news
The hidden cost of today's "smart" devices
Quoting: The hidden cost of today's "smart" devices — Free Software Foundation — Working together for free software —
Audio headsets that connect to computers wirelessly via Bluetooth demonstrate how quickly this loss of control turns into a security problem. Millions of Bluetooth-capable products utilize Google's "Fast Pair" service, which is nonfree software that promises to make pairing of wearable devices easier. It uses Bluetooth Low Energy and Android’s location services to detect nearby Bluetooth devices automatically and prompts you to pair. Security researchers discovered this feature was really a bug, as it introduced a serious weakness across a wide range of devices. This included wireless earbuds and headphones from major manufacturers, which could be turned into surveillance machines. Attackers could silently pair with these devices and hijack the audio to spy on the person wearing them, as well as anyone they spoke to. In some cases, the microphone could be activated and the wearer could be tracked through Google's own network.
What makes this so troubling is that researchers did not have access to the source code needed to inspect how Fast Pair worked. Instead, discovering the flaws required independent researchers to reverse engineer the nonfree software. This difficult and time-consuming process would not have been necessary if the software were free and available for anyone to study and improve.
The problem was not confined to one device model or a single vendor, and it is likely that many devices around the world are still vulnerable. Worse, most users will be unable to patch their device without utilizing nonfree software from the manufacturer or Google to run an update. Instead of giving users the freedom to modify and improve, they are forced to trust nonfree software that cannot be easily inspected.