Some services, such as the Item Press Profile, elect to not explicitly demand authentication or encryption so that pairing does not interfere with the user working experience involved with the service use-cases. Some method of DoS can also be doable, even in modern devices, by sending unsolicited pairing requests https://www.bluetoothspeaker.top/vanzon-bluetooth-portable-speakers/