BlueBorne and the Importance of Software Upgradeable Security - From Silicon Labs
A collection of Bluetooth vulnerabilities named “BlueBorne” has just been made public by the security research company Armis. The vulnerabilities have been disclosed responsibly, which means that vendors have had time to issue security patches. Therefore, please update and patch all Bluetooth-products based on Android, Windows, iOS or Linux! And if in doubt, follow best practice and update all smart products regardless of protocol and software platform.
The vulnerabilities are not in the Bluetooth standard itself, but rather in the specific implementations of the Bluetooth standard. The Silicon Labs Bluetooth implementation is different from the affected implementations, and without the bugs that BlueBorne exploits. Therefore, products based on our Bluetooth software are immune to BlueBorne.
As a note, fighting BlueBorne shows the importance of being able to software upgrade connected devices, as discussed here:
http://www.newelectronics.co.uk/electronics-technology/the-iot-requires-upgradable-security/156211/
References:
https://www.armis.com/blueborne/
https://www.wired.com/story/turn-off-bluetooth-security/
https://techcrunch.com/2017/09/12/new-bluetooth-vulnerability-can-hack-a-phone-in-ten-seconds/