TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

AirPods fast connect security vulnerability

312 pointsby memalign11 months ago

14 comments

jessriedel11 months ago
&gt; Its main purpose seems to be reducing the time it takes to establish a connection between two Apple devices from roughly 1 second down to about 0.5 seconds.<p>&gt; With this trick, they can establish that both devices are speaking the Fast Connect protocol without violating the Bluetooth specification, and then go on to exchange 3 more back-and-forth messages, negotiating all the things necessary to fully connect the two devices.<p>&gt; The fact that this only takes 4 messages back-and-forth in total is what makes Fast Connect fancy, because usually in Bluetooth the phase of wiring up the individual channels for a connection is quite a complex negotiation and involves sending various SDP descriptors that describe which protocols&#x2F;features both sides support.<p>Two devices in the same room communicating over even a very narrow slice of the electromagnetic spectrum could exchange many thousands of messages per second. What is it about Bluetooth that causes each message to take a hundred milliseconds rather than, say, a microsecond? What is setting the timescale for this process?
评论 #40834659 未加载
rock_artist11 months ago
&gt; That’s because AirPods auto-update their firmware by themselves, but only when they’re used together with an iPhone or MacBook, so Android users have no easy way to update their firmware.<p>From what I remember, advantage of affected Beats devices which also use same chip is they can actually be updated from the beats app on Android
评论 #40833416 未加载
worstspotgain11 months ago
The Apple Support link given in the article is for what looks like the Indian version. Here&#x27;s the US version:<p><a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;106340" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;106340</a><p>The US version shows different version numbers for the latest firmware, e.g. for the Airpods Pro 2nd Gen it&#x27;s 6F8, while in India it&#x27;s 6B34.
a1o11 months ago
Very nice write-up<p>&gt; ... see if I could get all the functionality working on Linux as well. ... I’ll talk about the specifics in another blog post ...<p>I am super curious to read when you do write-up about implementation of this functionality in Linux! Thanks for that and I will refresh the blog until that is written :)
sebazzz11 months ago
So my Airpods 2 have an outdated firmware version, but as a user I can&#x27;t explicitly have iOS update the firmware, and there is no indication when an update happens. I wish I would have more control.
评论 #40836817 未加载
评论 #40837956 未加载
评论 #40837804 未加载
评论 #40837174 未加载
schrodinger11 months ago
Obviously any vulnerability is bad, but I&#x27;m trying to understand just how bad this one is. What &quot;scary&quot; things could an attacker do?<p>It doesn&#x27;t sound like they could listen in on a phone call you&#x27;re having without your knowledge, or even an audio stream, since it breaks the original connection, right? So is the worst they could do is come within a pretty short distance of you, scan for your mac address, and the auto-connect and play some noise into your ears? Or is there more?<p>I suppose you could do something like take over the airpods of a high-level celebrity or politician while they&#x27;re on a video call, that could be bad (but caught instantly). Anything worse?
评论 #40834234 未加载
评论 #40835394 未加载
评论 #40833878 未加载
评论 #40833866 未加载
zeroz11 months ago
Settings &gt; Bluetooth &gt; Your AirPods (click on [i]) shows the version, even if AirPods are not actively connected.<p>6A326 seems to be the version including the fix.<p><a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT214111" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT214111</a>
评论 #40833859 未加载
StrLght11 months ago
I understand that chances are pretty slim but I still hope that this will make Apple do something regarding AirPods updates on other OSes or at least on Android.
diebeforei48511 months ago
There is no manual update option. Auto-update is the only way to update, and it&#x27;s unclear how to cajole it to auto-update.
评论 #40833498 未加载
bagels11 months ago
One more advantage of wired headphones in addition to them not running out of batteries.
评论 #40835862 未加载
hsbauauvhabzb11 months ago
I’ve got numerous gripes with AirPods under Linux - range doesn’t seem as good as my phone (I’ve tried multiple dongles etc), I wasn’t aware that you could connect to two devices but now I want that, when the microphone is enabled audio sounds absolutely trash. Oddly enough, the connect speed annoyed me but not as much as the other issues.<p>Are there any alternative headphones that solve all three of these well? I just want a headset that works.
评论 #40835859 未加载
评论 #40835194 未加载
评论 #40835408 未加载
cjk211 months ago
I didn&#x27;t even know about this vulnerability and mine are updated. Just how I like things.
nubinetwork11 months ago
&gt; Its main purpose seems to be reducing the time it takes to establish a connection between two Apple devices from roughly 1 second down to about 0.5 seconds<p>Oh no, I&#x27;ll never get that 0.5 seconds back... &#x2F;s
resource_waste11 months ago
Hard to think of a company with as poor security as Apple. No one else hits the headlines as much and creates so much real world consequences.