This post is older than 2 years and might not be relevant anymore
More Info: Consider searching for newer posts

does static passkey provide MITM protection after BLE4.2 ?

BLUETOOTH SPECIFICATION Version 5.0 | Vol 3, Part H page 2321 Figure 2.4

According to the figure, if an eavesdrop device exists in the pairing process, it is easy to obtain Cai, Nai, PKA, and PKb. It should not be difficult to obtain rai, and thus ra, that is, passkey.

Is it impossible to provide MITM protection,If I use static passkey.Or I understand the mistake.

Parents Reply
  • Just like Turbo J said, the MitM has all that is needed to perfectly fake the device once the static password is known.

    As I said in the question, getting a static passkey doesn't seem to be difficult, just need a sniffer ?

    So I think the static passkey cannot provide MITM protection. But there are many static passkey usages in the community, but I don't understand what the purpose of doing so is.

Children
No Data
Related