<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/57990/is-the-sweyntooth-vulnerabilities-addressed-in-nrf-products</link><description>As mentioned in this article are these vulnerabilities addressed in Nordic Semiconductor&amp;#39;s products? 
 https://thehackernews.com/2020/02/hacking-bluetooth-vulnerabilities.html 
 
 Best regards, 
 Vishnu Pradeep</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Mon, 30 Mar 2020 11:34:11 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/57990/is-the-sweyntooth-vulnerabilities-addressed-in-nrf-products" /><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/242380?ContentTypeID=1</link><pubDate>Mon, 30 Mar 2020 11:34:11 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5c2aa5b9-cf64-431e-bfd0-c67b00aa3be8</guid><dc:creator>Kenneth</dc:creator><description>[quote user="tomschreurs"]Did Nordic perform their own tests to see if their nRF chips are vulnerable?[/quote]
&lt;p&gt;Yes, Nordic has both inspected source code and run the attack tools to double confirm all findings.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/242110?ContentTypeID=1</link><pubDate>Fri, 27 Mar 2020 13:36:25 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:39264280-4cf0-4766-aa5a-6f8f574987d8</guid><dc:creator>tomschreurs</dc:creator><description>&lt;p&gt;Thanks for the info Kenneth. An official statement/communication in the form of an Informational Notice or similar would be very much appreciated though.&lt;/p&gt;
&lt;p&gt;In response to brindusa below you mention &amp;quot;&lt;span&gt;Nordic is not documented as an affected platform&amp;quot; and&amp;nbsp;&lt;/span&gt;&amp;quot;&lt;span&gt;The fact that our devices and software are unaffected is evidenced in the fact we are not identified in the CVEs&amp;quot;. I don&amp;#39;t agree with that. It could be a false negative, because I can&amp;#39;t find in the article (&lt;a href="https://asset-group.github.io/disclosures/sweyntooth/sweyntooth.pdf"&gt;https://asset-group.github.io/disclosures/sweyntooth/sweyntooth.pdf&lt;/a&gt;) that Nordic chips were subjected to the same attacks/tests.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Did Nordic perform their own tests to see if their nRF chips are vulnerable?&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/240381?ContentTypeID=1</link><pubDate>Wed, 18 Mar 2020 09:48:02 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5266bad5-4f28-428a-8d33-ca1d9ac60652</guid><dc:creator>Henrik T</dc:creator><description>&lt;p&gt;Based on your input above and the non-existence of a security IN for nRF8001, I assume that nRF8001 is also deemed not affected by SweynTooth.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/239470?ContentTypeID=1</link><pubDate>Thu, 12 Mar 2020 09:23:35 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:ebe621aa-a384-4d19-8ce7-1cbec4f27f09</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;All vulnerabilities have registered CVEs and are documented here:&lt;br /&gt;&lt;a href="https://asset-group.github.io/disclosures/sweyntooth/sweyntooth.pdf"&gt;https://asset-group.github.io/disclosures/sweyntooth/sweyntooth.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;All CVEs identify the hardware and software platforms affected.&amp;nbsp; Nordic is not documented as an affected platform.&lt;/p&gt;
&lt;p&gt;The fact that our devices and software are unaffected is evidenced in the fact we are not identified in the CVEs.&amp;nbsp; We do not need to issue an official statement to verify this, it can be independently verified by anyone as the CVE database is public.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;In general:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I recommend to regularly check the PCN and IN section on infocenter, if there are any information we want you to be aware it will be listed there, for instance check out for the nRF52832 here:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://infocenter.nordicsemi.com/topic/struct_nrf52/struct/nrf52832_pcn.html"&gt;https://infocenter.nordicsemi.com/topic/struct_nrf52/struct/nrf52832_pcn.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;At the same time check out the Errata section for any new issues that may have been identified that you should consider to handle in your application:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://infocenter.nordicsemi.com/topic/struct_nrf52/struct/nrf52832_errata.html"&gt;https://infocenter.nordicsemi.com/topic/struct_nrf52/struct/nrf52832_errata.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/239428?ContentTypeID=1</link><pubDate>Thu, 12 Mar 2020 02:49:20 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1846bda4-a0c8-46af-9f3b-2475ac619332</guid><dc:creator>brindusa</dc:creator><description>&lt;p&gt;Is there an official communicate from Nordic regarding this assessment?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/239173?ContentTypeID=1</link><pubDate>Tue, 10 Mar 2020 15:03:40 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:66d62641-30fa-4b84-ac69-a8700f91efb9</guid><dc:creator>Henrik T</dc:creator><description>&lt;p&gt;Hi Kenneth.&lt;/p&gt;
&lt;p&gt;We have a released product with&amp;nbsp;nRF8001-R2Q32-R, Build code D. Do you have a status on this?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/238281?ContentTypeID=1</link><pubDate>Thu, 05 Mar 2020 12:33:39 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4f2551a1-0e14-4f9e-9f6d-51d59a27e5b9</guid><dc:creator>Vishnu Pradeep</dc:creator><description>&lt;p&gt;Thanks for the update.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/237901?ContentTypeID=1</link><pubDate>Wed, 04 Mar 2020 02:27:55 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5243b261-274a-4a67-b07c-2eb0788b2726</guid><dc:creator>MakotoW</dc:creator><description>&lt;p&gt;OH I missed it.&lt;/p&gt;
&lt;p&gt;Thank you very much.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/237780?ContentTypeID=1</link><pubDate>Tue, 03 Mar 2020 13:41:32 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:c674b0a7-a2d4-46ad-9aa6-7e114b7766e0</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;I have updated the answer with final results of investigations.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/237593?ContentTypeID=1</link><pubDate>Tue, 03 Mar 2020 04:17:49 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:dca7d212-71cc-4d93-a359-08263cc59c48</guid><dc:creator>MakotoW</dc:creator><description>&lt;p&gt;I&amp;#39;m sorry for sudden reply.&lt;/p&gt;
&lt;p&gt;How about &amp;quot;s120_nrf51_2.1.0&amp;quot; &amp;quot;s110_nrf51_8.0.0&amp;quot; &amp;quot;s120_nrf51_2.0.0&amp;quot; &amp;quot;s110_nrf51822_7.0.0&amp;quot; ?&lt;/p&gt;
&lt;p&gt;We are using these version for mass-production.&lt;/p&gt;
&lt;p&gt;I need any answer.&lt;/p&gt;
&lt;p&gt;Kind regards.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/236075?ContentTypeID=1</link><pubDate>Mon, 24 Feb 2020 17:53:03 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:cb7521f9-6eb4-40b5-892b-994ca6c9d38d</guid><dc:creator>MATHEUS</dc:creator><description>&lt;p&gt;Thanks for the prompt action.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Is the SweynTooth vulnerabilities addressed in nrf products?</title><link>https://devzone.nordicsemi.com/thread/235159?ContentTypeID=1</link><pubDate>Wed, 19 Feb 2020 11:52:41 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5a0e9685-50c6-465c-a26f-08b46c30551e</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;&lt;strong&gt;Final update:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The investigation is now finished.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Nordic has determined:&lt;/p&gt;
&lt;p&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nRF51 SoftDevices are NOT affected by these attacks (S110, S120, S130 all versions)&lt;/p&gt;
&lt;p&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nRF52 SoftDevices are NOT affected by these attacks (S112, S113, S132, S140 all versions)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>