• On CHOW: Sexy vampire party
July 23, 2008 5:15 PM PDT

Pairing your cell with Bluetooth? Buyer beware

by Elinor Mills

I admit it; I've been in denial about my cell phone habit.

I'm a multitasker on the phone and I tend to make calls when I'm in transit. Why not get some of those calls I have to make out of the way while I'm walking or driving? (I really do try to not use the phone while on the bus so as not to annoy other passengers, but sometimes it just can't be avoided.)

(Credit: CNET News)

Of course, I've known for months that I was going to have to curb the habit while driving because of the hands-free law that went into effect for drivers in California three weeks ago. But I have been resisting buying a cell phone headset for a number of reasons.

For one, I find those cyborg-like devices sticking out of peoples' ears to be tacky. I'm sorry, but I do. Seeing people talking to themselves when they are not obviously on the phone is just off-putting.

Secondly, I had heard about security problems with Bluetooth and didn't want to have to figure it all out. Security experts discussed the risks to Bluetooth users at the Last HOPE (Hackers on Planet Earth) conference in New York last weekend, warning people to change the default password, turn off the headsets when not in use, and limit access to the data when communicating with other devices.

I also thought that buying a headset would unnecessarily feed a habit that I'd rather cut back on. I don't really like long phone conversations and I easily over dose on talking on the phone because I do it so much for my job. For me, getting a headset would be like getting TiVo when you're trying to watch less television.

But when I found myself tempted to break the law recently, needing to make a call while driving, I realized it was time to get one.

So I bought a standard Motorola variety for less than $50 on Tuesday night. Apparently, I'm not the only one thinking this way--a new study has found that the hands-free law boosted Bluetooth device sales to four times the national average.

On Wednesday, the U.S. CERT (Computer Emergency Readiness Team) decided the Bluetooth security risk was serious enough to publish a security advisory about it.

"Depending upon how it is configured, Bluetooth technology can be fairly secure," the advisory said. "Unfortunately, many Bluetooth devices rely on short numeric PIN numbers instead of more secure passwords or passphrases."

Basically, any device that can "discover" another Bluetooth device can send unsolicited messages or do things that could lead to extra fees, data being compromised or corrupted, data stolen in an attack called "bluesnarfing," or the device being infected with a virus, the advisory said.

To protect against these risks, Bluetooth owners should disable the technology when it is not being used, disable unnecessary features, and switch it to "hidden" mode, CERT said. Using "hidden" mode won't prevent me from using my headset with my phone because once the two devices have located each other, or paired, they will continue to be able to recognize each other thereafter.

Bluetooth users should also be careful where they are using the technology. For instance, using it in a public wireless "hotspot" poses a greater risk that someone else can intercept the connection than using it in your home or car, according to the advisory.

Now all I have to do is get something to protect me from the Bluetooth device's electromagnetic frequencies (EMFs), which may or may not pose health risks.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Eastern Europeans charged in payment processor hack
A child porn-planting virus: Threat or bad defense?
Microsoft patches critical hole in Windows kernel
Panda's Cloud Antivirus leaves beta behind
Apple plugs holes for domain spoofing, other attacks
Microsoft launches Forefront Protection 2010
'60 Minutes'--Cyberwar: Sabotaging the system
Microsoft to fix holes in Windows, Office
Add a Comment (Log in or register) Showing 1 of 2 pages (31 Comments)
by RickyFr July 24, 2008 3:34 AM PDT
You wrote, "really do try to not use the phone while on the bus so as not to annoy other passengers, but sometimes it just can't be avoided."

Nonsense, this can always be avoided. Turn your cellphone off. It will work everytime!
Reply to this comment
by mnwcsult July 24, 2008 5:52 AM PDT
Gee, My teen son did a science project that involved building a BlueSniping rifle (http://www.tomshardware.co.uk/how-to-bluesniper-pt1,review-1224-9.html)

That was 2006 and the "Security Flaw" in Bluetooth devices was largely confined to older model Nokia phones even then. See (http://news.zdnet.com/2100-1009_22-137331.html)

However if you want see for yourselves as what the extent of the problem could be go to http://trifinite.org/trifinite_stuff_blooover.html and download Bloover II into your Bluetooth enabled Cell phone and then visit the "food court", ride the "tubes" or subway.

Be prepared to be underwhelmed as you will likely scan many devices none will be hack able in any real manner.

Try social engineering, this sometimes works. Change your cell phones Bluetooth name to "To win a Million dollars, type 2345" This way when you attempt to pair with your selected target, they see the pairing request as "To win a Million dollars, type 2345".

