Firmware Insider Bluetooth Randomness is Mostly Random
2
RNG Variants 2 and 3
3
RNG Variant 2, PRNG Fallback
4
How random is the PRNG?
5
Optimizations
6
Uploading Random Data into the Cloud
7
HRNG Measurements
8
But what about the variants???
9
Variant 5
10
Variant 4: PRNG Inputs
11
Time Inputs
12
Signal Processing Inputs (1)
13
Where is randomness used anyway?
14
Active MITM on Numeric Comparison
15
The Patch (June 2020 Patchlevel)
16
Responsible Disclosure
17
Crystal Ball Security
18
Lessons Learned
Description:
Explore the intricacies of Bluetooth randomness in this 25-minute presentation by Jiska Classen at WAC 2020. Delve into various RNG variants, including the PRNG fallback mechanism and its randomness. Examine optimizations, cloud data uploads, and HRNG measurements. Investigate different variants, focusing on Variant 5 and Variant 4's PRNG inputs. Understand the role of time inputs and signal processing in randomness generation. Learn about randomness applications, active MITM attacks on numeric comparisons, and recent security patches. Gain insights into responsible disclosure practices and contemplate future security challenges in Bluetooth technology.
Firmware Insider- Bluetooth Randomness is Mostly Random