamburger, 😂
We suspected a security guard on 2nd shift, but as far as I know, no one was caught, and thievery stopped after about eight months
@Viss @funnymonkey@DelilahTech @Viss @funnymonkey oh and I should say that was a 1 time incident, he took about 15 wallets(don't know total count of money) and was never seen again. My wallet is always in my pocket, if you're close enough to put a hand in there and I don't react with a elbow or fist... You could probably just ask me to lend you some money
-
@DelilahTech @Viss @funnymonkey yeah, they started enforcing that after the incident. When I was with same company but different location we hired somebody like 3 days before 2 weeks off for Christmas. Due to the calendar that year Jan 2nd was Friday so they gave us that day off. Everyone forgot to tell the new guy. He showed up, his badge works since it was a valid work day. He didn't know there was a security system... He put his stuff in lockers, made a coffee, about to start working, police!
@vrek
LOL, I've accidentally gone to work on... Memorial day?Whichever the one is in May
Anyway, I was on 2nd shift back then, and I did it twice! 😅
You'd think the gate guard would have said something, you'd be wrong 🤦
@Viss @funnymonkey -
@vrek
LOL, I've accidentally gone to work on... Memorial day?Whichever the one is in May
Anyway, I was on 2nd shift back then, and I did it twice! 😅
You'd think the gate guard would have said something, you'd be wrong 🤦
@Viss @funnymonkey@DelilahTech @Viss @funnymonkey we didn't have a front gaurd at that site, just badges and a security system.
He ended up a good employee, no punishment.
One time I went to work on a Sunday for reasons, needed to go to clean room and turned on the lights in gowning. Later security walked by and saw lights on, turned them off. I needed to pee so I leave clean room, pee, turn lights back on to gown. Security sees lights, turns them off. I take lunch, security sees me in cafeteria... "it was you!" -
@DelilahTech @Viss @funnymonkey we didn't have a front gaurd at that site, just badges and a security system.
He ended up a good employee, no punishment.
One time I went to work on a Sunday for reasons, needed to go to clean room and turned on the lights in gowning. Later security walked by and saw lights on, turned them off. I needed to pee so I leave clean room, pee, turn lights back on to gown. Security sees lights, turns them off. I take lunch, security sees me in cafeteria... "it was you!"@DelilahTech @Viss @funnymonkey to be clear, my story was at second location with security guard.
-
@DelilahTech @Viss @funnymonkey we didn't have a front gaurd at that site, just badges and a security system.
He ended up a good employee, no punishment.
One time I went to work on a Sunday for reasons, needed to go to clean room and turned on the lights in gowning. Later security walked by and saw lights on, turned them off. I needed to pee so I leave clean room, pee, turn lights back on to gown. Security sees lights, turns them off. I take lunch, security sees me in cafeteria... "it was you!"A g- g- g- ghost!