Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

101–110 of 232 posts

Re: WiFi deauthentication attacks and home security

#101
The proper thing to do here would be to call a HOA meeting to decide whether or not devices like these should be allowed in the common spaces. Typically a HOA will have pretty strict rules in the articles and household rules about what you can and can not do in common areas. Another angle is that you may live in a place where two party consent is required for recording, this is not a public space ('the street') nor is it a private area (the dwelling of the owner of the device).

Running this software is likely illegal depending on the jurisdiction might be anything from a misdemeanor to a crime.

Re: WiFi deauthentication attacks and home security

#102
post #64

Earlier quoted context omitted.

I am saying not everyone is affected, only those who solely rely on wifi. Others have realized that a shared medium with questionable security is inherently unreliable and have other options at their disposal.

Ethernet is a shared medium as well if you want to talk to other devices on your network. So instead of deauth they do ARP poisoning.

Not in the same way that wifi is, where anyone outside the building can attack it. And even if your ethernet is under attack you have the advantage of being able to physically locate ports.

Re: WiFi deauthentication attacks and home security

#103
post #2

Depending on where you live, your neighbors recording audio may be illegal and you should confront them about it https://www.southerncaliforniadefenseblog.com/2018/04/do-rin...

That article is nonsense. “Wiretapping” is the interception of a signal, generally a telephone signal, to record or listen in on a conversation. A monitoring device, such as a Ring doorbell — those aren’t “wiretaps.”

The linked article is nothing but SEO spam designed as lead gen for a law firm. A lawyer certainly didn’t write that.

Re: WiFi deauthentication attacks and home security

#104
post #86

I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…

> You may not record what happens in public spaces on security cameras

In America this could be up for debate. Much of this kind of law depends on a "reasonable expectation of privacy", meaning that if anyone could see you there, it's not an issue to record or take pictures. An apartment hallway actually may or may not count as a public space, depending on whether or not the building is access controlled.

Re: WiFi deauthentication attacks and home security

#105
post #64

Earlier quoted context omitted.

I don't get the point of this post - are you saying deauth attacks are fine and everyone should just abandon Wi-Fi?

I am saying not everyone is affected, only those who solely rely on wifi. Others have realized that a shared medium with questionable security is inherently unreliable and have other options at their disposal.

> Others have realized that a shared medium with questionable security is inherently unreliable

The real the8472 would have never said that. Then again without you coming to pin your message on an actual bulletin board for everyone to see you we can neither confirm the authenticity of this message nor of it author. Implicitly its validity is questionable.

> have other options at their disposal

When I tried connecting all the phones, tablets, watches and other such devices in my house to Ethernet cables it proved to be a real hassle for my cat. Do not recommend.

There's value in convenience and it probably outweighs the drawbacks for all but a (very) few specific applications.

Re: WiFi deauthentication attacks and home security

#106
post #86

I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…

You might find it interesting that some German universities [1] actively send out deauthentication packages to clients that connect to SSIDs that are not on their internal whitelist to "protect" the clients from "rogue APs".

A lecturer from my Hochschule was fired for protesting this practice.

[1]: https://meinehochschulebehindertdaswlan.de/

Re: WiFi deauthentication attacks and home security

#107

Earlier quoted context omitted.

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

Agreed. But evidence? I've tried to convince the businesses to talk to the police. But, what they heck do the police/businesses do? How do you prove that there is a crime? They probably would believe me and would probably knock on doors and probably get a warrent. Then what? I'm not a professional cyber security person so how do I prove that device if found is causing damage? Also, the device is intermittent. I can c…

[deleted]

Re: WiFi deauthentication attacks and home security

#108
post #86

I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…

> You may not record what happens in public spaces on security cameras In America this could be up for debate. Much of this kind of law depends on a "reasonable expectation of privacy", meaning that if anyone could see you there, it's not an issue to record or take pictures. An apartment hallway actually may or may not count as a public space, depending on whether or not the building is access controlled.

In America, as a rule, anything in public can be filmed.

Re: WiFi deauthentication attacks and home security

#109
post #64

Earlier quoted context omitted.

I am saying not everyone is affected, only those who solely rely on wifi. Others have realized that a shared medium with questionable security is inherently unreliable and have other options at their disposal.

> Others have realized that a shared medium with questionable security is inherently unreliable The real the8472 would have never said that. Then again without you coming to pin your message on an actual bulletin board for everyone to see you we can neither confirm the authenticity of this message nor of it author. Implicitly its validity is questionable. > have other options at their disposal When I tried connecting…

Your analogy is flawed, the validity of my argument is independent of whether I am who I claim to be. HN does not require strong identity verification to function.

As for the convenience, I think the same kind of reasoning brought us endless ads and tracking.

Re: WiFi deauthentication attacks and home security

#110
post #97

Earlier quoted context omitted.

I think most people don’t know that their equipment is doing this. A lot of WiFi Routers set to auto channel will select some other channel than the one with a lot of deauthentication packages, because the traffic is not stabil on this channel. In this way you get a better Internet connection if your equipment is sending these packages out. As a manufacture you know that you only need a couple of these “bad” devices…

This is fascinating that some manufacturers may have gone down this Darwinian path in "improving" their products. Is there any such law against this or any efforts in introducing such laws, either in Norway or elsewhere?

The WiFi frequencies are unlicensed in afaik every jurisdiction (note that the precise frequencies aren’t de jure the same in every country) so it’s legal to send whatever packets you like within certain power constraints.
Post reply on HN