Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've looked and there were no changes to security. PIN entry still trivially leaks the key (even with 'LE Secure Connections'). Out-of-Band is secure but you can't use it because iOS and Android don't let you (except via NFC on Android). Just Works is inherently vulnerable to MitM (it's not really 'broken' but you can't use it if you want high security). Finally Numeric Comparison is apparently secure, but it requires a screen and buttons on both devices which is often not possible, and it's not the nicest user experience.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: