Got a pair of off-brand earbuds. How intrusive can malicious audio gear be to my privacy, whether it be bluetooth or direct connection?
Anything that’s powered on and has a mic is a potential tool for eavesdropping.
Analog headphones are also transducers so you can use them also as a mic (DJs sometimes plug their headphones into the mixer’s mic input to make announcements). So if your sound card can swap the port function malware could in theory use them for eavesdropping. A bit outside your use case but good to know.
More expensive headphones like Sony WH-1000 XM5+ have motion tracking so if your head orientation and movements are private there’s that to keep in mind. Knock offs most likely won’t have this feature for another decade, I’m just mentioning this to point out the expensive brand stuff isn’t necessarily more private, but has more features via more sensors
I don’t know if mine has a mic. Should I continue to use it?
Destroy it and burn it in the trash /s
But in seriousness, don’t outsource your entire brain to internet strangers on a forum. Use the thing between your two ears - why would you choose to keep using or not using it?
I don’t have any other source for this kind of info, what else am I supposed to do. And I don’t use it for hearing any personal audio content. In fact, I don’t even use it that much.
What’s the game if you do use it and it does have a mic? Is that even a big deal?
Well, yeah. I don’t want a mic hearing me. I’ve got the money now, so I’m thinking of buying a wired earbud. Like I said, I don’t really hear any private audio content when I am using it.
All blue-tooth devices have more or less the same risks. Wired once don’t have those.
It doesn’t really matter which brand it is. Major brands are more likely to be targeted, when they have security issues, but they also have usually a better software update policy.
I’d consider it a risk not worth thinking about. Targeting ear buds is not rewarding enough, especially since blue tooth requires proximity.
I think what I’m hinting at is you haven’t threat modelled.
Privacy (and security) is about risk management.
For example, I want to avoid not dying. I may say I don’t want to die from nuclear war, so I build a fallout shelter hundreds of meters below ground in my backyard. However the chances of that happening are so incredibly low that I’ve likely got better things to worry about.
So it becomes a hand wavey probability game. To make this a bit more decisive, we establish trust boundaries on things we trust and don’t. Trust often makes life easier, but incurs more risk. To determine if you need to manage that risk, we can loom at it in different ways.
I won’t explain what is already written - scroll to the bottom of this page and read up on it
- Threat Modeling: The First Step on Your Privacy Journey - Privacy Guides
- Common Threats - Privacy Guides
Simply put
- What’s the attack surface (how easy is it to generally be able to talk to the device) related to what you want to protect? Bluetooth requires closer proximity, so attack surface is people around you mostly. You’re going to assume your trust the device itself (your phone or computer), otherwise you wouldn’t be deciding between Bluetooth and wired.
- What is the skill level / type of the attacker you care about mitigating against? If it’s nation states, you probably already lost, but if it’s say just surveillance capitalism then Google isn’t going to send spooks just to hack your Bluetooth device.
- What is at risk if you fail to protect it? You said it yourself, you listen to nothing of concern if it leaked.
With this, what would your conclusion be on whether or not you can use Bluetooth headphones?
Pretty bottom of the food chain stuff to be worrying about. Just don’t download the manufacturers shitty app. Biggest Bluetooth privacy risk AFAIK is the bluetooth signal transmitting a unique device identifier and tracking you as you move around, though this is brand agnostic.
This being said if your threat model is at the point where you’re thinking about bluetooth headphones as a threat vector, then it’d probably be best not to use them. but this is some mr robot edward snowden sorta stuff