frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Bluetooth Headphone Jacking: A Key to Your Phone [video]

https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone
67•AndrewDucker•2h ago

Comments

swores•43m ago
I don't have time right now to watch the video and will be coming back to do so later, but here's a couple of snippets from the text on that page that made me want to bother watching (either they're overhyping it, or it sounds interesting and significant)

> The identified vulnerabilities may allow a complete device compromise. We demonstrate the immediate impact using a pair of current-generation headphones. We also demonstrate how a compromised Bluetooth peripheral can be abused to attack paired devices, like smartphones, due to their trust relationship with the peripheral.

> This presentation will give an overview over the vulnerabilities and a demonstration and discussion of their impact. We also generalize these findings and discuss the impact of compromised Bluetooth peripherals in general. At the end, we briefly discuss the difficulties in the disclosure and patching process. Along with the talk, we will release tooling for users to check whether their devices are affected and for other researchers to continue looking into Airoha-based devices.

[...]

> It is important that headphone users are aware of the issues. In our opinion, some of the device manufacturers have done a bad job of informing their users about the potential threats and the available security updates. We also want to provide the technical details to understand the issues and enable other researchers to continue working with the platform. With the protocol it is possible to read and write firmware. This opens up the possibility to patch and potentially customize the firmware.

dijit•39m ago
And everyone got mad at OpenBSD for refusing to develop bluetooth.

It’s a messy standard and we shouldn’t be surprised that the race to the bottom has left some major gaps.. though Sony WH1000’s are premium tier hardware and they have no real excuses..

I always wondered how people could justify the growth of the bluetooth headphone market in such a way.. Everyone seems to use bluetooth headphones exclusively (in Sweden at least), I’m guilty of buying into it too (I own both Airpods Pro’s and the affected Sony WH1000-XM5) but part of me has always known that bluetooth is just hacks on hacks… I allowed myself to be persuaded due to popularity. Scary.

I was also trying to debug bluetooth “glitching audio” issues and tried to figure out signal strength as the first troubleshooting step: I discovered that people don’t even expose signal strength anymore… the introspection into what’s happening extends literally nowhere, including not showing signal strength… truly, the whole thing is cursed and I’m shocked it works for the masses the way it does.. can you imagine not displaying wifi signal strength?

pyvpx•28m ago
Some of us kept using OpenBSD (longer than they should’ve?) because of that and a few other related decisions.

So who is everyone, in your meaning?

dijit•25m ago
It comes up enough that I am comfortable saying that it feels like “everyone” to the OpenBSD devs.

https://news.ycombinator.com/item?id=25950845

https://news.ycombinator.com/item?id=45798439

https://news.ycombinator.com/item?id=34667522

https://news.ycombinator.com/item?id=43144607

raverbashing•20m ago
Sometimes plugging a cord is a minor inconvenience.

But sometimes it's a large inconvenience

Example: if I'm using my laptop for work but at a slightly longer distance (think, using external monitor/keyboard) then it gets annoying (cord has to hang from the connection, or it gets between you and the keyboard, etc)

stefan_•18m ago
This is not a Bluetooth issue. The chip manufacturer Airoha just felt it acceptable to ship a wireless debug interface that allows reading the SoC memory with no authentication whatsoever, enabled in retail customer builds. They are just not a serious company (which is why their security email didn't work, either).
p0w3n3d•31m ago
Meanwhile all the phones dropping jack because Apple started it. Official reason is to "waterproof phones"
raverbashing•23m ago
Ah yes, the removal of headphone jacks, the gift that keeps on giving

Funny that there were always some people here pushing bt audio as "the future", whom I can only assume were the technically shallow but very opinionated people that would die on the smallest technical hills

NoiseBert69•16m ago
Thanks god the headphone jacks died in smartphones.

