Tech Videos
App steals medical device data on COTS phone
Relying on just Bluetooth Link Layer encryption to secure data between a medical device and the phone, leaves data vulnerable at higher layers above the Bluetooth stack.
This demonstration showcases that vulnerability through an example of a mock flashlight app (as anyone might download from the application store), also having a malicious capability which is to steal the blood pressure data.