Information
Bluetooth Sharing allows files to be exchanged with Bluetooth-enabled devices.
Disabling Bluetooth Sharing minimizes the risk of an attacker using Bluetooth to remotely attack the system.
Solution
Graphical Method:
Perform the following steps to disable Bluetooth Sharing:
- Open System Preferences
- Select Sharing
- Set Bluetooth Sharing to disabled
Terminal Method:
Run the following command to disable Bluetooth Sharing is disabled:
$ /usr/bin/sudo -u <username> /usr/bin/defaults -currentHost write com.apple.Bluetooth PrefKeyServicesEnabled -bool false $ /usr/bin/sudo -u firstuser /usr/bin/defaults -currentHost write com.apple.Bluetooth PrefKeyServicesEnabled -bool false
Impact:
Control 2.1.1 discusses disabling Bluetooth if no paired devices exist. There is a general expectation that Bluetooth peripherals will be used by most users in Apple's ecosystem. It is possible that sharing is required and Bluetooth peripherals are not. Bluetooth must be enabled if sharing is an acceptable use case.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION, SYSTEM AND SERVICES ACQUISITION
References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|MP-2, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|4.8, CSCv7|5.1, CSCv7|9.2, CSCv7|14.6
Control ID: 305101033febacf7d3d1123bb9ebd9fa36886e61618ca740f581813a8439c4eb