{"id":111833,"date":"2023-11-29T15:10:14","date_gmt":"2023-11-29T13:10:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku"},"modified":"2023-11-29T15:10:14","modified_gmt":"2023-11-29T13:10:15","slug":"bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","title":{"rendered":"BLUFFS &#8212; dob\u00ebsit\u00eb n\u00eb Bluetooth q\u00eb lejojn\u00eb nj\u00eb sulm MITM.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Daniele Antonioli, nj\u00eb studiues i siguris\u00eb Bluetooth, i cili m\u00eb par\u00eb zhvilloi teknikat e sulmeve BIAS, BLUR dhe KNOB, identifikoi dy vulnerabilitete t\u00eb reja (CVE-2023-24023) n\u00eb mekanizmin e negociat\u00ebs s\u00eb seanc\u00ebs Bluetooth, q\u00eb prekin t\u00eb gjitha implementimet Bluetooth q\u00eb mb\u00ebshtesin modet e \u00e7iftimit t\u00eb sigurt\u00eb \"Secure Connections\" dhe \"Secure Simple Pairing\", t\u00eb p\u00ebrputhshme me specifikimet Bluetooth Core 4.2-5.4. Si nj\u00eb demonstrim i aplikimeve praktike t\u00eb vulnerabiliteteve t\u00eb identifikuara, jan\u00eb zhvilluar 6 variante sulmesh q\u00eb lejojn\u00eb nd\u00ebrhyrjen n\u00eb lidhjen midis pajisjeve Bluetooth q\u00eb jan\u00eb marr\u00ebdh\u00ebnie m\u00eb par\u00eb. Kodi me implementimin e metodave t\u00eb sulmit dhe utilitetet p\u00ebr t\u00eb kontrolluar pranin\u00eb e vulnerabiliteteve \u00ebsht\u00eb publikuar n\u00eb GitHub.      <\/p>\n<p>Vulnerabilitetet u zbuluan gjat\u00eb analiz\u00ebs s\u00eb mekanizmave t\u00eb arritjes s\u00eb sekretit t\u00eb drejtp\u00ebrdrejt\u00eb (Forward and Future Secrecy) t\u00eb p\u00ebrshkruara n\u00eb standard, t\u00eb cilat parandalojn\u00eb komprometimin e \u00e7el\u00ebsave t\u00eb seanc\u00ebs n\u00eb rast se \u00e7el\u00ebsi i p\u00ebrhersh\u00ebm p\u00ebrcaktohet (komprometimi i nj\u00ebrit nga \u00e7el\u00ebsat e p\u00ebrhersh\u00ebm nuk duhet t\u00eb \u00e7oj\u00eb n\u00eb dekriptimin e seancave q\u00eb jan\u00eb kapur m\u00eb par\u00eb ose t\u00eb ardhshme) dhe rip\u00ebrdorimin e \u00e7el\u00ebsave t\u00eb seanc\u00ebs (\u00e7el\u00ebsi nga nj\u00eb seanc\u00eb nuk duhet t\u00eb aplikohet n\u00eb nj\u00eb seanc\u00eb tjet\u00ebr). Vulnerabilitetet e gjetura lejojn\u00eb anashkalimin e mbrojtjes s\u00eb p\u00ebrmendur dhe rip\u00ebrdorimin e nj\u00eb \u00e7el\u00ebsi seance t\u00eb pasigurt n\u00eb seanca t\u00eb ndryshme. Vulnerabilitetet jan\u00eb t\u00eb shkaktuara nga mang\u00ebsi n\u00eb standardin baz\u00eb, nuk jan\u00eb specifike p\u00ebr stek\u00ebt e ve\u00e7ant\u00eb t\u00eb Bluetooth dhe shfaqen n\u00eb \u00e7ipa t\u00eb prodhuesve t\u00eb ndrysh\u00ebm.     <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/eb2b7d9e0a1b270ee116ffbb2ba86a5a.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Metodat e proponuara t\u00eb sulmit implementojn\u00eb variante t\u00eb ndryshme t\u00eb organizimit t\u00eb spufingut t\u00eb lidhjeve klasike (LSC, Legacy Secure Connections t\u00eb bazuara n\u00eb primitiv\u00eb t\u00eb vjetruar kriptografik\u00eb) dhe t\u00eb sigurta (SC, Secure Connections t\u00eb bazuara n\u00eb ECDH dhe AES-CCM) midis sistemit dhe pajisjes periferike, si dhe organizimin e sulmeve MITM p\u00ebr lidhjet n\u00eb modet LSC dhe SC. Supozohet se t\u00eb gjitha realizimet e Bluetooth, q\u00eb i p\u00ebrkasin standardit, jan\u00eb t\u00eb ekspozuara ndaj varianti t\u00eb caktuar t\u00eb sulmit BLUFFS. Funksionimi i metod\u00ebs \u00ebsht\u00eb demonstruar n\u00eb 18 pajisje nga kompani t\u00eb tilla si Intel, Broadcom, Apple, Google, Microsoft, CSR, Logitech, Infineon, Bose, Dell dhe Xiaomi.      <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/497b2dc1fc82f929bd57895618bb3fa9.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Thelbi i vulnerabiliteteve \u00ebsht\u00eb mund\u00ebsia p\u00ebr t\u00eb detyruar p\u00ebrs\u00ebri lidhjen n\u00eb p\u00ebrdorimin e modit t\u00eb vjet\u00ebr LSC dhe nj\u00eb \u00e7el\u00ebs sesioni t\u00eb pasigurt (SK), pa shkelur standardin, p\u00ebrmes tregimit n\u00eb procesin e negociat\u00ebs s\u00eb lidhjes t\u00eb entropis\u00eb minimale t\u00eb mundshme dhe duke injoruar p\u00ebrmbajtjen e p\u00ebrgjigjes me parametrat e autentikimit (CR), \u00e7ka \u00e7on n\u00eb gjenerimin e nj\u00eb \u00e7el\u00ebsi sesioni mbi baza t\u00eb parametrave hyr\u00ebs konstant\u00eb (\u00e7el\u00ebsi i seanc\u00ebs SK llogaritet si KDF nga \u00e7el\u00ebsi konstant (PK) dhe parametrat e r\u00ebn\u00eb dakord gjat\u00eb seanc\u00ebs). P\u00ebr shembull, nj\u00eb sulmues gjat\u00eb nj\u00eb sulmi MITM mund t\u00eb z\u00ebvend\u00ebsoj\u00eb gjat\u00eb procesit t\u00eb negociat\u00ebs s\u00eb seanc\u00ebs parametrat R1 dhe R2 me vlera zero, dhe t\u00eb vendos\u00eb entropin\u00eb R3 n\u00eb vler\u00ebn 1, \u00e7ka do t\u00eb \u00e7onte n\u00eb formimin e nj\u00eb \u00e7el\u00ebsi sesioni R4 me entropi reale prej 1 byte (konsiderata minimale e entropis\u00eb \u00ebsht\u00eb 7 byte (56 bit), e cila n\u00eb nivelin e besueshm\u00ebris\u00eb \u00ebsht\u00eb e barasvlershme me p\u00ebrzgjedhjen e \u00e7el\u00ebsave DES).    <\/p>\n<p>If the attacker manages to have a shorter key used during the connection negotiation, they can then use brute force to determine the permanent key (PK) used for encryption and achieve decryption of the traffic between devices. Since during a MITM attack one can initiate the use of the same encryption key, if this key is guessed, it can also be used to decrypt all past and future sessions intercepted by the attacker.  <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/e27d88365015f585e8d6dace90547f46.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>To block the vulnerabilities, researchers have proposed amendments to the standard that expand the LMP protocol and change the logic of using KDF (Key Derivation Function) when forming keys in LSC mode. The change does not break backward compatibility, but leads to the inclusion of an extended LMP command and the need to send an additional 48 bytes. The Bluetooth SIG organization, responsible for developing Bluetooth standards, has proposed as a protective measure to reject connections over an encrypted communication channel with keys of up to 7 bytes in size. Implementations that always apply Security Mode 4 Level 4 are recommended to reject connections with keys sized up to 16 bytes.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60192\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432 Bluetooth, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0432\u0441\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 Bluetooth, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0440\u0435\u0436\u0438\u043c\u044b \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0433\u043e \u0441\u043e\u043f\u0440\u044f\u0436\u0435\u043d\u0438\u044f &#171;Secure Connections&#187; \u0438 &#171;Secure Simple Pairing&#187;, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f\u043c Bluetooth Core 4.2-5.4. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043e 6 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u043e\u0432 \u0430\u0442\u0430\u043a, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":111834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47BLUFFS \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Bluetooth, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 MITM-\u0430\u0442\u0430\u043a\u0443 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-11-29T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-11-29T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47BLUFFS \u2014 dob\u00ebsi n\u00eb Bluetooth q\u00eb lejojn\u00eb nj\u00eb sulm MITM | ProHoster","description":"Daniele Antonioli, nj\u00eb hulumtues i siguris\u00eb Bluetooth, i cili m\u00eb par\u00eb ka zhvilluar teknikat e sulmeve BIAS, BLUR dhe KNOB, ka zbuluar dy dob\u00ebsi t\u00eb reja (CVE-2023-24023) n\u00eb mekanizmin e negociat\u00ebs s\u00eb seancave.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47BLUFFS \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Bluetooth, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 MITM-\u0430\u0442\u0430\u043a\u0443 | ProHoster","og:description":"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-11-29T13:10:15+00:00","article:modified_time":"2023-11-29T13:10:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/111833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=111833"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/111833\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/111834"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=111833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=111833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=111833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}