<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/7964/le-secure-connections-ecdh-on-s130</link><description>Is the ECDH encrypted key exchange supported on the new S130? If not, when can we expect it to be available? 
 I am surprised this is not given a higher priority, since now the only safe solution is to use OOB, which requires additional hardware. The</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 02 Oct 2015 07:21:13 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/7964/le-secure-connections-ecdh-on-s130" /><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28522?ContentTypeID=1</link><pubDate>Fri, 02 Oct 2015 07:21:13 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e9deec50-8a00-456e-b900-f122b4dafed7</guid><dc:creator>Vahid Shirvani</dc:creator><description>&lt;p&gt;Any news? Could you update us on the progress? Do you know when we are going to get the LE Secure Connections? This is a crucial feature that is necessary otherwise the encrypted connection could be compromised by the passive eavesdropper.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28521?ContentTypeID=1</link><pubDate>Mon, 06 Jul 2015 08:16:13 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4f8a24d5-1a91-4aa4-981d-ccc3c9743610</guid><dc:creator>Ulrich Myhre</dc:creator><description>&lt;p&gt;Indeed, I was just surprised that mobile vendors basically ignored OOB pairing for so long, but then very quickly accepted a new security mode (and still doesn&amp;#39;t support OOB). Not that the community in general want to use it. To me it seemed like the mobile world didn&amp;#39;t really care that much about security, but I guess they are just selective in what to include. (nRF52 supports NFC, which is perfect for OOB pairing - among other things).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28520?ContentTypeID=1</link><pubDate>Mon, 06 Jul 2015 08:11:30 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2d4577cf-cf74-4c13-bf73-b63dea1814de</guid><dc:creator>Dominik</dc:creator><description>&lt;p&gt;Nice point, reducing the TX power is a good idea. I will keep that in mind for our application! But I don&amp;#39;t follow you in your last statement. Since vendors are lacking OOB support, wouldn&amp;#39;t that be all the more reason to have LE secure connections which will then spare the necessity for OOB?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28518?ContentTypeID=1</link><pubDate>Sat, 04 Jul 2015 15:45:08 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:a60c26b9-0697-435e-9dd0-b26f8f9ffde2</guid><dc:creator>Ulrich Myhre</dc:creator><description>&lt;p&gt;It is also possible to reduce TX power dramatically during bonding, which will require the devices to be very close. This severely limits passive eavesdropping, since a single missed packet of the 6-way &amp;quot;handshake&amp;quot; will make it much harder to regenerate the STK used when distributing the long-term keys.&lt;/p&gt;
&lt;p&gt;Sadly, most mobile vendors are still lacking in OOB support, so I&amp;#39;m surprised to see LE-Secure Connections embraced so quickly.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28519?ContentTypeID=1</link><pubDate>Fri, 03 Jul 2015 14:19:59 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3504a8d8-49b6-4bf0-a5d4-c6bfc751ee9c</guid><dc:creator>Dominik</dc:creator><description>&lt;p&gt;Thanks for the clarification! We will see which road to take, either add encryption ourselves or use NFC for OOB pairing. And although a protected environment is a theoretical solution, it is not really practical.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28517?ContentTypeID=1</link><pubDate>Fri, 03 Jul 2015 12:43:30 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:faebbacf-e6f6-4d67-9aa9-7b47ee9dae3b</guid><dc:creator>Hung Bui</dc:creator><description>&lt;p&gt;@Dominik,  endnode: Current S130 (v1.0.0) doesn&amp;#39;t support LE Secure Connection.&lt;/p&gt;
&lt;p&gt;It&amp;#39;s in our road map, but I don&amp;#39;t know when it will be available.&lt;/p&gt;
&lt;p&gt;For official information on future feature/product, please contact our sales representative.&lt;/p&gt;
&lt;p&gt;I agree that Just work and Passkey is not very safe, but some measures can be done to make them safer, such as only perform bonding inside a protected environment, such as a Faraday Cage (microwave oven for example)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28516?ContentTypeID=1</link><pubDate>Thu, 02 Jul 2015 14:38:12 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:aae53863-3cb6-4e85-9858-cba2adce3b42</guid><dc:creator>Dominik</dc:creator><description>&lt;p&gt;Yes I agree with you, OOB is pretty safe, and I think he also mentions that in his talk. The vulnerability is mainly with JustWorks and the 6-digit Passkey in which case the key exchange is done over the air and unencrypted. I am going to alter my original question.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: LE Secure Connections (ECDH) on S130</title><link>https://devzone.nordicsemi.com/thread/28515?ContentTypeID=1</link><pubDate>Thu, 02 Jul 2015 13:43:11 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:7f675c50-81ea-4620-9756-9eaddd1fa555</guid><dc:creator>endnode</dc:creator><description>&lt;p&gt;Hi Dominik,&lt;/p&gt;
&lt;p&gt;I back your question because having this is important for &amp;quot;BLE only&amp;quot; devices to have complete security from the point zero. However I&amp;#39;d like to clarify your claim (supported by the reference to the Blackhat talk) that all 3 security modes (JustWorks, 6-digit Passkey and Out Of Band) are vulnerable to the passive (or even active) attack. My understanding is that in OOB you exchange raw 128-bit AES Long Term Key by other way then over the air and thus you are completely safe. Sure this is applicable only for specific devices/infrastructures (most probably minority) but still it&amp;#39;s usable if you want this level of security. Could you point me to any reference for attack against OOB mode?&lt;/p&gt;
&lt;p&gt;Thanks for clarification
Jan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>