Contact Tracing: Beware of Bluetooth Vulnerabilities

Contact tracing: Beware of Bluetooth Vulnerabilities | Total Security Software


With the trend of contact tracing applications, attacks exploiting Bluetooth vulnerabilities are likely to increase. It is, therefore, necessary to ensure the security of such applications. Security researchers are also advising all users to update their mobile devices to ensure they fix any past security vulnerabilities.

As more governments turn to track apps to help them in their efforts to contain the coronavirus, cybersecurity experts warn it could spark renewed interest in Bluetooth attacks. They urge developers to ensure that these applications are regularly tested for their vulnerabilities and to promptly release patches to address potential gaps, while governments should ensure their databases are secure and data collected will not be used for purposes other than those originally intended.

Users should also take the necessary steps to safeguard their personal data and prevent their devices from becoming targets of cybercriminals

Bluetooth vulnerability

According to Stas Protassov, co-founder and president of technology at Acronis, Bluetooth has already exhibited several vulnerabilities in the past, including last February when Blue Frag, a critical vulnerability that affected Android devices, was patched. This kind of problem has also happened on iOS devices several times.

Stas Protassov warns: if these flaws are not fixed, devices can be hacked by nearby attackers, and the user's personal data can be stolen. It thus highlights the need for users to update their devices to ensure that vulnerabilities are fixed quickly. And as with any app, they should also check the permissions requested by these contact tracing apps.

You should only install official applications, ”he insists, adding that malicious applications resembling official applications are probably already under development and that they will be published shortly after the official applications.

The Example of Singapore

Governments should also ensure that back-end databases are secure and conduct regular application testing to limit the use of contact tracing applications. "Any personally identifiable information collected must be properly stored and encrypted," insists Stas Protassov, who adds that it would be preferable if the data is not stored at all. According to him, all possible precautions must be taken to avoid a massive data breach such as the one involving Equifax.

Singapore, where Acronis is headquartered, was cited as the government has been transparent about the national contact tracing application, TraceTogether. Governments, he said, should take the lead and make it clear what information these apps collect, how the data is collected, and who has access to it. In addition, the data should as far as possible be made anonymous, or at least pseudonymized. The Singapore government specifies that its TraceTogether app does not collect any location data and asks for the user's phone number during setup, which is owned by the Department of Health and stored in "a highly secure server" with a random anonymous identifier that is linked to the number cell phone.

When TraceTogether is running on the phone, it creates a temporary ID which is generated by encrypting the user's ID with a private key, which is held by the Department of Health. The temporary identifier is then exchanged with neighboring phones and renewed regularly, which makes it difficult to identify or link the temporary identifier to the user, details GovTech, the government agency behind the application. contact tracing. The temporary identifier can only be decrypted by the Department of Health, the agency adds, and the app shows connections between devices, not their location. This data log is stored on the phone of the

“Your phone will store temporary identifiers of neighboring phones, as well as information about the neighbor phone's model, Bluetooth signal strength, and time. All of this information is stored locally on your phone, and is not sent to the Department of Health unless your contact is traced, ”GovTech said.

Bluetooth, Easy Prey?

According to Samantha Isabelle Beaumont, senior security consultant at Synopsys Software Integrity Group, contact tracing applications allow cyberattackers to access users' Bluetooth, and thus read all bluetooth communications on their connected devices - including their car, music they listen to, their home IoT (Internet of Things) devices, among others.

It therefore recommends that users protect themselves by limiting various elements such as the number of applications they download, the number of BlueTooth elements with which they connect, the number of bluetooth elements that appear in "white list" - or in known devices - and the amount of information they transfer via bluetooth.

Conversely, the Singapore government believes that it is unlikely that hackers could break into a device without the knowledge of the targeted user. to use a computer to extract information from their phone without it. remark it ”. However, the agency urges users to make sure their phone's operating system is up to date.

Kevin Reed, head of information systems security at Acronis, adds that the developers do believe that the attack must be carried out in a close range, and that the devices

Guarantee Privacy After the Crisis

Beyond security and privacy, Zulfikar Ramzan questions fairness. And in particular, can the systems be implemented in such a way as to ensure that the data collected will not be misused and for purposes other than those originally intended?

For these apps to gain popularity and confidence, he stresses that governments should put in place checks and balances to reduce the likelihood that the data collected will be misused. In addition, organizations involved in the design of these systems and their components should have robust procedures in place to respond quickly to emerging security issues.

“Today we are living in a golden age of surveillance where our actions leave small digital stones behind them. And you make sure how to secure device with any kind of virus and malware and trojan attack we inform you because of you  protect your self with it total security Software and antivirus they secure your device with this kind of virus.


Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software