Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

41–50 of 232 posts

Re: WiFi deauthentication attacks and home security

#41

Did I read the article correctly in that it is possible to disrupt WiFi networks to make devices disconnect from it, without breaking its encryption? Wow.

Enterprise wifi systems from Cisco, xirrus, ruckus and others implement this feature for rogue access point suppression.

Wait what? Enterprise WiFi Systems are actively attacking each other if you put them close enough together and they overlap on some details like frequency band?

... skims search result for "rogue access point suppression"

wow this is just stupid

Re: WiFi deauthentication attacks and home security

#42
post #17

Earlier quoted context omitted.

Unlikely. Devices installed for security purposes cannot trigger wiretapping charges since there's no reasonable expectation of privacy in a public place and no intent to record confidential conversations in the first place. Either way, it's not a well written post. I'd shred it here but the comments below it already cover what I would have said.

> Devices installed for security purposes cannot trigger wiretapping charges since there's no reasonable expectation of privacy in a public place These ring devices are also installed outside of the US. The law is entirely different in other countries. A statement as "no reasonable expectation of privacy": why not? Just because people could record and film you doesn't mean it's allowed or that it's ok. For Netherland…

> For Netherlands: You cannot just have a camera recording the public. Though there's a bit of leeway, meaning if you have a camera recording your property it's logical that it'll record a bit of the road. You just have to minimize that bit.

This is simply not at all true. You can film anything you want in public. I believe the laws around publishing photographs or films of other people is a bit more complex though.

Re: WiFi deauthentication attacks and home security

#43
post #39

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

Why are people actually doing this on a wide scale?

they want privacy?

Re: WiFi deauthentication attacks and home security

#44
post #24

Earlier quoted context omitted.

Do you have case law citations for that?

It looks like it is quite divided and could go either way at least wrt apartment buildings: https://illinoislawreview.org/print/vol-2018-no-3/fourth-ame...

What experience?

Edit: Parent comment edited such that this makes no sense now

Re: WiFi deauthentication attacks and home security

#45
post #44

Earlier quoted context omitted.

It looks like it is quite divided and could go either way at least wrt apartment buildings: https://illinoislawreview.org/print/vol-2018-no-3/fourth-ame...

What experience? Edit: Parent comment edited such that this makes no sense now

[deleted]

Re: WiFi deauthentication attacks and home security

#46
> The most interesting one here is the deauthentication frame that access points can use to tell clients that they're no longer welcome. These can be sent for a variety of reasons, including resource exhaustion or authentication failure. And, by default, they're entirely unprotected. Anyone can inject such a frame into your network and cause clients to believe they're no longer authorised to use the network, at which point they'll have to go through a new authentication cycle - and while they're doing that, they're not able to send any other packets.

Anyone has background info on why the hell WiFi spec is designed this way?

Re: WiFi deauthentication attacks and home security

#47

Did I read the article correctly in that it is possible to disrupt WiFi networks to make devices disconnect from it, without breaking its encryption? Wow.

Regardless of any encryption, wireless can always be disrupted via jamming. Even if management frames were encrypted you can still disconnect devices by jamming the signal.

The power requirements for jamming are much higher. Making it much easier to detect a jammer, and harder to run one. Also quite a bit more illegal.

Besides, jamming has a much less targeted effect than a de-auth.

Re: WiFi deauthentication attacks and home security

#48

Did I read the article correctly in that it is possible to disrupt WiFi networks to make devices disconnect from it, without breaking its encryption? Wow.

Yup. You can buy a little open source ESP8266-based watch to do it too: https://dstike.com/

Re: WiFi deauthentication attacks and home security

#49
post #47

Earlier quoted context omitted.

Regardless of any encryption, wireless can always be disrupted via jamming. Even if management frames were encrypted you can still disconnect devices by jamming the signal.

The power requirements for jamming are much higher. Making it much easier to detect a jammer, and harder to run one. Also quite a bit more illegal. Besides, jamming has a much less targeted effect than a de-auth.

When talking about home security I doubt the attacker cares much about legality, and detection requires specialised equipment, by the time it is brought in the robbery has already been committed and the attacker is long gone.

Re: WiFi deauthentication attacks and home security

#50
post #26

Earlier quoted context omitted.

> A statement as "no reasonable expectation of privacy": why not? Just because people could record and film you doesn't mean it's allowed or that it's ok In the US, it is allowed and is OK, though. Legally, you do not have a right to privacy if you are in a public location as a hallway in an apartment building would be considered. Whether or not it is a nice or considerate behavior is moot when it comes to the law. E…

I understand that it's US and per law, but "no reasonable expectation of privacy" is more of a judgement. It should always mention that it's due to the law. The statement probably is entirely reasonable if you're born in the US (as you're used to it). Other countries have other expectations of what's reasonable and normal. The often repeated "no reasonable expectation of privacy" in a public place to me is entirely o…

In US privacy (case) law. "Reasonable expectation of privacy" is a specific term that determines whether it's okay to record things. There is a lot of case law around what does and doesn't imply a reasonable expectation of privacy.

Hence people are using the term in a specific legal way, rather than saying "I don't think it is reasonable to expect privacy here", they are saying "I think legal precedent would make a judge rule there is no 'reasonable expectation of privacy' here".

Post reply on HN