Now of curse if anyone falls for that ...

In closing this is an OLD issue that has been way overstated.
Reply to this comment
by mnwcsult July 24, 2008 5:55 AM PDT
Gee, My teen son did a science project that involved building a BlueSniping rifle (http://www.tomshardware.co.uk/how-to-bluesniper-pt1,review-1224-9.html)

That was 2006 and the "Security Flaw" in Bluetooth devices was largely confined to older model Nokia phones even then. See (http://news.zdnet.com/2100-1009_22-137331.html)

However if you want see for yourselves as what the extent of the problem could be go to http://trifinite.org/trifinite_stuff_blooover.html and download Bloover II into your Bluetooth enabled Cell phone and then visit the "food court", ride the "tubes" or subway.

Be prepared to be underwhelmed as you will likely scan many devices none will be hack able in any real manner.

Try social engineering, this sometimes works. Change your cell phones Bluetooth name to "To win a Million dollars, type 2345" This way when you attempt to pair with your selected target, they see the pairing request as "To win a Million dollars, type 2345".

Now of curse if anyone falls for that ...

In closing this is an OLD issue that has been way overstated.
Reply to this comment
by mnwcsult July 24, 2008 6:11 AM PDT
Sorry for the previous double post, and the end should have been "Of course if anyone falls for that ..."
Reply to this comment
by Dalkorian July 24, 2008 8:58 AM PDT
Appalling ...
----------------------------------
Why not get some of those calls I have to make out of the way while I'm walking or driving? (I really do try to not use the phone while on the bus so as not to annoy other passengers, but sometimes it just can't be avoided.)
----------------------------------
It's nice you're so worried about "bothering" people on the bus, but what makes you think you're so important that you need to chat on that self-absorbed toy of yours while driving? Thanks for thinking other people's personal safety is so less important than chatting with your friends about last nights "Deal or no deal". I hope the only person who gets injured in the accident you're going to cause is you. (It's been PROVEN that you're generally a better driver when legally drunk than you are when chatting on that idiotic "I'm so important" toy of yours - http://unews.utah.edu/p/?r=062206-1.)
Bottom line - YOU ARE NOT SO FREAKING IMPORTANT THAT YOU CAN'T PULL OVER FOR A FEW MINUTES TO DEAL WITH YOUR IDIOTIC SELF-ABSORBED "SEE HOW IMPORTANT I AM" TOY!!!
The good news is that idiotic toy of yours appears to be nuking your brain. Enjoy your brain cancer.
Reply to this comment
by clayhorste July 24, 2008 9:05 AM PDT
Why not get one with a wire? It isn't like you will be using the phone that far away. The wire doesn't need to be charged and the phone's battery life is extended when you turn Bluetooth off. The security issue would be moot at that point. There wouldn't be any EMF's either. Sounds like a winner to me.
Reply to this comment
by moopenguin32 July 24, 2008 9:44 AM PDT
Can you even change the PIN for a bluetooth headset? Motorola has this to say on their support site for their bluetooth headsets:

Question: What's the pairing pin code and can I change it?
Answer: The default pin code or passkey for Motorola Bluetooth accessories products is 0000 and cannot be changed.
Reply to this comment
by wlxfeedpartner4 October 15, 2009 12:06 AM PDT
Test reply to a comments - 15th Oct
by FRE0 July 24, 2008 11:10 AM PDT
Studies have shown that using hands-free cell phones while driving does not solve the safety probem. In fact, it may even be more dangerous because drivers think that they are being safer.

Driving while using the phone should, except in case of road emergencies, be illegal!!
Reply to this comment
by skrubol July 29, 2008 1:35 PM PDT
As should eating, looking for stuff in the car, or daydreaming. I've seen all these studies that compare talking on the phone to driving distraction free, but nobody has bothered comparing with the other common distractions. I've heard of one study that concluded that talking on the phone was more distracting than talking to someone in the car. Not exactly overwhelming.
by ReVeLaTeD July 24, 2008 11:30 AM PDT
People please...stop the FUD.

Bluetooth is no more or less secure than Wi-Fi. They're both culprits of the same issue: user ignorance.

To connect to a Bluetooth device, it has to be discoverable (which most aren't by default), enter a PIN, then confirm the connection on the other end. How is that any different from a hotspot? It's not - except MAYBE the PIN part, but most hotspots are password protected, same thing.