I switched to USB-C soundcard cables which are dirt cheap and survive much much more plug-unplug-cycles. They easily can be replaced.

raverbashing•4m ago
The epidemic of people not wearing headphones has been directly caused by the lack of headphone jacks
TheAceOfHearts•21m ago
Haven't watched the video yet, but I think this capability was leaked by VP Kamala Harris during her recent interview with the Late Night Show [0]. She stated she doesn't use wireless headphones because she's been in security meetings and knows they're not safe.

[0] https://youtu.be/BD8Nf09z_38 (Timestamp 18:40)

denysvitali•12m ago
Disclaimer: This comment is not intended to be political - I don't care about the specific party she's part of.

Out of all the people I would trust on the matter, Kamala Harris doesn't certainly end up at the top of my list, for reasons such as this one: https://youtu.be/O2SLyBL2kdM?si=Zq-EN8zxj4Y_UCwI

You also don't need to be in classified meetings to understand that Bluetooth/ BLE (and specifically the way most vendors implement the spec) is not as secure as other more battle-tested technologies

dijit•6m ago
I think many people would be justified in making the argument that bluetooth has existed for at least 20 years and thus is the established battle tested protocol.
ahoef•4m ago
What she says isn't necessary untrue, now is it? She just skips a lot of steps most people have no clue about.

I had files in a cabinet, now they are digital. And most often also on a cloud drive, which is metaphysical in some sense. For most it is indistinguishable from magic.

miduil•12m ago
Glad this submission is finally receiving upvotes.

This was just shown at the 39C3 in Hamburg, few days back.

Common (unpached) Bluetooth headsets using Airoha's SoCs can be completely taken over by any unauthenticated bystander with a Linux laptop. (CVE-2025-20700, CVE-2025-20701, CVE-2025-20702)

This includes firmware dumps, user preferences, Bluetooth Classic session keys, current playing track, ...

> Examples of affected vendors and devices are Sony (e.g., WH1000-XM5, WH1000-XM6, WF-1000XM5), Marshall (e.g. Major V, Minor IV), Beyerdynamic (e.g. AMIRON 300), or Jabra (e.g. Elite 8 Active).

Most vendors gave the security researchers either silent treatment or were slow, even after Airoha published fixes. Jabra was one of the positive outlier, Sony unfortunately negatively.

What is exciting, even though the flaws are awful, that it is unlikely for current generation of those Airoha bluetooth headsets to change away from Aiorha's Bluetooth LE "RACE" protocol. This means there is great opportunity for Linux users to control their Bluetooth headsets, which for example is quite nice in an office setting to toggle "hearthrough" when toggling volume "mute" on your machine.

RACE Reverse Engineered - CLI Tool: https://github.com/auracast-research/race-toolkit

I feel like this should receive state-level attention, the remote audio surveillance of any headset can be a major threat. I wonder what the policies in countries official buildings are when it comes to Bluetooth audio devices, considering that Jabra is a major brand for conference speakers, I'd assume some actual espionage threats.

Privacy aware layman understanding of cancer medical records using RAG and ML

https://understand-your-cancer-medical-records-in-layman-ese.vercel.app/
1•tuxguy•1m ago•0 comments

Sorting with Fibonacci Numbers and a Knuth Reward Check

https://orlp.net/blog/fibonacci-sort/
1•g0xA52A2A•1m ago•0 comments

What Happened in 2025

https://avc.xyz/what-happened-in-2025
1•wslh•8m ago•0 comments

Cinderella Stamp

https://en.wikipedia.org/wiki/Cinderella_stamp
2•bookofjoe•11m ago•0 comments

Show HN: LeadSynth – Capture leads at the exact moment they're looking

https://www.leadsynthai.app/
1•datamine007•12m ago•1 comments

Securing MCP Infrastructure

https://aliparnan.com/blog-mcp-security.html
1•aliparnan•22m ago•0 comments

Nokia went from iPhone victim to $1B Nvidia deal

https://www.ft.com/content/0a07cbc3-dac4-4b89-9f26-038deb833060
1•mmarian•23m ago•1 comments

