Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

161–170 of 232 posts

Re: WiFi deauthentication attacks and home security

#161

Earlier quoted context omitted.

Wait what? Enterprise WiFi Systems are actively attacking each other if you put them close enough together and they overlap on some details like frequency band? ... skims search result for "rogue access point suppression" wow this is just stupid

It's been a feature of enterprise WiFi for a long time. Airespace had the functionality before their acquisition by Cisco, that was March of 2005. Edit: minor grammar clarification.

Though I don't see this feature in my environment anymore I am guessing it was pulled by Cisco after https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jam...

Re: WiFi deauthentication attacks and home security

#162
post #26

Earlier quoted context omitted.

> A statement as "no reasonable expectation of privacy": why not? Just because people could record and film you doesn't mean it's allowed or that it's ok In the US, it is allowed and is OK, though. Legally, you do not have a right to privacy if you are in a public location as a hallway in an apartment building would be considered. Whether or not it is a nice or considerate behavior is moot when it comes to the law. E…

I understand that it's US and per law, but "no reasonable expectation of privacy" is more of a judgement. It should always mention that it's due to the law. The statement probably is entirely reasonable if you're born in the US (as you're used to it). Other countries have other expectations of what's reasonable and normal. The often repeated "no reasonable expectation of privacy" in a public place to me is entirely o…

Hey bkor, thanks for the interesting information on CCTV laws in the Netherlands. I am curious from a photographic perspective. What if I visit NL and I take some photos of buildings and happen to capture pictures of the public? (Its on my list of places to see someday) Can you not post those photos publicly online without consent?

Generally much of the US protections for photography of the public reach pretty far, nice legal outline here http://www.krages.com/ThePhotographersRight.pdf

I found this fun guide I think others would enjoy while I was looking up this topic: https://commons.wikimedia.org/wiki/Commons:Country_specific_...

Sadly I don't find much on NL would be cool to build a chart to contrast and compare laws in each nation as they pertain to video/photo/audio recording in public.

Re: WiFi deauthentication attacks and home security

#164
I've said it before and I'll say it again:

20+ years ago when I was a Windows sysadmin, you could immediately discern the technological savviness and technological maturity of an individual by looking at their system tray:

The number of little icons in their system tray was inversely proportional to their level of this kind of technological maturity.

The system tray of 2019 is connected/smart/cloud devices in ones home.

Re: WiFi deauthentication attacks and home security

#165

Earlier quoted context omitted.

In America, as a rule, anything in public can be filmed.

It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.

This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.

Re: WiFi deauthentication attacks and home security

#166
post #123

Earlier quoted context omitted.

Anywhere you don't have reasonable expectation of privacy.

Strange example - in a hotel, with an open window, on the 45th floor. If paparazzi with a telephoto lens can see you, it is considered fair game.

This is a poor example for two reasons. The reasonable expectation of privacy standard is for audio, not images. And you do have an expectation of privacy in your own hotel room

Re: WiFi deauthentication attacks and home security

#167
post #39

Earlier quoted context omitted.

Why are people actually doing this on a wide scale?

I think most people don’t know that their equipment is doing this. A lot of WiFi Routers set to auto channel will select some other channel than the one with a lot of deauthentication packages, because the traffic is not stabil on this channel. In this way you get a better Internet connection if your equipment is sending these packages out. As a manufacture you know that you only need a couple of these “bad” devices…

Eh? I haven't seen a single router that monitors packets on the channel other than their own, not to mention management frames of other AP's

A deauth packet needs the MAC address of the AP to deauth clients connected to it and the MAC address of client you want to deauth, the latter is not required and an omission would result in the packet being treated as a "broadcast deauth" but many clients do not accept broadcast deauth requests.

"Auto Channel Selection" is done very poorly on most routers, there isn't an algorithm to do so in the spec and the vast majority of routers either to a round robin on boot up or default to channel 6 when set to auto, I can count on one hand the number of routers I've seen that run any type of spectrum analysis on the available bands before selecting a channel.