All the fashion nuts who refuse to wear Bluetooth, don't. It says use a headset, doesn't have to be a Bluetooth headset, just any headset.

The problem is that too many people are so set in their ways and refuse to follow this, the most simplest of laws, because they think it'll mess up their style/hair/makeup/etc.

ALL YOU HAVE TO DO IS USE A HEADSET WHEN DRIVING. Why is that hard?

If you don't want to do it, don't...pay the $200-400 fine each time and go on about your business. I'll keep on using my Bluetooth setup.
Reply to this comment
by kwilsonjr July 24, 2008 1:11 PM PDT
I installed a Parrot 3200-LS car kit the day the law went into effect. Best Buy had a deal that included free installation. Since I know from past car kit experience that it is generally about $100 for installation, I jumped on it.

I couldn't be happier. It tunrs down my stereo when I make or receive a call and the sound comes out my stereo speakers. I really great feature for noisy roadways.

This particular unit generates a RANDOM pin for pairing that is displayed on the full color Parrot display, and must be entered on the phone to pair.

I wish I had installed this device sooner. I just love it!
Reply to this comment
by zephwr July 24, 2008 5:06 PM PDT
To second FRE0's comment, you state:

Why not get some of those calls I have to make out of the way while I'm walking or driving? (I really do try to not use the phone while on the bus so as not to annoy other passengers

I would much prefer you annoy some other passengers on the bus, than be distracted behind the wheel, and perhaps kill someone as a result. The majority of vehicle operators on US roads seem to be sitting behind the wheel while going from point A to B, often focused on other tasks. Very few of them are actively driving-- paying attention to traffic, looking further than one vehicle ahead, predicting trouble and avoiding it before it happens.

Have a look at http://web.utah.edu/news/releases/05/feb/cellphones.html

Please, when you're behind the wheel, hang up and drive!
Reply to this comment
by wtortorici July 24, 2008 5:50 PM PDT
It's to late, mobile phone use in cars has already fried the user's brains.
Reply to this comment
by ahrensr July 24, 2008 8:40 PM PDT
To all the knuckleheads damning the folks that talk hands free while driving:

I hope you never drink your morning coffee while driving, or have an accident with someone that does.

I hope you never have an argument with your significant other, or have an accident with someone that does.

I hope you leave your car radio or stereo off and never change the station or song, or have an accident with someone that doesn't and is fiddling with it.

I hope you never eat a hamburger while driving, or have an accident with someone that does.

I hope you never get distracted by your kids, or have an accident with someone that does.

Get the picture? It isn't the particular OBJECT you use that is the problem. It's the fact of your distraction. We can pass laws till the cows come home outlawing anything we can think of that can distract a driver, but some idiot will find something else to distract himself with that ISN'T illegal.

Almost every state has laws making driving while distracted illegal. We don't need to pass any laws detailing the distractions, because they are legion.

Just enforce the laws we have, and train our drivers how to drive properly.

I have driven for over forty years, and ALL of the accidents I had were because I wasn't paying attention to the road, or the other traffic, but holding something, or fiddling with the radio were not involved. I have had very distracting arguments with my spouse, my kids, heck, other drivers, and have NEVER been more distracted by a cell phone than those arguments made me.

So, what, shall we make arguing with someone illegal, too?
Reply to this comment
by MaxAgent86 July 25, 2008 9:24 AM PDT
You would be 100% right if a: you have an argument with your significant other each time you are driving
b) you eat a hamburger each time you are driving
c) Your kids are in the car each time you are driving
d) You change cd or radio stations every 5-10 mins or so

Chances are that the above is not true, but a cell phone is always with you, you never know when a call is going to come in and that call could be your significant other on the other end and you could be having an argument because one of your kids has done something thus distracting you (so a or c do not necessarily need to be in the car)

As for the hamburger same a a cell phone, you should not be driving when your attention is not on the road
Same goes for the radio, if its taking your attention away too long, pull over
As for the coffee, it should be avoided
You are right when you say that distractions are legion

So what is to be done ? the answer is simple but the application is not: self-discipline and unfortunately that is something we are missing (more or less) in our world today.

What is the use of learning to stop to eat an hamburger, do a phone call, discipline our kids if we cannot convince our self it is the thing to do, we always find some "good reason" for not doing it.

