<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sniffing with the nRF52840 dongle</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/82415/sniffing-with-the-nrf52840-dongle</link><description>Can the nRF52840 dongle be used to sniff/record BLE communications even if the recorded packets cannot be decrypted, or can it only record packets when decryption is possible (have the required TK and pairing method)?</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Tue, 07 Dec 2021 15:19:02 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/82415/sniffing-with-the-nrf52840-dongle" /><item><title>RE: Sniffing with the nRF52840 dongle</title><link>https://devzone.nordicsemi.com/thread/342420?ContentTypeID=1</link><pubDate>Tue, 07 Dec 2021 15:19:02 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e9cbcc44-0a40-4e6e-a50e-3cdc696f23ac</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;Honestly speaking I don&amp;#39;t see that very useful, the nRF sniffer it used to sniff a connection during development,&amp;nbsp;typically you will then use bonding method that can be decrypted or provide debug keys to decrypt the connection on the fly.&lt;/p&gt;
&lt;p&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing with the nRF52840 dongle</title><link>https://devzone.nordicsemi.com/thread/342154?ContentTypeID=1</link><pubDate>Mon, 06 Dec 2021 16:13:56 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2823e6a0-8798-440a-af7e-0794adfc4bdd</guid><dc:creator>INShaikh</dc:creator><description>&lt;p&gt;Thanks Kenneth.&lt;/p&gt;
&lt;p&gt;At DEFCON 27, Damien Cauquil demonstrated a method of inferring the channel hopping counter used. This enabled him to determine the sequence of channel hops, thus allowing him to sniff the BLE session. Sure, it wouldn&amp;#39;t work if there were continuous changes made to the connection parameters, but else from that, there wasn&amp;#39;t much of an issue. This was implemented on his BTLEJack.&lt;/p&gt;
&lt;p&gt;Has Nordic not yet been able to implement this or a similar technique to sniff a connection, or have I misunderstood something?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sniffing with the nRF52840 dongle</title><link>https://devzone.nordicsemi.com/thread/342099?ContentTypeID=1</link><pubDate>Mon, 06 Dec 2021 13:54:09 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3b278aad-69a9-4538-adaf-49a15a925b7b</guid><dc:creator>Kenneth</dc:creator><description>&lt;p&gt;It&amp;#39;s only really able to record packets when decryption is possible, the main reason is that the link will very likely change the connection parameters or hopping sequence, and without decryption the sniffer will not be able to receive the change.&lt;/p&gt;
&lt;p&gt;Kenneth&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>