The only thing I've seen that even resembles closely to what you claim is that some ISP provided routers default to "disconnect" every 12-24 hours. Some just reset the DSL connection, but some also reset the clients. This is done primarily by cheap ISP's that want to free up IP addresses they basically reset the DSL connection and complete the handshake but does receive a lease until a client on their network attempts to connect to the internet, think of it as a standby mode. To ensure that random traffic on the network does not trigger a lease some deauth their wifi clients to reset all existing connections. However this is pretty rare as most DSL providers just reboot the router remotely....

However again random deauth MGMT frames on the same channel would not affect your own wifi network since the MAC addresses of those APs are not identical, conflicting MACs could cause issues but they could cause so many other issues as well way before anything like this could become an issue.

I really don't know why home internet connection and particularly WIFI has so many insane myths and conspiracy theories around it. The reality is simple the 2.4ghz spectrum is the most contested unlicensed spectrum in common use with everything down from your microwave to house and car alarms, wireless headsets and other wireless radio equipment using because that spectrum has been pretty much defined as unlicensed globally way before WIFI every became a thing.

As a result WIFI equipment and especially old and or cheap equipment works really poorly, and the fact that everything from your mobile phone to your toothbrush today comes with wifi and in many cases spams the spectrum even when it's not enabled only complicates the issue.

Then you have housing that outside of the US is primarily built out of reinforced concrete or bricks even for internal walls and you get the worst possible environment for a stable connection.

It's slightly better now in Europe as wood, foam and composites are becoming more and more common for housing both internally and externally but still I've seen flats in London that the wifi won't work from one room to another if the door was closed, we later figured out that the door had an old layer of lead paint and the flat was in a converted victorian town house from the late 1800's which was built from brick and still had lead piping, some of the windows can also be made out of lead glass especially if they are old and pebbled or painted if they weren't replaced recently (which if you live in a graded building they likely weren't because it would cost a small fortune), and some of the clay bricks and fire bricks may contain high levels of tin and lead naturally.

Re: WiFi deauthentication attacks and home security

#168

I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…

Contact your local HAM group.

They do this kind of thing - it's called a "fox hunt".

Re: WiFi deauthentication attacks and home security

#169

Earlier quoted context omitted.

Use the guide I posted here to locate the device responsible using the signal-strength in Wireshark (search for NKOM). Could be you can break the device by flooding it with fake SSID, using AirPlay-ng. A bit more technical but should be possible with every Mac or most WIFi dongles that support monitor-mode (could be illegal).

I did follow it and found roughly where it is. But, have not talked to that landlord. It is a 3 story building with a handful of apartments in an old stone and brick building locked at the ground floor (i.e. refection is a problem but I imagine signal strength outside the door would be a good indicator once inside). Not sure about breaking the device by flooding with SSIDs? Sorry, not my area here. From what I know,…

"I did follow it and found roughly where it is. But, have not talked to that landlord. It is a 3 story building with a handful of apartments in an old stone and brick building locked at the ground floor (i.e. refection is a problem but I imagine signal strength outside the door would be a good indicator once inside)."

Have you considered that what you are seeing is unintentional ? I myself have set up many different (RX only!) experiments in GNU Radio, etc., and had to leave them sit for weeks at a time while I was busy with actual work.

Maybe someone was tinkering/playing/experimenting and just left it on ? I would suggest putting up a polite, but loud and eye-catching one page sign at the entrance to this building alerting someone that they are dramatically impacting their neighbors.

Re: WiFi deauthentication attacks and home security

#170
post #27

Owner of wired cameras that do not store data in the cloud unaffected.

Yep. Wired is always best. You get (almost) the entire electromagnetic spectrum to yourself for each device. There's no reason to share a single spectrum if you don't have to.
Post reply on HN