Live data from Hacker News

ESP32/ESP8266 Wi-Fi Attacks

github.com

141–150 of 152 posts

Re: ESP32/ESP8266 Wi-Fi Attacks

#141

Well that sucks. I have probably 20 esp8266 chips around the house doing various things (when you can get an MCU for like $2, you find a lot more uses!), but I don't think any of them really need to worry about this aside from the DoS attacks taking them offline. I'll need to maybe look into some alerts when they start going offline, but not much. I'm not familiar with the Enterprise WPA2 stuff. Is it widely used in…

> I have probably 20 esp8266 chips around the house doing various things

How do you power them all? 20 AC adaptors or battery/solar or something?

Re: ESP32/ESP8266 Wi-Fi Attacks

#142

Earlier quoted context omitted.

That story was widely debunked in followup stories. No one ever demonstrated any of the claims in that story.

I didn’t say it wasn’t debunked, I said that it is what GP was talking about. I didn’t think the “debunked” part was relevant to the question asked that I was responding to. I guess you think it is, so my apologies.

The question asked if it ever happened. That your story didn’t actually happen is most certainly relevant.

Re: ESP32/ESP8266 Wi-Fi Attacks

#143
post #141

Well that sucks. I have probably 20 esp8266 chips around the house doing various things (when you can get an MCU for like $2, you find a lot more uses!), but I don't think any of them really need to worry about this aside from the DoS attacks taking them offline. I'll need to maybe look into some alerts when they start going offline, but not much. I'm not familiar with the Enterprise WPA2 stuff. Is it widely used in…

> I have probably 20 esp8266 chips around the house doing various things How do you power them all? 20 AC adaptors or battery/solar or something?

A few are powered by mains (I have a habit of using them to automate "dumb" appliances. So I put one in a cheap dehumidifier in place of the physical on switch), and the rest with repurposed small lithium ion rechargable batteries meant to be used with drones.

The battery powered ones need to be careful with how they sip power, but in most cases I can rig something up to get them to last. And the batteries I got off eBay all came with their own USB charger, so like 30 minutes of charging every few months and they are good.

I want to look into solar, but I just haven't had time to tinker with it yet.

Re: ESP32/ESP8266 Wi-Fi Attacks

#144
post #133
post #104

Earlier quoted context omitted.

Are holes in security infrastructure required to collect metadata? Are keys, data that secures content - considered metadata? They're not content. Since you can't discuss the letters publicly, a claim could be that it is metadata, and compel keeping the request to collect it as such secret - similarly the fight from the silenced party, if there were any fight, could be out of public visibility.

No they aren't. Read the Wikipedia page you linked to. It's great that you can make claims like this based on zero evidence or even allegations, but there is no basis in fact for it. What's more the number of 3rd party people that have to be involved in something like this make it virtually impossible that the national security letter structure could keep them all silent, especially since there are numerous foreign n…

Since when has the US government felt limited by its own laws? The naïveté here is incredible.

That doesn’t prove they have done it. But arguing they can’t is crazy.

Re: ESP32/ESP8266 Wi-Fi Attacks

#145
post #113

Earlier quoted context omitted.

How do you power them conveniently though? I can wrap my head around doing the soldering. But power means either power adapter or battery? If I’m doing power I might as well use a raspberry.

I tend to power my devices via a simple USB phone-charger. Like the parent I have a few temperature/humidity sensors dotted around the house. Using a PI would be overkill and I'd have to keep the system packages up to date, worry about failing storage-device, etc.

>simple USB phone-charger.

Damn. Was hoping that isn't the answer.

Phone chargers everywhere are ugly & in the way

>I'd have to keep the system packages up to date, worry about failing storage-device, etc.

Fair point

Re: ESP32/ESP8266 Wi-Fi Attacks

#146

Earlier quoted context omitted.

I would be interested in a review of applicable law which would limit the effect of a US FISA court order. I'm not aware of anything that would prevent the court from ordering a vendor to implement features to effectuate surveillance ordered by the court.

