Shield TV Bluetooth Visibility To Be Addressed

by Andrroid

tl;dr Got an email from Nvidia customer service telling me they intend to release a fix for this, but it requires some backend work so it won't be in the next release

The issue: Currently the Shield TV is visible as a bluetooth device to any nearby devices with bluetooth. This means that someone can attempt to connect to your shield TV any time it is on. They cannot complete the connection, as they need information from the shield. However, repeat attempts can be used to effectively deny you use of the device. Each time an attempt is made, the user is kicked out of whatever application they are in and the bluetooth connection screen is displayed.

I live in an apartment complex and have only had this happen once, but it was very frustrating. I do not think it was out of malicious intent, as when I changed the device name to "please stop trying to connect to me" they stopped. But this vulnerability could definitely be used by someone with malicious intent.

I reported the bug a couple months ago and just received this response:

I just wanted to provide you with an update on the issue below. We will be releasing a minor update soon to fix a few bugs reported in the last release. Because of the backend work required for this change, it cannot be added in time for the next release but we have a plan to address it in the following release. Thank you for your patience.

watchyirc

Sweet. Really loving nvidias support of this product.

Tired8281

That's a security bug you reported. Thank you. Did you get a bounty or a plaque or anything?

edwardnowdeadhands

I hope they also take a look at the fact that BT devices cannot be reconnected without forgetting the device

nimdae

Nexus Player user here with a question: You actually can't complete pairing on the Shield TV without prompting? On the Nexus Player, you can. No information is required from the Nexus Player. It happily accepts the pairing request.

Contacting Google directly on this seems to be nearly impossible. I've tried reaching out to them for the past month before just posting the info publicly on their community supported product forum.

I, too, live in an apartment and any of my neighbors could potentially take control over my Nexus Player. I've resorted to renaming it simply to avoid being an easy target, but this is not security.

[deleted]

It's horse shit this isn't a priority