|
|
|
|
|
by lucb1e
3486 days ago
|
|
I was not aware of this[1], thanks for linking. Do you know whether the same is true for non-LE connections? I always thought those were secure, provided there are no bugs in the implementations. [1] The paper's conclusion summarizes very nicely, though they write it formally and a little confusingly: the thing is utterly broken. They can read contents, even if they key exchange was not observed/captured, and they can inject traffic. Basically it's obfuscated plain text. |
|