# to get your ass hacked

**URL:** <https://boards.straightdope.com/t/to-get-your-ass-hacked/797909>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [October 4, 2017, 1:19am UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909 "2017-10-04T01:19:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![eschereal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/eschereal/32/18939_2.png) [@eschereal](https://boards.straightdope.com/u/eschereal)\
**Post date:** [October 4, 2017, 1:19am UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/1 "2017-10-04T01:19:54Z")

</div>

Due to scenes of a sexual nature,

[spoiler]Apparently, probably not too surprisingly, some new toys have been outfitted with Bluetooth[spoiler]Yes, _those_ kind of toys. It seems as though some people enjoy designing and sharing vibration patterns, and/or, perhaps, remote activation.

There is the issue: _remote activation_. The toys have zero security, so, theoretically, just about anyone happening by within range could fuck with someone else’s toy. They even have a name for that, [screwdriving](https://arstechnica.com/information-technology/2017/10/screwdriving-many-bluetooth-sex-toys-leave-users-vulnerable/)

> [@](#):
>
> … reverse-engineering the control messages between apps and a number of devices was not terribly difficult—the communications between the apps and the toys were not encrypted … (Alex) Lomas noted that while walking in Berlin recently with a Bluetooth discovery app on his phone, “I was genuinely surprised to see the Hush BLE name, LVS-Z001, pop up.”

So, if you happen to be using one of these things, be mindful of your surroundings. That is, unless that sort of thing sounds appealing …[/spoiler][/spoiler]

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [October 4, 2017, 4:12am UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/2 "2017-10-04T04:12:49Z")

</div>

There’s just [no telling what devices your Bluetooth might discover](http://www.fieldbrook.net/TechTips/images/Bluetooth_Airbus.jpg).

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [October 4, 2017, 1:37pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/3 "2017-10-04T13:37:16Z")

</div>

About 17 years ago I was visiting the US research lab for a major Japanese electronics company.

They were really big on Bluetooth for connecting everything. I read up on it.

Holy cow, what a terrible protocol. They actually thought consumers _wanted_ to watch ads for a store on their phones as they passed by it! The protocol was connection friendly and then some.

So it’s no surprise that there are [terrible security problems](https://mobile.slashdot.org/story/17/09/12/2030213/blueborne-vulnerabilities-impact-over-5-billion-bluetooth-enabled-devices)\* with lurking behind every corner.

- The only security “fix” for this is to turn Bluetooth off.

---

<div class="post-metadata">

**Author:** ![Gatopescado](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gatopescado/32/5711_2.png) [@Gatopescado](https://boards.straightdope.com/u/Gatopescado)\
**Post date:** [October 4, 2017, 1:57pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/4 "2017-10-04T13:57:23Z")

</div>

I don’t understand, and am afraid of this Brave New World.

---

<div class="post-metadata">

**Author:** ![eschereal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/eschereal/32/18939_2.png) [@eschereal](https://boards.straightdope.com/u/eschereal)\
**Post date:** [October 4, 2017, 2:00pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/5 "2017-10-04T14:00:59Z")

</div>

> [@ftg](#):
>
> - The only security “fix” for this is to turn Bluetooth off.

I have learned that, in the latest version of Apple’s iOS, you cannot actually turn off BT from the quick-control screen. You have to do it in the Settings app. Turning it off from the control screen only disables discoverability.

---

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [October 4, 2017, 2:15pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/6 "2017-10-04T14:15:18Z")

</div>

If this gets popular, it could make it interesting to walk through the Adult Entertainment Electronics Convention in Las Vegas. You could, with the right hookup, experience different things as you pass by every booth.

And, of course, receive the same results, unwanted, when you walked by practitioners outside.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [October 4, 2017, 2:34pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/7 "2017-10-04T14:34:59Z")

</div>

I note that the issue was discovered by a company that specializes in penetration testing.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [October 4, 2017, 3:41pm UTC](https://boards.straightdope.com/t/to-get-your-ass-hacked/797909/8 "2017-10-04T15:41:26Z")

</div>

2004: UFIA.  
2017: UBIA.

(gotta put some lowercase in. stupid software.)
