Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

51–60 of 232 posts

Re: WiFi deauthentication attacks and home security

#51
post #39

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

Why are people actually doing this on a wide scale?

I think most people don’t know that their equipment is doing this. A lot of WiFi Routers set to auto channel will select some other channel than the one with a lot of deauthentication packages, because the traffic is not stabil on this channel. In this way you get a better Internet connection if your equipment is sending these packages out.

As a manufacture you know that you only need a couple of these “bad” devices before you damage the traffic for everyone, forcing everyone to upgrade all their equipment. It also benefit the Internet providers, because faster network will camouflage the problem a bit.

Re: WiFi deauthentication attacks and home security

#52
post #17

Earlier quoted context omitted.

> Devices installed for security purposes cannot trigger wiretapping charges since there's no reasonable expectation of privacy in a public place These ring devices are also installed outside of the US. The law is entirely different in other countries. A statement as "no reasonable expectation of privacy": why not? Just because people could record and film you doesn't mean it's allowed or that it's ok. For Netherland…

> For Netherlands: You cannot just have a camera recording the public. Though there's a bit of leeway, meaning if you have a camera recording your property it's logical that it'll record a bit of the road. You just have to minimize that bit. This is simply not at all true. You can film anything you want in public. I believe the laws around publishing photographs or films of other people is a bit more complex though.

Wrong. You can not aim a security camera at a public space in the Netherlands.

First Google result: https://www.politie.nl/themas/camera-in-beeld.html?sid=42aaf...

Re: WiFi deauthentication attacks and home security

#53
post #10

Earlier quoted context omitted.

It's not clear that a corridor inside an access controlled building is a public place.

Edit: it seems it is divided and cases have gone both ways in regards to expectation of privacy in apartment buildings: https://illinoislawreview.org/print/vol-2018-no-3/fourth-ame...

There’s more here: http://www.wisconsinappeals.net/on-point-by-the-wisconsin-st...

> Because the state offered credible testimony — specifically believed by the trial court — that third parties had unfettered access to the basement of this four-unit building, the defendant did not have a subjective expectation of privacy

GP suggested this wouldn’t be allowed in the hallway of an access-controlled building and precedent suggests that’s accurate. The key is whether a random person could wander into the area without encountering something analogous to a locked door.

If the door to the apartment block wasn’t locked (i.e. Joe Public could wander in and right up to your door), however, then when in the hallway a person would have no more expectation of privacy than when in the street.

Re: WiFi deauthentication attacks and home security

#54
post #17

Earlier quoted context omitted.

> Devices installed for security purposes cannot trigger wiretapping charges since there's no reasonable expectation of privacy in a public place These ring devices are also installed outside of the US. The law is entirely different in other countries. A statement as "no reasonable expectation of privacy": why not? Just because people could record and film you doesn't mean it's allowed or that it's ok. For Netherland…

> For Netherlands: You cannot just have a camera recording the public. Though there's a bit of leeway, meaning if you have a camera recording your property it's logical that it'll record a bit of the road. You just have to minimize that bit. This is simply not at all true. You can film anything you want in public. I believe the laws around publishing photographs or films of other people is a bit more complex though.

Pointing a permanent security camera at a public space as a private person really is illegal.

This is different from occasionally using a handheld camera.

Because one is surveillance that is meaningfully different from what you could do just by watching someone, and the other is not (this is my argument, not sure whether this is the legal argument in NL)

Re: WiFi deauthentication attacks and home security

#55
post #46

> The most interesting one here is the deauthentication frame that access points can use to tell clients that they're no longer welcome. These can be sent for a variety of reasons, including resource exhaustion or authentication failure. And, by default, they're entirely unprotected. Anyone can inject such a frame into your network and cause clients to believe they're no longer authorised to use the network, at which…

The wifi alliance has a long history of failing when it comes to security audits and not doing public RFCs

Re: WiFi deauthentication attacks and home security

#56

Did I read the article correctly in that it is possible to disrupt WiFi networks to make devices disconnect from it, without breaking its encryption? Wow.

Regardless of any encryption, wireless can always be disrupted via jamming. Even if management frames were encrypted you can still disconnect devices by jamming the signal.

Jamming is not as useful as a targeted attack, so this still seems like a defect in the WiFi spec.

For example, an attacker may wish to keep their network working while disrupting others (there is an example of Marriott hotels doing this linked elsewhere in the comments here).

Re: WiFi deauthentication attacks and home security

#58
post #46

> The most interesting one here is the deauthentication frame that access points can use to tell clients that they're no longer welcome. These can be sent for a variety of reasons, including resource exhaustion or authentication failure. And, by default, they're entirely unprotected. Anyone can inject such a frame into your network and cause clients to believe they're no longer authorised to use the network, at which…

The wifi alliance has a long history of failing when it comes to security audits and not doing public RFCs

Network consortium proceedings after the 2000s have become a vehicle for companies to sabotage one another, and practically nothing else.

Wifi is being used outside the much narrower scope it was probably designed for initially.

Installing a cloud-based security system as your primary source of security constitutes several engineering decisions that were out of scope and it only cost $50 so short-sighted porch thieves targeted would still be plenty deterred by it.

Re: WiFi deauthentication attacks and home security

#60

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

That’s really interesting. Did you ever publish a report on this? If you feel like it, please post a link. (Norwegian is fine.)
Post reply on HN