I have my phone running grapheneos set to automatiically switch off Bluetooth after not being used for 5 mins. Makes life easier for sure.
just by having Bluetooth enabled on our devices.
Which is why i do not. Not in piblic at least.
Might not help.
Some Samsung Bluetooth sharing services talk to other devices with Bluetooth off.
Likely on other brands too. It’s infuriating how normalised this has become despite the obvious privacy and security issues.
From my home office, running Bluehood in passive mode (just listening, never connecting), I could detect:
- When delivery vehicles arrived, and whether it was the same driver each time
- The daily patterns of my neighbours based on their phones and wearables
- Which devices consistently appeared together (someone’s phone and smartwatch, for instance)
- The exact times certain people were home, at work, or elsewhere
I mean, forget just locally monitoring around you. Google and Apple’s Location Services, used by iOS and Android devices, phone home with the MAC addresses and signal strengths of nearby Bluetooth devices, so they know when all those devices were active and where. Unless it makes use of MAC randomization, they can track it. You can identify a device’s manufacturer by its OUI, the first 24 bits of the MAC.
Google knows where people with Bluetooth headphones have gone, even if those people have never used Google products, just as long as they’ve been near someone with an Android phone using Location Services. They can probably identify where many people have met each other, by correlating locations of devices. They know, say, when and where Bluetooth-enabled Lovense sex toys were active.
Unless it makes use of MAC randomization, they can track it.
I’d also add that I’d be far from sure that even devices that are randomizing them are using a cryptographically-secure PRNG and reliable source of entropy to seed that PRNG. Even much-more-expensive and capable-of-obtaining-entropy personal computers with software that can be more-readily-inspected have had a spotty record of using solid randomization. I’d give pretty good odds that there are devices out there using a fixed seed and non-cryptographically-secure PRNG for MAC randomization, and that someone like Google, with a vast database of MAC/time/location data and a bunch of smart computer scientists on staff, could probably break the randomization if it wanted on at least some devices.
But you gotta crawl before you can walk, and today, we know that we aren’t even crawling.
Fml
The project was heavily assisted by AI

Tldr: Bluetooth isn’t entirely the problem. The problem is manufacturers who don’t add privacy features like rotating identifiers into their Bluetooth enabled devices. Many smartphones are doing this these days.
E.g. modern non-cheap devices (iphone, pixel, general higher level android, airpods, apple watches, other modern headphones etc.) have those, and are not really track able like this.
I’d say that it is Bluetooth, because the Bluetooth guys didn’t build resistance to tracking and leaking data into the base protocol. There were efforts to patch over these protocol problems that came later.
I have a Pixel and I remember seeing this specific option in Graphene. But that still leaves the devices you connect to anyway, which still travel with you and probably won’t rotate the identifiers.
Get a faraday pouch.
I have a pixel, I am being tracked. This one element might be better but it is an invasive device.
No GrapheneOS?





