<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/4478/nrf51-s110-block-bonding-allow-access-to-some-services</link><description>Hello 
 I&amp;#39;m developing software for beacon-type device based on NRF51822. It has no buttons or other user inputs. Our use case: 
 User buy beacon-device. First phone which connect and bonds to beacon is saved in and has access to all BLE services. Other</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 19 Nov 2014 19:54:36 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/4478/nrf51-s110-block-bonding-allow-access-to-some-services" /><item><title>RE: NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/thread/15888?ContentTypeID=1</link><pubDate>Wed, 19 Nov 2014 19:54:36 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3c79bc2d-7f63-49ac-86c4-67d5acce1cd8</guid><dc:creator>Mathew Juzwiak</dc:creator><description>&lt;p&gt;Now I know, it&amp;#39;s impossible to block ONLY bonding new devices, and my fix does not contain any terrible bug (ie, bypass it simply). We&amp;#39;ll consider Your proposed options and security issues. Thank You for answer.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/thread/15885?ContentTypeID=1</link><pubDate>Wed, 19 Nov 2014 15:14:33 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:38579d59-82aa-42e9-8b1a-b14165db55d6</guid><dc:creator>Petter Myhre</dc:creator><description>&lt;p&gt;Is your device on when it is bought? Is it a concern that an attacker can bond with the device before the user can?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/thread/15887?ContentTypeID=1</link><pubDate>Wed, 19 Nov 2014 15:13:36 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:15d03cff-3628-47fc-b35e-94d39d326ebb</guid><dc:creator>Petter Myhre</dc:creator><description>&lt;p&gt;I can&amp;#39;t see why your quick fix shouldn&amp;#39;t work, but it depends on your application.&lt;/p&gt;
&lt;p&gt;As you have understood you can’t use whitelisting which means that anyone can connect to your device, blocking you from connecting to it. The attacker will only be disconnected when he tries to pair, but he can always reconnect.&lt;/p&gt;
&lt;p&gt;This could for example be solved by using whitelisting in general, but not the first 60 seconds after a reset. In the first 60 seconds you can connect and insert your secret code.&lt;/p&gt;
&lt;p&gt;Another option is to disconnect devices that don’t try to pair, after a certain time period.&lt;/p&gt;
&lt;p&gt;I&amp;#39;m assuming that you have thought of this, but please ensure that your device is protected from brute force attacks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/thread/15884?ContentTypeID=1</link><pubDate>Tue, 18 Nov 2014 15:02:02 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:dd21a753-6550-4897-885a-0fea026b8f4b</guid><dc:creator>Mathew Juzwiak</dc:creator><description>&lt;p&gt;Power off and on device? Access to device might be hard, but we can assume that yes, he can.
Edit. But device can be also reseted by non-authorized person, and must be protected against it.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NRF51 + S110: Block bonding, allow access to some services</title><link>https://devzone.nordicsemi.com/thread/15886?ContentTypeID=1</link><pubDate>Tue, 18 Nov 2014 14:56:16 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:c32f714f-5d50-4970-825a-c9256afbbd40</guid><dc:creator>Petter Myhre</dc:creator><description>&lt;p&gt;Can the user reset the device?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>