Earlier quoted context omitted.
>so it’s legal to send whatever packets you like within certain power constraints. No. https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jam... >No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government. https://www.law.cornell.edu/uscode/text/47/333
That law seems to explicitly apply to transmissions on FCC licensed spectrum, where FCC authorizes operations and ensures that you don't get interference. Wifi happens on unlicensed spectrum, wifi is not "radio communications of any station licensed or authorized by or under this chapter".
WiFi deauthentication attacks and home security
221–230 of 232 posts
Re: WiFi deauthentication attacks and home security
#222Earlier quoted context omitted.
You might find it interesting that some German universities [1] actively send out deauthentication packages to clients that connect to SSIDs that are not on their internal whitelist to "protect" the clients from "rogue APs". A lecturer from my Hochschule was fired for protesting this practice. [1]: https://meinehochschulebehindertdaswlan.de/
From a network admin's perspective- this is necessary to protect the integrity of the air space. It discourages the use of rogue AP's which wreck the channel utilization for everyone. It's common to find this feature in enterprise wifi systems. Some actively spoof the SSID of the rogue AP in order to draw the client back to the institution's network.
There is no private property right to the radio frequency energy traversing someone's property. The owner / lessor of a property may not interfere in someone's use of the airwaves.
[1] https://www.cnn.com/2014/10/03/travel/marriott-fcc-wi-fi-fin...
Re: WiFi deauthentication attacks and home security
#223Earlier quoted context omitted.
Why are people actually doing this on a wide scale?
I think most people don’t know that their equipment is doing this. A lot of WiFi Routers set to auto channel will select some other channel than the one with a lot of deauthentication packages, because the traffic is not stabil on this channel. In this way you get a better Internet connection if your equipment is sending these packages out. As a manufacture you know that you only need a couple of these “bad” devices…
Re: WiFi deauthentication attacks and home security
#224Earlier quoted context omitted.
>This is done primarily by cheap ISP's that want to free up IP addresses they basically reset the DSL connection and complete the handshake but does receive a lease until a client on their network attempts to connect to the internet, think of it as a standby mode How many IP addresses can you possibly save with this tactic? If you have 1000 subscribers, are you really going to only get 990 IP addresses, and hope that…
You’ll be surprised just how many people are not using their home internet most of the time.
So they would have to be not home, and not leave any IoT device on when away. Of course this happens, but is probably very rare in the evenings (and at night).
Re: WiFi deauthentication attacks and home security
#225Earlier quoted context omitted.
Possibly the CFAA?
The CFAA only applies to protected computers and intrusion into those computers. Watching network traffic or modifying network traffic in a MitM possition, without using found credentials doesn't seem to rise to the level of a computer intrusion. Of course, it's unlikely a protected computer is going to be connecting to a public WiFi AP in the first place.. https://en.wikipedia.org/wiki/Protected_computer
> In practice, any ordinary computer has come under the jurisdiction of the law, including cellphones, due to the interstate nature of most Internet communication.
https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act#P...
Re: WiFi deauthentication attacks and home security
#226Earlier quoted context omitted.
This is fascinating that some manufacturers may have gone down this Darwinian path in "improving" their products. Is there any such law against this or any efforts in introducing such laws, either in Norway or elsewhere?
The WiFi frequencies are unlicensed in afaik every jurisdiction (note that the precise frequencies aren’t de jure the same in every country) so it’s legal to send whatever packets you like within certain power constraints.
I posted what turned out to be a misunderstanding (or incomplete if you are more generous) understanding of spectrum rules. My comment was correctly downvoted to 0, but more importantly I got a response that simply explained where I was (utterly) wrong. No flames, no further conjecture, just references. There's a little bit of following discussion.
This is the way it's supposed to work!!
Re: WiFi deauthentication attacks and home security
#227Earlier quoted context omitted.
The WiFi frequencies are unlicensed in afaik every jurisdiction (note that the precise frequencies aren’t de jure the same in every country) so it’s legal to send whatever packets you like within certain power constraints.
I just want to comment that this is who HN is great. I posted what turned out to be a misunderstanding (or incomplete if you are more generous) understanding of spectrum rules. My comment was correctly downvoted to 0, but more importantly I got a response that simply explained where I was (utterly) wrong. No flames, no further conjecture, just references. There's a little bit of following discussion. This is the way…
Re: WiFi deauthentication attacks and home security
#228Earlier quoted context omitted.
This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.
I am not incorrect. Record audio at your peril: (This is re: New York) http://www.dmlp.org/forum/newsgathering-law/new-york-recordi... “...it is possible to violate the Wiretapping Act (and thereby commit a felony) by pointing a camera at a person speaking on a cell phone and creating an audio recording of part of the telephone conversation.” Recording audio is always fraught with risk. You should avoid it, especiall…
Re: WiFi deauthentication attacks and home security
#229Earlier quoted context omitted.
> by supporting WPA3 and PMF (encrypt management frames). OpenWRT 19.07 adds wpa3 support and the linux kernel supports 802.11w so probably many more APs could be secured.
You don't have to have WPA3 to have PMF though. You just have to search more which APs support 802.11w.
Re: WiFi deauthentication attacks and home security
#230I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…
In Belgium there's a similar law which almost prohibits the usage of Ring. In the law, there are two main usages of this kind of system. In case you want to use it to identify persons who ring your doorbell, you need to comply with the following: - The camera can only be active when someone actually rings your doorbell - You cannot store any images from this camera. If the system you have installed doesn't abide by t…