Home Covid tests can be fooled by this Bluetooth bug

Tajammul Pangarkar
Tajammul Pangarkar

Updated · Dec 22, 2021

SHARE:

Scoop.market.us is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more.
close
Advertiser Disclosure

At Market.us Scoop, we strive to bring you the most accurate and up-to-date information by utilizing a variety of resources, including paid and free sources, primary research, and phone interviews. Our data is available to the public free of charge, and we encourage you to use it to inform your personal or business decisions. If you choose to republish our data on your own website, we simply ask that you provide a proper citation or link back to the respective page on Market.us Scoop. We appreciate your support and look forward to continuing to provide valuable insights for our audience.

At a time when President Biden is preparing to make at-home Covid tests available to more Americans, a security researcher has discovered a flaw that could allow someone to change the results in one such test that has been granted emergency use authorization in the US.

While there are now a number of at-home Covid-19 tests available, Elume offers a self-administered antigen test that individuals can use to check to see if they've contracted the virus. Instead of submitting a sample to a testing facility, the company's testing kit allows users to collect their own nasal sample and then test it using the included Bluetooth analyzer.

The Bluetooth analyzer, which reports a user's test result to them as well as to health authorities using Elume's mobile app, caught the attention of F-Secure security consultant Ken Gannon who specializes in mobile security.

During his investigation, Gannon found that it was possible to exploit a bug in the Bluetooth analyzer to change the results of a Covid test before they were reported to Ellume's app. Additionally, Gannon and a colleague were able to obtain a proof of observation certificate for a changed result from a third-party video observation service they were directed to by the company's website.

Falsifying Covid test results

After discovering that he could falsify the results of Ellume's at-home Covid tests, Gannon shared his findings with the company which launched an investigation, confirmed the problem and implemented several improvements to its tests to prevent users from tampering with their results.

Gannon provided further insight on his discovery and how it could be abused by those looking to secure a negative Covid test every time in a press release, saying:

“Our research involved changing a negative test result to positive, but the process works both ways. Prior to Ellume’s fixes, highly skilled individuals or organizations with cyber security expertise trying to circumvent public health measures meant to curb COVID’s spread, could’ve done so by replicating our findings. Someone with the proper motivation and technical skills could’ve used these flaws to ensure they, or someone they’re working with, gets a negative result every time they’re tested.”

Although Gannon first decided to investigate the Bluetooth analyzer used in Ellume's at-home Covid test out of curiosity, he pointed out that other individuals or organizations can leverage similar security flaws to circumvent public health measures. Thankfully though, Eludme's at-home Covid tests are now even more secure thanks to Gannon's discovery and the fact that he responsibly disclosed his findings to the company.

We've also highlighted the best hybrid working tech, best business webcams and best video conferencing software

Source Link Home Covid tests can be fooled by this Bluetooth bug

SHARE:
Tajammul Pangarkar

Tajammul Pangarkar

Tajammul Pangarkar is a CMO at Prudour Pvt Ltd. Tajammul longstanding experience in the fields of mobile technology and industry research is often reflected in his insightful body of work. His interest lies in understanding tech trends, dissecting mobile applications, and raising general awareness of technical know-how. He frequently contributes to numerous industry-specific magazines and forums. When he’s not ruminating about various happenings in the tech world, he can usually be found indulging in his next favorite interest - table tennis.