Ubuntu 18.04 LTS bluetooth left discoverable

Bug #1787867 reported by jowfdoijdfdwfwdf
94
This bug affects 20 people
Affects Status Importance Assigned to Milestone
indicator-bluetooth (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Ubuntu 18.04 LTS, when Bluetooth is on, the computer stays discoverable which opens up unnecessary vulnerability surface. There should be a separate UI switch for discoverability with auto timeout. Leaving bluetooth on (using a Bluetooth mouse) should not leave the computer always discoverable.

Current behavior does not match documentation https://help.ubuntu.com/stable/ubuntu-help/bluetooth-visibility.html.en, even without Bluetooth panel open, the computer is still discoverable.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in indicator-bluetooth (Ubuntu):
status: New → Confirmed
Revision history for this message
Peter I. Linkp (interlinkpage) wrote :

Can confirm this bug. After activating Bluetooth via Setting menu in Ubuntu 18.04.1 the computer stay in a permanent bluetooth discoverable mode and is connectable by external bluetooth devices until the next system reboot.

Revision history for this message
Mike Lugar (mikelugar) wrote :

Can confirm this bug as well. Bluetooth remains discoverable from other devices when Bluetooth is On. - Thinkpad X220

Revision history for this message
Jean-Christophe Baptiste (jc-baptiste) wrote :

I can't believe that such a basic security/privacy issue has not been fixed yet.

Normally, the device should only be discoverable when the bluetooth settings are opened.

Revision history for this message
Jean-Christophe Baptiste (jc-baptiste) wrote :

Probably, lot of clues there:

https://bugzilla.redhat.com/show_bug.cgi?id=1602985

Some upstream patches seem to be availabe, can they be ported to Ubuntu ?

Revision history for this message
Kirk Topits (ktopits) wrote :

Also, not only is "Discoverable" left on, "Discovery" is left on. If someone goes to Bluetooth Settings, Discovery is turned on (started) and can only be turned off (stopped) by disconnecting BT adapter or reseting bluetooth.service. This leads to hundreds of detected devices per minute in a public space or office building.

So as per comments above, Discovery should only be on when the bluetooth settings are opened.

Revision history for this message
WirelessMoves (gsmumts) wrote :

I can confirm the behavior. At least its possible to deactivate 'discoverable' and 'discovery' on the command line:

sudo hiconfig hci0 noscan

Interesting: This survives a reboot!

Note: 'discoverable' and 'discovery' is switched-on again when selecting the Bluetooth settings.

Revision history for this message
Rael Gugelmin Cunha (rael-gc) wrote :

This is a serious security issue and it's fixed in Gnome upstream. Probably should be backported.

Revision history for this message
Kevin Senecal (kevin34ct) wrote :

sudo hciconfig hci0 noscan will turn discovery off but leave bluetooth on. I added the line to the /etc/rc.local file so that it will start at every reboot without the sudo. So the line will read hciconfig hci0 noscan. This is a temporary workaround until this is fixed. This bug persists in 20.04.

Revision history for this message
Rael Gugelmin Cunha (rael-gc) wrote :

Just checked in 20.04, with a connected Bluetooth device, and my system is no more automatically discoverable. It's discoverable only when the Bluetooth Settings panel is opened.

Revision history for this message
Stephan T (sierratango) wrote :

I can confirm this bug still exists on 20.04 after testing my desktop and laptop.

Using hciconfig to turn off visibility works and does survive a reboot.

After using hciconfig and opening the Bluetooth settings panel, visibility turns on. When closing the panel, visibility turns off. So hciconfig seems to fix the bug for now. Still, it would be better if this never happened in the first place since it does seem to be a security issue.

Revision history for this message
Stephan T (sierratango) wrote :

Over time and several reboots later, the issue has reappeared, so the workaround above is definitely not a permanent solution.

Revision history for this message
Zeratul2k (zeratul2k) wrote :

Can confirm the bug still exists in 20.04.1 and just like Stephan T mentioned, the workaround only works for a few reboots, then goes back to visibility being on by default and becoming a security issue.

Revision history for this message
Frank H (fhireman) wrote :

Can confirm this bug is still present in 20.04.2.
Dell XPS with Ubuntu 20.04.2 was closed and suspended but could see it as a Bluetooth device on my newly unwrapped work laptop.
It's kind of a security and privacy issue seeing as it pulls my name@XPS-13 as a Bluetooth name.

Revision history for this message
Andreas (blueeyedcreature) wrote :

confirm this is still happening
when settings panel is not open > device is visible on bluetooth
I did pair a keyboard and a mouse before.. later purchased a usb receiver because pairing took a few seconds after resume from standby.. is it possible the system is looking for those accessories?

anyway.. I just deleted the devices and the ubuntu laptop is still visible on my friend's laptop under "available devices" - and we never did pair our devices.

Ubuntu 20.04.2 LTS with Gnome 3.36.8

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.