And when people/corporation cannot self discipline themselves that is when government pass laws & bylaws 7 make things illegal.
by tpobrienjr July 25, 2008 10:30 AM PDT
The UPenn cancer researcher who raised an alarm about cell phone usage, then recommended that people use Bluetooth headsets wasn't doing his homework.
A BT transceiver radiates 1, 10, or 100 milliwatts at 2.4 GHz, depending on the type of link. I suspect that 10 mW right at your ear for 8 or 10 hours a day would be equivalent to the RF exposure from a cell phone for an hour or so per day. In any case, it's in a different microwave band (closer to the microwave oven frequency) from the 1.8 GHz PCS that your cell phone uses. As to the courtesy aspect, it is outweighed by the distraction aspect. Hang up (or otherwise disconnect) and DRIVE.
Reply to this comment
by Hopalite July 25, 2008 4:02 PM PDT
I don't understand what the fuss is all about. I use a blue tooth headset when I'm driving and have never been distracted. My hands are free to drive and I still keep my eyes on the other drivers north, south. east and west of my car. I also am able to avoid erratic drivers and prepare defensive maneuvers for possible accidents. In addition; I keep an eye out for deer and other wild animals that live in the woods adjacent to routes 55 and 295. It's call multitasking or maybe higher intelligence then the doomsayers on this site. I taught my daughter and son to drive always on the defensive whether or not they are using their blue tooth headsets and they have not had an accident. I haven't had an accident since I was a first time driver in the 70's. I am now 56 years old and have had a clean driving record for over 35 years. I summit that those who have accidents while talking on their blue tooth cell phones have had accidents even before using the blue tooth device. Many people are always looking for someone or something to blame for their problems. You need to take the responsibility for your actions and stop blaming your problems on the blue tooth device.
Reply to this comment
by ahrensr July 26, 2008 7:48 AM PDT
"You need to take the responsibility for your actions and stop blaming your problems on the blue tooth device."

You need to take the responsibility for your actions and stop blaming your problems on the device you are using.

There, fixed it for you.
Reply to this comment
by shanedr July 26, 2008 11:26 AM PDT
When not at work calls can always be avoided. Turn the phone off! If you people don't stop letting your phones command your life and the lives of those around you it will force laws to be legislated that will seriously limit when and where calls can be received.

Remember the abuse of privilege always results in limiting those privileges. You're supposed to be an adult! Act like it!
Reply to this comment
by ahrensr July 26, 2008 11:32 AM PDT
What is your problem? My phone doesn't RULE anything. I use it as a tool, as do millions of others. As such, I need to use it, and have it available when I WANT it to be there!

Where do you see abuse of privilege? Don't be insane. The previous caller hit it well, use your phone properly, and don't LET it distract you, any more than you are distracted by dozens of other devices we use very day, some in our cars.

Cell phone laws are passed by overeager legislators that want to show that they are doing something.
by Thunderbuck July 28, 2008 1:12 PM PDT
ONE study suggested headsets are no more safer than handsets, but I think I know why that might have happened.

Early headsets had a bit of a learning curve, and many users may have been distracted just getting their headset on and working. Especially if they weren't wearing it when a call came in.

Just speaking for myself, yes, I DO feel safer using my BT headset. It's less distracting than having to hold a handset to my ear. I also have an easier time driving with both hands available to control the car.

I don't see how talking on a BT headset is any more distracting than conversing with OTHER PEOPLE IN THE CAR! Should we make that illegal, as well?

And on another note, I actually really dislike all these cell-phone laws. Not because I don't think it should be illegal, but because I think it already IS, in the form of "driving without due care and attention" laws. Such laws cover cell-phones, fast food, and cosmetics. Why not just enforce laws already on the books instead of creating new ones?
Reply to this comment
by Jordan Skylar August 3, 2008 4:38 AM PDT
You talk on the phone while driving, but try not to on a bus so you don't disturb people.

You should NOT be talking on the phone in either case. Concentrate on driving and talk when you get home or to your office. Don't disturb people in public places with your phone calls. That includes many more spots than a bus. I get annoyed when people use their cell phones in doctor's offices. I've asked them to use the phone outside. The same with other places, like libraries, movies, museums, etc. No one wants any more noise!
Reply to this comment
by pacman83 November 19, 2008 5:32 PM PST
I think what you wrote about the bluetooth was useful because it is good to know that people are hacking into them and adding additional fees to people's phone bill. Also that it is a good idea to change the default password and turn off the head set when you are not using it. This even relates to myspace accounts and email accounts because people can hack into them if you do not periodically change your password. I do not think people should be talking on the phone while they are driving because this can cause an accident because it distracts them.
Reply to this comment
Showing 1 of 2 pages (31 Comments)
advertisement

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right