# 061 - A Case of the Sniffles Page: https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/061-a-case-of-the-sniffles Text version: https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/061-a-case-of-the-sniffles.md Podcast: [Unnamed Reverse Engineering Podcast](https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753) Published: 2022-11-09T05:54:24+00:00 Episode link: https://reverseengineering.libsyn.com/061-a-case-of-the-sniffles Audio file: https://traffic.libsyn.com/secure/reverseengineering/061_-_A_Case_Of_The_Sniffles.mp3?dest-id=552832 Processing state: processed JSON: https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/061-a-case-of-the-sniffles Duration seconds: 3600 ## Resource A deep dive into Bluetooth Low Energy (BLE) security, focusing on the development of the Sniffle tool and the mechanics of relay attacks. Guest Sultan Qasim Khan explains how low-level sniffing reveals firmware bugs and vulnerabilities in proximity-based authentication. ## Highlights - Main idea: Low-level BLE sniffing is essential for debugging firmware bugs that higher-level stack captures miss - Practical takeaway: Using tools like Sniffle with Wireshark plugins allows for real-time analysis of Bluetooth 5 features - Failure mode: Relay attacks can trick proximity-based systems, like car key fobs, by forwarding signals between a legitimate key and a target - Technical insight: Modern defenses against relay attacks include implementing distance-bounding or time-of-flight ranging checks - Lesson: Security vulnerabilities are frequently found in the less-traveled, unexamined parts of a protocol implementation ## Topics Bluetooth Low Energy, Reverse Engineering, Cybersecurity, Relay Attacks, IoT Security, Packet Sniffing, Firmware Analysis, Protocol Security ## Chapters - 1:00 — Introduction and Background: Sultan Qasim Khan discusses his transition from software development to reverse engineering via Linux driver porting. - 5:00 — The Origins of Sniffing: A look at the early tools used for USB and Bluetooth analysis and the challenges of hardware-level debugging. - 10:00 — Improving Ubertooth Firmware: Addressing limitations in channel mapping and firmware capabilities for better packet capture. - 14:00 — The Sniffle Toolset: How Sniffle provides support for high-bitrate BLE and integrates with Wireshark for protocol analysis. - 19:00 — Decoding the BLE Stack: The technical difficulties of handling preambles, access addresses, and simultaneous transmissions. - 28:00 — IoT Provisioning Vulnerabilities: How BLE is used in IoT setup processes and the risks of firmware bugs in integrated controllers. - 32:00 — Mechanics of Relay Attacks: An explanation of how attackers bypass proximity authentication in cars and smart locks. - 37:00 — Defending Against Proximity Fraud: Discussing ranging checks and hardware-level solutions to prevent signal forwarding attacks. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/unnamed-reverse-engineering-podcast-752753/episodes/061-a-case-of-the-sniffles/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/unnamed-reverse-engineering-podcast-752753/061-a-case-of-the-sniffles.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.