Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

191–200 of 232 posts

Re: WiFi deauthentication attacks and home security

#191

Earlier quoted context omitted.

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

"There you go, giving a fuck when it's not your turn to give a fuck" --Bunk Moreland, The Wire Finding a cop that's willing to go out on their own to find a potentially unsolvable crime is going to be pretty hard. There are way bigger cases they are already tasked making them too busy to actually get interested in this kind of non-violent/non-life threatening case. 1st world problem: my wifi isn't working because som…

While I agree somewhat, most decent officers will follow up if you give them enough info and make a point to keep updating them. We got a stolen phone back this way by being the "detective" and having the officers knock on candidate doors. Took about 4 hours, and their knowledge of the suspects history, family, and whereabouts was invaluable.

Re: WiFi deauthentication attacks and home security

#192
post #177

Earlier quoted context omitted.

You’ll be surprised just how many people are not using their home internet most of the time.

>most of the time That's the problem though. Even if most people are offline during the night or during holidays/weekends, you still need to provision enough IP addresses for peak demand. ISPs aren't paying for IP addresses by the hour, they're probably leasing/buying subnets on a yearly basis, if not longer.

Peak demand is much lower than the total number of actual subscribers many ISP run as much as 30% deficit these days.

Re: WiFi deauthentication attacks and home security

#193
> The industry doesn't seem to have learned from this.

I think industries follow the money. If the end user doesn't absolutely demand security features, then there won't be such features. Typically people who obsess about security build a product that provides security as a product (vs. a camera as a product).

The guy who wrote Minix makes this argument (and no, he doesn't dislike Linux Torvalds): There are solutions to security problems, but you need to be interested in them in the first place. The military for example is interested in microkernels because in their case security is critical. Minix I believe is written more for reliability (e.g.: uptime) and (better) security comes as a added benefit.

Re: WiFi deauthentication attacks and home security

#194

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

> a lot of people with equipment sending deauthentication packages

Why do they do that?

Re: WiFi deauthentication attacks and home security

#195
post #178
post #133

Earlier quoted context omitted.

And what about the people who don't/can't use the institution's network? Why should the institution be allowed to effectively monopolize the unlicensed airwaves?

If I was in some kind of debate club or moot court or something like that and got assigned to side that is supposed to argue for allowing this, I'd probably look into some kind of property rights approach and make a distinction between radio waves transiting the property and radio waves that originate on the property. The property owner could make not operating an access point on the property a condition of granting…

Can you prove that you wont deauth people just outside your property? Probably not.

Re: WiFi deauthentication attacks and home security

#196
post #181
post #178

Earlier quoted context omitted.

If I was in some kind of debate club or moot court or something like that and got assigned to side that is supposed to argue for allowing this, I'd probably look into some kind of property rights approach and make a distinction between radio waves transiting the property and radio waves that originate on the property. The property owner could make not operating an access point on the property a condition of granting…

>If they choose to exercise this monopoly by using technical measures to stop other access points from working, rather than by physically evicting those access points, why should that make a difference as long as those technical measures do not interfere with access point not on their property? By the same argument, can I also ban cellphones from my property and set up cellphone jammers to enforce this ban? You're fr…

Emergency calls are given a lot of special protections, and for this reason, you cannot.

Re: WiFi deauthentication attacks and home security

#197

Earlier quoted context omitted.

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

Agreed. But evidence? I've tried to convince the businesses to talk to the police. But, what they heck do the police/businesses do? How do you prove that there is a crime? They probably would believe me and would probably knock on doors and probably get a warrent. Then what? I'm not a professional cyber security person so how do I prove that device if found is causing damage? Also, the device is intermittent. I can c…

Have you considered contacting the landlord for that apartment building?

Re: WiFi deauthentication attacks and home security

#198

Earlier quoted context omitted.

I think most people don’t know that their equipment is doing this. A lot of WiFi Routers set to auto channel will select some other channel than the one with a lot of deauthentication packages, because the traffic is not stabil on this channel. In this way you get a better Internet connection if your equipment is sending these packages out. As a manufacture you know that you only need a couple of these “bad” devices…

Eh? I haven't seen a single router that monitors packets on the channel other than their own, not to mention management frames of other AP's A deauth packet needs the MAC address of the AP to deauth clients connected to it and the MAC address of client you want to deauth, the latter is not required and an omission would result in the packet being treated as a "broadcast deauth" but many clients do not accept broadcas…

Just replying to point Ubiquiti APs can regularly scan channels for utilization and direct clients away from congested ones. I don’t think it has protection from deauth attempts but I think it would come across as congestion and send clients elsewhere..

Re: WiFi deauthentication attacks and home security

#199

Earlier quoted context omitted.

I can't see how screwing up the internet for everyone else improves your own privacy.

Really, you can't? While I don't think this is what GP meant, I sure can! We all had a lot more privacy before the internet.

Internet sure. But we are talking wifi specifically here.

Re: WiFi deauthentication attacks and home security

#200
post #177

Earlier quoted context omitted.

You’ll be surprised just how many people are not using their home internet most of the time.

>most of the time That's the problem though. Even if most people are offline during the night or during holidays/weekends, you still need to provision enough IP addresses for peak demand. ISPs aren't paying for IP addresses by the hour, they're probably leasing/buying subnets on a yearly basis, if not longer.

Your phone doesn’t sleep, its always talking to Apple or Google. IP addresses are rotated to keep trouble users at bay. Just like qos isn’t really saving on bandwidth costs.. if you download via http you’re gonna get full transfer speeds available to you, but a single BitTorrent connection won’t. It’s all about mitigating power/problem users
Post reply on HN