Privacy Watch: Cell Phones Get Chatty With Hackers
One Bluetooth attack essentially turns your wireless phone into a bugging device.
Andrew Brandt
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Earlier this year, two security researchers, Adam Laurie and Martin Herfurt, created a collection of hacks they call BlueSnarfing that enabled them to stealthily duplicate the address book, call records, photos, and text messages from certain phone models.
The development is particularly disturbing, Laurie says, because phones are increasingly being used to store sensitive information such as passwords and PIN numbers.
In one demonstration they call BlueBugging, the two researchers forced a targeted phone to call a phone of their own. That transforms the victim's phone into a bugging device, at least until the victim realizes that the phone is connected to another one.
In addition, criminals might use BlueBugging to commit fraud, Laurie says. For example, an attacker could force victims' phones to dial a phone service that bills per call or per minute. You wouldn't know that you'd been ripped off until you got your phone bill--and then you'd have to convince your phone company that it wasn't you who called a psychic hotline 40 times.
Laurie, who is chief security officer and director of The Bunker Secure Hosting in southern England, says Bluetooth-enabled consumer electronics products complicate his job of protecting sensitive data. He notes that, because radio waves pass through walls, "you don't have to be visible to the person you're targeting."
Not all Bluetooth phones are susceptible to the attacks. The researchers haven't tested many different handsets, but the ones that they have checked out are among the most popular models, and Laurie estimates that 50 to 70 percent of Bluetooth phones are open to one or more BlueSnarfing attacks. Click here (for a complete list of vulnerable phone models.)
Nokia is reportedly working on a plan to fix the problem by updating the firmware in customers' phones, but it hasn't released details. Sony Ericsson spokesperson Peter Bodor says that customers can bring any of the company's at-risk handsets (the T610, T628, T630, and Z600 models share the same vulnerability) to any service center for a firmware update to fix the problem.
In the meantime, if you are not using your cell phone's Bluetooth feature, turn it off entirely. Not only will you protect your privacy, but you will prolong the phone's battery life, as well.
Andrew Brandt is a senior associate editor for PC World. You can send him e-mail at privacywatch@pcworld.com.
Laptop Showcase
VoIP Web Demo
Related Phones Articles
- Apple Can 'Kill' iPhone Apps Remotely, Or Can It? Apple "kill switch" found in iPhone 2.0 OS causes stir as developers ponder why it's there.
- On the Road: Tote a Laptop or Grab a Handheld? Can users leave their laptops in the office when they travel? Maybe not just yet.
- Review: Facebook 1.1 for IPhone Facebook for iPhone is currently the most popular social-networking application on the App Store.
- Clever iPhone Tricks Did you know you can dictate e-mail messages to your iPhone? That's just one of the tricks up our sleeves.
- Fifteen Countries Due to Get IPhone 3G in August Brace yourself: the onslaught is at hand. Last month, in Apple's Q3 conference call, Tim Cook said that Apple was still on...
Best Prices on PDAs
N810 Internet TabletPrice: $349.99
TX Handheld PDAPrice: $159.96
Reader Digital Book - SilverPrice: $269.99
PRS-505/LC Reader Digital Book - Dark BluePrice: $285.18
iPAQ 111 PDAPrice: $239.95
Tungsten E2 Handheld PDAPrice: $109.96
- Myth of the Million Dollar Database Think only the big boys can afford the best database solutions? Think again. Learn about low cost systems that have proven time and time again to outperform legacy UNIX vendors on a dollar for dollar basis.
- The Future Sales Force - A Consultative Approach This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ in today's evolving market.




