BD_ADDR logs and privacy
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- security
Research direction
Start by reviewing the FIA_BLT_EXT.1/2/3 audit requirements and the Wi-Fi PP-Module update referenced in the issue. Define how the audit requirement should offer either full MAC/name details or masked MAC and Bluetooth profile information for all three events.
Written by the indexing model from the issue text.
Description
Currently the log events for FIA_BLT_EXT.1/2/3 all require the full BD_ADDR (and in some cases the name) to be provided in the audit record. This has raised privacy concerns about the ability to track the devices that are being connected to (as seen with the COVID-19 tracing apps listing devices that were being contacted initially) and a need to further restrict the full information.
For Wi-Fi it is being allowed to use a mask of the AP MAC address, and the proposal here would be to do something similar, where a MAC address can be masked (say the last 2 or 3 octets) can be listed, for specifying connection attempts. Paired with a BT profile would seem to provide a good indicator of what type of device was being connected to.
The preference for the audit requirement would be to provide a selection (like with the Wi-Fi PP-Module update) that would provide the agility to choose either the MAC/name or the masked MAC/BT Profile as an option for the device being connected for all three SFR audit events.
- Dominant language
- Makefile
- Stars
- 3
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from commoncriteria/bluetooth
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
commoncriteria/bluetooth#32 ·
-
v2 - BibliographyOpenrecommend close
Difficulty 1/5 Under an hour Newbie friendliness 68/100
commoncriteria/bluetooth#31 · 1 comment ·
-
recommend close
Difficulty 1/5 Under an hour Newbie friendliness 65/100
commoncriteria/bluetooth#26 ·
-
consistency_review
Difficulty 1/5 1-3 hours Newbie friendliness 74/100
commoncriteria/bluetooth#20 · 3 comments ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
commoncriteria/bluetooth#30 ·
All issues in commoncriteria/bluetooth
Similar issues
-
Difficulty 2/5 Half a day Newbie friendliness 68/100
codingjoe/django-letter#17 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
agent-canvas bug llm priority:low ready-for-dev
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
OpenHands/OpenHands#17806 · 3 comments ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
HarperFast/oauth#243 ·
Maintainers usually reply within 5 days