Skip to content

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reversing and Attacking Google Nearby #2198

Closed
maciejkrolik opened this issue Nov 27, 2023 · 2 comments
Closed

Reversing and Attacking Google Nearby #2198

maciejkrolik opened this issue Nov 27, 2023 · 2 comments
Labels
type: question General questions (we may not have time to provide an answer)

Comments

@maciejkrolik
Copy link

Hello, I came across an article about reversing and attacking Google Nearby. Scripts used to attack Google Nearby are 5 years old. Has the issue already been addressed? Is it still a problem?
https://francozappa.github.io/project/rearby/
https://www.cs.ox.ac.uk/files/10367/ndss19-paper367.pdf

@maciejkrolik maciejkrolik added needs-triage Issue still needs to be assigned, labeled and deduplicated type: question General questions (we may not have time to provide an answer) labels Nov 27, 2023
@Xlythe
Copy link
Collaborator

Xlythe commented Dec 8, 2023

The attacks in the paper relied on clients ignoring the authentication tokens provided by Nearby Connections and blindly connecting to devices. To avoid man-in-the-middle attacks, it's important that both sides have an opportunity to verify the token (or to treat all data as unencrypted until the token is confirmed, if you accept first).

It's been a while since I read the paper, so I'll take some time to do a refresher to make sure I didn't miss anything.

@bkmgit
Copy link

bkmgit commented Jan 19, 2024

@maciejkrolik Would there be interest in standardizing the protocol? For example through an IETF RFC. This would possibly:

@bourdakos1 bourdakos1 removed the needs-triage Issue still needs to be assigned, labeled and deduplicated label Apr 16, 2024
@google google locked and limited conversation to collaborators Apr 16, 2024
@bourdakos1 bourdakos1 converted this issue into discussion #2448 Apr 16, 2024

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

Labels
type: question General questions (we may not have time to provide an answer)
Projects
None yet
Development

No branches or pull requests

4 participants