<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reject example LTK used by other side</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/49098/reject-example-ltk-used-by-other-side</link><description>I saw this BLE security issue and was wondering how Nordic deals with it. When the other side uses the example LTK from the BLE spec, can the softdevice automatically reject it or do I need to do something in my app to reject it? 
 https://cve.mitre.org</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 28 Jun 2019 07:06:33 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/49098/reject-example-ltk-used-by-other-side" /><item><title>RE: Reject example LTK used by other side</title><link>https://devzone.nordicsemi.com/thread/195264?ContentTypeID=1</link><pubDate>Fri, 28 Jun 2019 07:06:33 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2d668dfd-7a29-48d8-8d82-fd722f3c8149</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;The SoftDevice does not reject this LTK automatically. You can handle this in your application, which gets all pairing/bonding data from the SoftDevice (needed since the application is responsible for storing all bonding data (including the LTK)).&lt;/p&gt;
&lt;p&gt;But I wonder why you want to do this? It makes sense for Windows (and other PC and mobile operating systems) to block this LTK, as it has been used in a number of BLE devices. However, unless your device will be used together with any such device, it is not a practical issue. If for instance, you are making a peripheral for PC&amp;#39;s or mobile devices, then I do not see any reason for considering this.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>