This security researcher fooled an at-home COVID-19 test using a Bluetooth hack


A security researcher was able to change the results of an at-home COVID test and get those results certified by intercepting and modifying Bluetooth traffic from the device before it reached the app. The researcher, Ken Gannon, found the flaw in Ellume’s nasal swab test, which is designed to analyze and transmit data to a companion app which displays and saves the results. According to a press release from F-Secure, the security company Gannon consults for, Ellume has now fixed the issue.
The process of falsifying results wasn’t a simple one — according to F-Secure’s writeup, the researcher used a rooted Android device to tap into and analyze the data the tester was sending to the app. From there, Gannon was able to determine how the results were sent, and how their authenticity was verified. Then, he wrote two scripts that were able to successfully change a negative result into a positive one. When he got an email with his results from Ellume, he says, it incorrectly showed he had tested positive. If you’re interested in the technical details, you can read the writeup here.
Ellume says it followed F-Secure’s recommendations to do more analysis to ensure that data was accurate, and made changes to the app that should make it harder to analyze its data or take over the data transmission. Gannon told The Verge in an email that he didn’t test to see if his research was applicable to the iOS version of the app, and that the goal of his research was “to see if an ‘average person’ can fake a positive/negative COVID test.” He said that, in theory, “a dedicated threat actor could use [his] research to modify the Ellume app to always report a positive / negative result,” which could be installed on a non-rooted phone.
While Gannon’s writeup only includes changing negative results to positive ones, he says in F-Secure’s press release that “the process works both ways.” Before Ellume’s patches, Gannon says that “someone with the proper motivation and technical skills could’ve used these flaws to ensure they, or someone they’re working with, gets a negative result every time they’re tested.”
In theory, a fake certification could be submitted to meet US re-entry requirements. Not only was F-Secure able to get an incorrect result certified, it did so without a video test supervisor being able to detect it.
The press release says Ellume is now working on a “verification portal” that will let authorities verify that its at-home tests are authentic, and has gone back to analyze all its previous results for accuracy. Ellume says it found that none of them had been faked.
A security researcher was able to change the results of an at-home COVID test and get those results certified by intercepting and modifying Bluetooth traffic from the device before it reached the app. The researcher, Ken Gannon, found the flaw in Ellume’s nasal swab test, which is designed to analyze…
Recent Posts
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
- Nvidia is launching ‘priority access’ to help fans buy RTX 5080 and 5090 FE GPUs
- HPE launches slew of Xeon-based Proliant servers which claim to be impervious to quantum computing threats
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010