HardenedBSD/etc
Conrad Meyer 648176e095 bluetooth: Default to discoverable off
Try to not expose bluetooth devices to external devices unless the user
explicitly configures it, like any other radio/network device.  Bluetooth
has a long history of security problems and it is probably best to keep it
disabled if not needed.

Users who do use the bluetooth device should enable "discoverable" in
bluetooth.device.conf(5) after this change.

Keep in mind that bluetooth addresses can be discovered by passive
monitoring or whole address-space scans[0], so a safety conscious user
should also disable "connectable" in bluetooth.device.conf(5).

[0]: https://www.sans.edu/cyber-research/security-laboratory/article/bluetooth

Reviewed by:	emax, hselasky
Security:	maybe
Sponsored by:	Dell EMC Isilon
Differential Revision:	https://reviews.freebsd.org/D12831
2017-11-01 18:58:54 +00:00
..
autofs
bluetooth
casper
cron.d
defaults
devd
etc.aarch64
etc.amd64
etc.arm
etc.i386
etc.mips
etc.powerpc
etc.riscv
etc.sparc64
gss
mail
mtree
newsyslog.conf.d
ntp
pam.d
periodic
pkg
rc.d
root
sendmail
syslog.d
amd.map
apmd.conf
auto_master
blacklistd.conf
crontab
csh.cshrc
csh.login
csh.logout
ddb.conf
devd.conf
devfs.conf
dhclient.conf
disktab
fbtab
freebsd-update.conf
ftpusers
gettytab
group
hosts
hosts.allow
hosts.equiv
hosts.lpd
inetd.conf
libalias.conf
libmap.conf
login.access
login.conf
mac.conf
Makefile
Makefile.depend
master.passwd
minfree
motd
netconfig
netstart
network.subr
networks
newsyslog.conf
nls.alias
nscd.conf
nsmb.conf
nsswitch.conf
ntp.conf
opieaccess
pccard_ether
pf.os
phones
portsnap.conf
printcap
profile
protocols
rc
rc.bsdextended
rc.firewall
rc.initdiskless
rc.resume
rc.sendmail
rc.shutdown
rc.subr
rc.suspend
regdomain.xml
remote
rpc
services
shells
snmpd.config
sysctl.conf
syslog.conf
termcap.small