Fountain pens are enjoying a revival among the digital generation

https://www.theglobeandmail.com/life/social-trends/article-fountain-pens-are-enjoying-a-revival-a...
1•pseudolus•23m ago•1 comments

One Number I Trust: Plain-Text Accounting for a Multi-Currency Household

https://lalitm.com/post/one-number-i-trust/
1•todsacerdoti•24m ago•0 comments

Starlink 2025 Progress Report

https://starlink.com/progress
1•davidgh•25m ago•0 comments

Dembrandt – Extract Design Systems in Seconds

https://www.dembrandt.com/
1•s4i•26m ago•0 comments

Corroded: Illegal Rust

https://github.com/buyukakyuz/corroded
1•christoph-heiss•33m ago•0 comments

Shipping publicly taught me more than months of "preparing to launch"

https://www.google.com/search?q=site:vect.pro&sca_esv=6ac9360805b83292&prmd=ivns&sxsrf=AE3TifMYbm...
1•afrazullal•34m ago•0 comments

Show HN: I built a weather alert system for photographers

https://app.photoweather.app/demo/live-demo
2•pontussw•35m ago•1 comments

AI and Open Source: A Maintainer's Take (End of 2025)

https://st0012.dev/ai-and-open-source-a-maintainers-take-end-of-2025
1•st0012•37m ago•2 comments

An LLM-Driven Multi-Agent Framework for Telescope Proposal Peer Review

https://arxiv.org/abs/2512.24754
1•TMEHpodcast•44m ago•0 comments

Instagram boss says the platform's polished feed is 'dead' thanks to AI

https://www.businessinsider.com/instagram-head-ai-images-polished-feed-dead-adam-mosseri-2026-1
2•pseudolus•45m ago•1 comments

The Accountability Trap: Why School Systems Abandon Gifted Students

https://wendyx3.substack.com/p/the-accountability-trap-why-school
1•barry-cotter•46m ago•1 comments

We've made an Open Source video platform

https://www.boostervideos.net
1•machimilah•47m ago•1 comments

Critique of Techno-Feudal Reason (2023) [pdf]

https://eclass.uoa.gr/modules/document/file.php/ECON969/Evgeny%20Morozov%20-%20Critique%20of%20Ne...
2•wslh•47m ago•0 comments

Destroying x86_64 instruction decoders with differential fuzzing

https://blog.trailofbits.com/2019/10/31/destroying-x86_64-instruction-decoders-with-differential-...
1•fanf2•47m ago•0 comments

Games in PostScript [pdf]

https://seriot.ch/ps_talk/gambiconf.pdf
2•beefburger•48m ago•0 comments

Brazil's largest lottery prize ever delayed due to 125k bets per second

https://manualdousuario.net/en/brazils-largest-lottery-prize-ever-postponed/
2•rpgbr•49m ago•0 comments

The NYC subway station chosen for Mamdani's swearing-in

https://www.npr.org/2025/12/31/nx-s1-5662726/mamdani-nyc-subway-station-history
2•wslh•50m ago•1 comments

Snoop Project Update (search for usernames on 5k websites)

https://github.com/snooppr/snoop/blob/master/README.en.md
1•zaharqoops•51m ago•0 comments

A Declaration of Interdependence

https://github.com/experimental-123/doi-2026
2•engiserstakr•53m ago•0 comments

Clojure: Transducers

https://clojure.org/reference/transducers
1•tosh•55m ago•0 comments

Real-life experiment shows Bohr was right in theoretical debate with Einstein

https://phys.org/news/2025-12-real-life-niels-bohr-theoretical.html
3•pseudolus•56m ago•0 comments

Meta made scam ads harder to find instead of removing them

https://sherwood.news/tech/rather-than-fully-cracking-down-on-scam-ads-meta-worked-to-make-them-h...
6•wtcactus•1h ago•0 comments

China's first real gaming GPU is here, benchmarks are brutal

https://www.howtogeek.com/are-chinese-gpus-coming-to-eat-nvidias-lunch/
3•msolujic•1h ago•0 comments