BreakMi: Reversing, Exploiting & Fixing Fitness Tracking Ecosystems by M. Casagrande & D. Antonioli

  Переглядів 1,167

hardwear.io

hardwear.io

9 місяців тому

Abstract:
---------------
Xiaomi is the leading company in the fitness tracking industry. Successful attacks on its fitness tracking ecosystem would result in severe consequences, including the loss of sensitive health and personal data. Despite these relevant risks, we know very little about the security mechanisms adopted by Xiaomi. In this work, we uncover them and show that they are insecure. In particular, Xiaomi protects its fitness tracking ecosystem with custom application-layer protocols spoken over insecure Bluetooth Low-Energy (BLE) connections (ignoring standard BLE security mechanisms already supported by their devices) and TLS connections. We identify severe vulnerabilities affecting such proprietary protocols, including unilateral and replayable authentication.
Those issues are critical as they affect all Xiaomi trackers released since 2016 and up-to-date Xiaomi companion apps for Android and iOS. We show in practice how to exploit the identified vulnerabilities by presenting six impactful attacks. Four attacks enable to wirelessly impersonate any Xiaomi fitness tracker and companion app, man-in-the-middle (MitM) them, and eavesdrop on their communication. The other two attacks leverage a malicious Android application to remotely eavesdrop on data from a tracker and impersonate a Xiaomi fitness app.
Overall, the attacks have a high impact as they can be used to exfiltrate and inject sensitive data from any Xiaomi tracker and compatible app. We propose five practical and low-overhead countermeasures to mitigate the presented vulnerabilities. Moreover, we present BreakMi, a modular toolkit that we developed to automate our reverse-engineering process and attacks. breakmi understands Xiaomi application-layer proprietary protocols, reimplements Xiaomi security mechanisms, and automatically performs our attacks. We demonstrate that our toolkit can be generalized by extending it to be compatible with the Fitbit ecosystem. We will open-source BreakMi.
#miwatch #hardwaresecurity #mitm #hardwear_io #hw_ioUSA2023
------------------------------------------------------------------------------------------------------
Website: hardwear.io
Twitter: / hardwear_io
LinkedIn: / hardwear.io-hardwarese...
Facebook: / hardwear.io

КОМЕНТАРІ: 2
@jaines2927
@jaines2927 9 місяців тому
Great 👏👏
@michaelzhou5095
@michaelzhou5095 8 місяців тому
any research on ble protocol of xiaomi band 7 tracker?
LIVE - Парад Победы в Москве. 9 Мая 2024
2:27:56
AKIpress news
Переглядів 2,2 млн
ШАХТАР - ДИНАМО. КОМЕНТУВАННЯ. УПЛ. 28 ТУР
4:04:31
Артем Пивоваров х Klavdia Petrivna - Барабан
03:16
Artem Pivovarov
Переглядів 8 млн
Best OS for programming? Mac vs Windows vs Linux debate settled
8:40
How to create AI agents that don't suck
1:11:15
Beeloud
Переглядів 1,2 тис.
I Built a Wildlife Pond - here's what happened
15:11
Stefano Ianiro
Переглядів 22 млн
Meet a 12-year-old hacker and cyber security expert
5:01
CBS Mornings
Переглядів 7 млн
Day in the Life of a Cybersecurity Student
5:28
Grant Collins
Переглядів 3,8 млн
DoDIIS 2017- Teddy Bear Hacking with 11/ yo Cyber Prodigy Reuben Paul
9:46
How Neuralink Works 🧠
0:28
Zack D. Films
Переглядів 26 млн
Airpods’un Gizli Özelliği mi var?
0:14
Safak Novruz
Переглядів 1,9 млн