Received: by 2002:a05:7412:b10a:b0:f3:1519:9f41 with SMTP id az10csp317470rdb; Thu, 30 Nov 2023 05:48:39 -0800 (PST) X-Google-Smtp-Source: AGHT+IGMcUwTbXviWzAzLfNf54ON9tOwdt2vp9nuOnsU3jrObi4JzqtvffQ3bFxE1a9L3CD2PINQ X-Received: by 2002:a9d:77d6:0:b0:6d6:4d8f:56d6 with SMTP id w22-20020a9d77d6000000b006d64d8f56d6mr22874145otl.13.1701352119251; Thu, 30 Nov 2023 05:48:39 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1701352119; cv=none; d=google.com; s=arc-20160816; b=bzhSO92gs4W4aWrvWqOM6hZQ+40qkf3Kq4TO4R0EbkqL2ZbLdZ7VNmA+FQMrGfR/8q t5IQLjBdJxvJFNZPTmeRZgd7SRFSRlQg+QRPjJ6HjoBjoQlMNauKAwBMxR5Y5tpvnb03 0dzisk9oP5g9lGx/V5DOKJNoTZpNi4FVAzGGJa6pKXA5orMdqyWuTHvqWTlllit1Anyr Uh2sKWzbOQoVLJSG61VYwAnY30h6PoE+0hkd2lPzFBUAUqHTbrbPyJpNb171LgJ+y5ML f1IHyC1jYowgduk7/RPcQE5sd6rxA910SUnTu61BexgLEigec3O2081Gr5tdb6zF+jh5 4rFg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:subject:from:to:content-language :user-agent:mime-version:list-unsubscribe:list-subscribe:list-id :precedence:date:message-id; bh=UP4AVvk6KmYZ8ue5cNpDmBNjovkbDrA6fH/xbwqyMFo=; fh=4lGQI6056MBa4/oovMyIYaKLn+Wz/24RGvUivMmQP8E=; b=RvEOi8rQeRh4YApSL3XNYc8tyI+35qL7UBH13W9mpra8f0WHEUJS8UlINz9ebYLDLZ KV+4er3uxlIsoPn8Op3WxCDp7ACtItyTxce+8It77w14OhlP7jaOgkM8uQ89GwuME8sq AGv+euF/jBftLUmjuyChv/tE+qIZNqYj7A7Ct4qVcZPD6Kog0evh1Vjsbd6SO/em714F TD7QKQpPSRFOlgMpk0SNCIEi4xM6i6Jzrx8Xx/ieVT6O2DT6isZJJrG2Yx3IchtbSxRK cHKKt9Swj0L9MEyvPO+k/qVs6y/6xoyYJi9AIwI46mOD7FnVnAdmtrBlQGPLQCRXu78l 1rIQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-bluetooth+bounces-308-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.48.161 as permitted sender) smtp.mailfrom="linux-bluetooth+bounces-308-linux.lists.archive=gmail.com@vger.kernel.org" Return-Path: Received: from sy.mirrors.kernel.org (sy.mirrors.kernel.org. [147.75.48.161]) by mx.google.com with ESMTPS id bs132-20020a63288a000000b005be0f40b55csi1268259pgb.488.2023.11.30.05.48.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Nov 2023 05:48:39 -0800 (PST) Received-SPF: pass (google.com: domain of linux-bluetooth+bounces-308-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.48.161 as permitted sender) client-ip=147.75.48.161; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-bluetooth+bounces-308-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.48.161 as permitted sender) smtp.mailfrom="linux-bluetooth+bounces-308-linux.lists.archive=gmail.com@vger.kernel.org" Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sy.mirrors.kernel.org (Postfix) with ESMTPS id A0FE0B21041 for ; Thu, 30 Nov 2023 13:48:29 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id C3DE3482E6; Thu, 30 Nov 2023 13:48:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=none X-Original-To: linux-bluetooth@vger.kernel.org Received: from mx3.molgen.mpg.de (mx3.molgen.mpg.de [141.14.17.11]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 65CBE194 for ; Thu, 30 Nov 2023 05:48:18 -0800 (PST) Received: from [141.14.220.40] (g40.guest.molgen.mpg.de [141.14.220.40]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: pmenzel) by mx.molgen.mpg.de (Postfix) with ESMTPSA id 0E41C61E5FE03 for ; Thu, 30 Nov 2023 14:48:15 +0100 (CET) Message-ID: <352db44d-7ed9-48ee-8f44-1fcd0e75768c@molgen.mpg.de> Date: Thu, 30 Nov 2023 14:48:14 +0100 Precedence: bulk X-Mailing-List: linux-bluetooth@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Content-Language: en-US To: linux-bluetooth@vger.kernel.org From: Paul Menzel Subject: BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses (CVE-2023-24023) Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Dear Linux Bluetooth folks, Probably you are already aware of BLUFFS [1], published on November 27th, 2023. Kind regards, Paul [1]: https://francozappa.github.io/post/2023/bluffs-ccs23/