FISC/FISCR don't order surveillance, they permits it; the only compulsory powers they have are to limit the scope and conditions of the surveillance permitted, and that's binding on the government under FISA, which criminalizes certain surveillance unless authorized by FISC/FISCR. And that's a pretty weak compulsion, since the people who are bound are the people who would ordinarily prosecute any federal crime, and t…

FISA courts issue warrants, which are court orders. All US courts have the power of the writ which means they can issue further orders to effectuate an order or ruling. So a court can order a company to assist the government in the execution of a warrant. This is pretty long-settled law.

The fact that some government agent applies for the warrant does not alter the fact that the warrant, once granted, is an order nor does it remove the power of the writ for further orders to effectuate the warrant.

Re: ESP32/ESP8266 Wi-Fi Attacks

#147

Earlier quoted context omitted.

hahaha, this is not a backdoor. It's just logical implementation flaws. If wifi products had good certification, this things wouldn't happen.

Parent didn't say this was a backdoor; just that they " can be compelled " to add one, if requested by the Chinese government in the future. Sadly this isn't a tin foil hat possibility.

Not unique to Chinese firms either. Sprint resisted blanket surveillance, for a while, and were finally coerced into line. Do you imagine hardware vendors are immune to the same pressure, in the US, Japan, and Europe?

Re: ESP32/ESP8266 Wi-Fi Attacks

#148
post #75

Earlier quoted context omitted.

Espressif have not released the sources of the WiFi implementation, just binaries. I would define that as "security through obscurity".

At least they seem to be working on opening parts of the code and have already released the supplicant code for example. https://github.com/espressif/esp32-wifi-lib/issues/2 https://github.com/espressif/esp-idf/commit/c1396830243b4c8f...

And then they said that users should only buy products with reputably sourced chips, like my mom is opening up her electronics and trying to figure out whether or not the USB to serial chip is a fake or not.

Re: ESP32/ESP8266 Wi-Fi Attacks

#149
post #14

First and foremost, this speaks to the ubiquity and hacker friendliness of Espressif's chips. Most of their competitors (I'm looking at you, Broadcom), prefer security through obscurity and make it extremely difficult to get access to chips, let alone SDKs. I am certain that similar vulnerability exist in every embedded WiFi chipset out there. That being said, the status quo is completely untenable. Connectivity has…

yes. "Most of their competitors... prefer security through obscurity" Count Texas Instruments ("TI") in this camp. For example, Josh Wyatt of TI is proud of TI's "black box" approach to security, and even became a bit defensive about TI's closed source / "you don't need to know" aspects of its security for its CC3220 chips: https://e2e.ti.com/support/wireless-connectivity/wifi/f/968/... Why the F would anyone use the…

Their "Trusted Root Catalog" is a total fiasco as well. They were one of the AWS IoT launch partners and they apparently repeatedly failed to including AWS root authorities in their catalog. They were responsive in acknowledging, but typically took a month plus to actually update the SDK, (released quarterly,) to address it.

https://e2e.ti.com/support/wireless-connectivity/wifi/f/968/...

They did finally provide a method to use a custom root CA for SSL a year later, https://e2e.ti.com/support/wireless-connectivity/wifi/f/968/....

They seemingly failed to comprehend why anyone would not want to use TI's chain of trust, that is not manufacturer customizable, on proprietary IoT devices. This was explicitly an issue for code signing as well, as it required obtaining a third-party code signing certificate from any number of CA's instead of using our explicit root CA.

[edit] spelling, clarity

Re: ESP32/ESP8266 Wi-Fi Attacks

#150
post #70

Honestly most of the IOT consumer tech infrastructure does security via the "please don't look at me" approach. Still don't know exactly why my home assistant can discover & control my wifi bulbs...never provided passwords or anything.

Re: wifi bulbs: I think most of them just inherently trust WLAN and broadcast to / accept any connections or instructions from WLAN. Especially if they don't connect to cloud at all, it's a fairly simple solution (albeit with low-security too). Basically, your WiFi password is the password.
Post reply on HN