Can the nRF52840 dongle be used to sniff/record BLE communications even if the recorded packets cannot be decrypted, or can it only record packets when decryption is possible (have the required TK and pairing method)?
Can the nRF52840 dongle be used to sniff/record BLE communications even if the recorded packets cannot be decrypted, or can it only record packets when decryption is possible (have the required TK and pairing method)?
Thanks Kenneth.
At DEFCON 27, Damien Cauquil demonstrated a method of inferring the channel hopping counter used. This enabled him to determine the sequence of channel hops, thus allowing him to sniff the BLE session. Sure, it wouldn't work if there were continuous changes made to the connection parameters, but else from that, there wasn't much of an issue. This was implemented on his BTLEJack.
Has Nordic not yet been able to implement this or a similar technique to sniff a connection, or have I misunderstood something?
Honestly speaking I don't see that very useful, the nRF sniffer it used to sniff a connection during development, typically you will then use bonding method that can be decrypted or provide debug keys to decrypt the connection on the fly.
Kenneth
Honestly speaking I don't see that very useful, the nRF sniffer it used to sniff a connection during development, typically you will then use bonding method that can be decrypted or provide debug keys to decrypt the connection on the fly.
Kenneth