https://bugs.kde.org/show_bug.cgi?id=358753

            Bug ID: 358753
           Summary: unauthorized device autoconnects
           Product: Bluedevil
           Version: 5.4.3
          Platform: Other
                OS: Linux
            Status: UNCONFIRMED
          Severity: critical
          Priority: NOR
         Component: general
          Assignee: now...@gmail.com
          Reporter: kde-b...@ginguppin.de

in short: an unknown iPhone apparently connected via BT to my computer without
my approval.

long:
just now there was first a not fully rendered notification bubble, followed
immediatelly by another one asking
"iPhone LB is asking if the PIN is correct: 503545"
since i don't have an iPhone, i replied with "no" and had a look at the list of
connected devices -- and despite my refusal, that iPhone was listed as
connected device!

i hit disconnect, which only showed a spinner, and after a few seconds pulled
the BT dongle.

checking the .xsession-errors, i found _two_ requests with two different PINs,
of which i catched  only the second one:

log_kioremote: RemoteDirNotify::FilesAdded
log_kioremote: RemoteDirNotify::toRemoteURL( QUrl("bluetooth:/") )
log_kioremote: result => KUrl()
QXcbConnection: XCB error: 3 (BadWindow), sequence: 11666, resource id:
69206019, major code: 15 (QueryTree), minor code: 0
log_kioremote: RemoteDirNotify::FilesAdded
log_kioremote: RemoteDirNotify::toRemoteURL( QUrl("bluetooth:/") )
log_kioremote: result => KUrl()
bluedevil: AGENT-RequestConfirmation  "iPhone LB" "088305"
Currrent active notifications: QHash()
Guessing partOf as: 0
 New Notification:  "Bluetooth system" "iPhone LB is asking if the PIN is
correct: 088305" 0 & Part of: 0
qml:  totalCountChanged 1
qml:  totalCountChanged 1
qml:  totalCountChanged 0
qml:  totalCountChanged 0
QXcbConnection: XCB error: 3 (BadWindow), sequence: 13455, resource id:
81788932, major code: 18 (ChangeProperty), minor code: 0
bluedevil: ProcessClosed:  1
bluedevil: Rejecting request
QXcbConnection: XCB error: 3 (BadWindow), sequence: 13496, resource id:
38377497, major code: 3 (GetWindowAttributes), minor code: 0
file:///usr/share/plasma/plasmoids/org.kde.plasma.mediacontroller/contents/ui/main.qml:
QML Plasmoid: Cannot anchor to an item that isn't a parent or sibling.
file:///usr/share/plasma/plasmoids/org.kde.plasma.mediacontroller/contents/ui/main.qml:
QML Plasmoid: Cannot anchor to an item that isn't a parent or sibling.
bluedevil: AGENT-RequestConfirmation  "iPhone LB" "503545"
Currrent active notifications: QHash()
Guessing partOf as: 0
 New Notification:  "Bluetooth system" "iPhone LB is asking if the PIN is
correct: 503545" 0 & Part of: 0

i am a bit scared to see that a strange BT device apparently is able to connect
to my computer -- be it despite my refusal or, worse, because the confirmation
popup wasn't rendered/seen by me!

the BT adapter was set to "always visible", but that shouldn't lead to
unauthorized connections, right?

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to