Skip to content

Security questions on the Bluetooth serial API. #186

@hemeryar

Description

@hemeryar

Hi there!
The TAG review for the bluetooth via serial classic ended up on the Open Web Platform Intent review list. I had some questions to help us better understand the security/privacy implications of the API:

  • Are the service UUIDs fixed to this list https://www.bluetooth.com/specifications/specs/ or can you have truly custom ones?
  • If truly custom ones exist, do you have an idea of the kind of use cases that would involve them?
  • Do you know if there exists a list of vulnerable devices or would we need to craft one?
  • Is there any reason to not standardize the defense mechanisms? Do you expect for example platforms to matter and the browser would have to mitigate depending on a heuristic?

Thanks,
Arthur

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions