Earlier quoted context omitted.
In the US, what law makes it illegal to MitM network traffic using a WiFi evil twin or other technique? I'm genuinely curious because I was under the impression there are generally no such statutes and that the only thing that would be illegal is if the MitM used found credentials.
Possibly the CFAA?
WiFi deauthentication attacks and home security
211–220 of 232 posts
Re: WiFi deauthentication attacks and home security
#212Earlier quoted context omitted.
A man-in-the-middle attack is what can happen here. Deauth and then the device tries to reauth. At that point, the attacker can pose as the router and collect the password hash. The WiFi spec has serious problems.
WiFi doesn't work the way you're claiming. You can use Deauth to be obnoxious/DoS but MITM could be accomplished without Deauth (via higher signal strength + cloned SSID) and WiFi Auth doesn't involve sending a "password hash" over the air that can be "collected." WiFi is protected via PSK (pre-shared [encryption] key), public cryptography (via CA generated key-pairs), or RADIUS. With RADIUS auth you may be able to h…
Re: WiFi deauthentication attacks and home security
#213Earlier quoted context omitted.
Absolutely false, the PTK is sent over the air and is constructed from a hash of the PMK, client/ap MAC, and client/AP Nonce. The attack the parent comment is describing is exactly why WPA3 was made with SAE. One need only capture 2 packets of the initial handshake to start offline cracking by comparing MICs and then you can decrypt the entire conversation since there was no perfect forward secrecy in WPA2 and older.…
> Absolutely false Let's first off go back to what I was replying to: > At that point, the attacker can pose as the router and collect the password hash. By claiming my correction is "absolutely false" you're asserting that the above statement is "absolutely true." But even your technically unsound correction doesn't actually address the underlying inaccuracy of the original statement or why you seemingly believe it…
> By claiming my correction is "absolutely false" you're asserting that the above statement is "absolutely true."
Correct.
> technically unsound correction
Please explain how.
> It is also pretty clear from your reply that you're attempting to muddy the waters by conflating the PTK with the PSK or any other "password."
The PMK is part of the PTK hash. When using a PSK the PSK = the PMK. Not much to conflate, the PTK is a hash of the password with other variables. Exactly as I explained.
> in order to derive it you need additional information which you need to attack
I already explained how the rest of the information needed to derive the PTK is sent in the handshake frames.
> Your post reads like...
Please stick to talking about WiFi authentication.
> Plus is "collect the password hash" really a hill worth dying on for WiFi Auth?
Prior to WPA3, yes - as explained already.
> So it is "incorrect" because I simplified it rather than describing the process in intricate technical detail?
It was incorrect because the password isn't used as a PSK so cracking the PTK gets you a nonce instead of the user password.
> And you won't point out why it was "incorrect" because it is too technically difficult..?
Given we are still trying to agree how the 4 way handshake works and what parts get hashed in it, yes - it is.
.
https://www.wifi-professionals.com/2019/01/4-way-handshake
https://security.stackexchange.com/questions/66008/how-exact...
Re: WiFi deauthentication attacks and home security
#214Earlier quoted context omitted.
Eh? I haven't seen a single router that monitors packets on the channel other than their own, not to mention management frames of other AP's A deauth packet needs the MAC address of the AP to deauth clients connected to it and the MAC address of client you want to deauth, the latter is not required and an omission would result in the packet being treated as a "broadcast deauth" but many clients do not accept broadcas…
Just replying to point Ubiquiti APs can regularly scan channels for utilization and direct clients away from congested ones. I don’t think it has protection from deauth attempts but I think it would come across as congestion and send clients elsewhere..
Re: WiFi deauthentication attacks and home security
#215Earlier quoted context omitted.
Not in the same way that wifi is, where anyone outside the building can attack it. And even if your ethernet is under attack you have the advantage of being able to physically locate ports.
What's your thoughts on EMP attacks?
Re: WiFi deauthentication attacks and home security
#216Earlier quoted context omitted.
A man-in-the-middle attack is what can happen here. Deauth and then the device tries to reauth. At that point, the attacker can pose as the router and collect the password hash. The WiFi spec has serious problems.
I’m not asking for an explanation of what the problem is (and your explanation is wrong), I’m asking about why WiFi spec is designed with this very specific, seemingly obvious flaw (anyone can fake deauth to DoS anyone else). I doubt this wasn’t considered during the design process, and I don’t think the rationale is “screw you”, so there’s gotta be a reason. Edit: According to other comments, it seems that “spoofed”…
Re: WiFi deauthentication attacks and home security
#217Earlier quoted context omitted.
It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.
This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.
This means you can't leave a microphone at a bus stop to record random conversations, say, not without a) owning the bus stop, and b) loudly announcing the presence of the microphone to all users of said bus stop. Replace "bus stop" with any public space. This also applies to private spaces as well, even when you're the owner. Thus you can have video surveillance at any office, but audio surveillance is generally a big no-no.
Re: WiFi deauthentication attacks and home security
#218Earlier quoted context omitted.
It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.
This does vary by U.S. state, though. Most are “one-party”, but some are “two-party”. https://en.wikipedia.org/wiki/Telephone_call_recording_laws#...
Re: WiFi deauthentication attacks and home security
#219Earlier quoted context omitted.
> Also, sniffing Wifi for data not aimed at you is illegal. Ugh, yuck, I hate when lawmakers write laws like that. What does that even mean ? All WiFi that I can hear is aimed at me. That's how radio works. No, I'm not being disingenuous or obtuse, this is a legitimate concern with the way we're allowing artistic liberty into the written law. It's really badly ambiguous, not to mention the ridiculous violation of aut…
Poor word choice on my part. You are only free to capture and process information that either a broadcast without target or addressed specifically to you in some form. And that makes total sense. There is some leeway in the interpretation so that the mandatory reception and decoding as part of the technical implementation are not illegal in themselves, but any further processing of data clearly addressed at someone/s…
Re: WiFi deauthentication attacks and home security
#220Earlier quoted context omitted.
The WiFi frequencies are unlicensed in afaik every jurisdiction (note that the precise frequencies aren’t de jure the same in every country) so it’s legal to send whatever packets you like within certain power constraints.
>so it’s legal to send whatever packets you like within certain power constraints. No. https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jam... >No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government. https://www.law.cornell.edu/uscode/text/47/333