I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…
Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?
WiFi deauthentication attacks and home security
111–120 of 232 posts
Re: WiFi deauthentication attacks and home security
#112Earlier quoted context omitted.
> You may not record what happens in public spaces on security cameras In America this could be up for debate. Much of this kind of law depends on a "reasonable expectation of privacy", meaning that if anyone could see you there, it's not an issue to record or take pictures. An apartment hallway actually may or may not count as a public space, depending on whether or not the building is access controlled.
In America, as a rule, anything in public can be filmed.
Re: WiFi deauthentication attacks and home security
#113Earlier quoted context omitted.
> Others have realized that a shared medium with questionable security is inherently unreliable The real the8472 would have never said that. Then again without you coming to pin your message on an actual bulletin board for everyone to see you we can neither confirm the authenticity of this message nor of it author. Implicitly its validity is questionable. > have other options at their disposal When I tried connecting…
Your analogy is flawed, the validity of my argument is independent of whether I am who I claim to be. HN does not require strong identity verification to function. As for the convenience, I think the same kind of reasoning brought us endless ads and tracking.
Of course it isn't. The person making one argument against convenience chose convenience over the massive downsides of using the option with "questionable security" and that is "inherently unreliable". Hence the validity of the claim is undermined. Tomorrow your message might read that "WEP secured WiFi networks are the pinnacle of security and reliability" because dang decided it's a funny thing to do, with little recourse from your side.
The world is not only black or white. You're using the downsides of one extreme as an argument to support the other extreme. Do you realize now that they're both extremes and likely equally wrong?
There's always a balance between security and usability. A sweetspot where the system is convenient to use and still offers as much security as possible. Make it too inconvenient and it's either not used at all or people just end up circumventing all the controls to get that convenience. And this happens ad-hoc, uncontrolled, which is worse.
Re: WiFi deauthentication attacks and home security
#114Earlier quoted context omitted.
Even 802.11w doesn't fix the fundamental problem... WiFi runs in an unlicensed band, and anything else in those bands might disrupt it. There is no service guarantee. You should never rely on it working, especially not for security or safety.
Anything running over rf is vulnerable to jamming. It's really just a matter of how much disruption an attacker is willing to cause.
Yeah, and the same sentence can be changed to "Anything running anywhere is vulnerable to something" and it's still true. I guess the valuable lessons are "There is never any service guarantee" and "something will always go wrong" when you want to built something reliable.
Re: WiFi deauthentication attacks and home security
#115In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…
OpenWRT 19.07 adds wpa3 support and the linux kernel supports 802.11w so probably many more APs could be secured.
Re: WiFi deauthentication attacks and home security
#116Re: WiFi deauthentication attacks and home security
#117Earlier quoted context omitted.
> You may not record what happens in public spaces on security cameras In America this could be up for debate. Much of this kind of law depends on a "reasonable expectation of privacy", meaning that if anyone could see you there, it's not an issue to record or take pictures. An apartment hallway actually may or may not count as a public space, depending on whether or not the building is access controlled.
In America, as a rule, anything in public can be filmed.
Re: WiFi deauthentication attacks and home security
#118I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…
Re: WiFi deauthentication attacks and home security
#119I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…
- The camera can only be active when someone actually rings your doorbell
- You cannot store any images from this camera.
If the system you have installed doesn't abide by those rules, it falls under the more stringent camera surveillance law. That includes hanging up pictograms indicating camera surveillance, registering and obtaining permission,... and so on (gdpr becomes relevant).
Re: WiFi deauthentication attacks and home security
#120Earlier quoted context omitted.
Your analogy is flawed, the validity of my argument is independent of whether I am who I claim to be. HN does not require strong identity verification to function. As for the convenience, I think the same kind of reasoning brought us endless ads and tracking.
> Your analogy is flawed Of course it isn't. The person making one argument against convenience chose convenience over the massive downsides of using the option with "questionable security" and that is "inherently unreliable". Hence the validity of the claim is undermined. Tomorrow your message might read that "WEP secured WiFi networks are the pinnacle of security and reliability" because dang decided it's a funny t…
But it should not be the only option since it can't be relied on due to its many problems. Deauth attacks aren't the only issue.