Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

141–150 of 232 posts

Re: WiFi deauthentication attacks and home security

#141
post #13

Did I read the article correctly in that it is possible to disrupt WiFi networks to make devices disconnect from it, without breaking its encryption? Wow.

So easily that a tamagotchi style game has been made of it and other wifi attacks https://pwnagotchi.ai/

hadn't seen this one yet and just got a zero, thanks for posting this

Re: WiFi deauthentication attacks and home security

#142

Earlier quoted context omitted.

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

Agreed. But evidence? I've tried to convince the businesses to talk to the police. But, what they heck do the police/businesses do? How do you prove that there is a crime? They probably would believe me and would probably knock on doors and probably get a warrent. Then what? I'm not a professional cyber security person so how do I prove that device if found is causing damage? Also, the device is intermittent. I can c…

I called the police once when I noticed a wifi AP that was MiTM'ing traffic at the local Kroger. They sent someone out and said it was a misconfigured system in the Deli.

Guy was real nice and seemed to understand what I was worried about.

Re: WiFi deauthentication attacks and home security

#143
post #123

Earlier quoted context omitted.

Strange example - in a hotel, with an open window, on the 45th floor. If paparazzi with a telephoto lens can see you, it is considered fair game.

If you're standing in front of a window and can see out (and can be seen), you don't really have a reasonable expectation of privacy. This applies to my single floor single family residence. If I want privacy, I close the blinds and/or drapes. As a matter of courtesy, I never aim a telephoto at windows. Paparazzi are an entirely different class though in that most have no "class" anymore it seems.

You don't have a practical expectation. Its reasonable to expect polite neighbors not to stare in windows, take photos etc. Used to be called a 'Peeping Tom' and was actionable. Nowadays we've become jaded?

Re: WiFi deauthentication attacks and home security

#144

I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

"There you go, giving a fuck when it's not your turn to give a fuck" --Bunk Moreland, The Wire

Finding a cop that's willing to go out on their own to find a potentially unsolvable crime is going to be pretty hard. There are way bigger cases they are already tasked making them too busy to actually get interested in this kind of non-violent/non-life threatening case. 1st world problem: my wifi isn't working because someone else's wifi is being mean.

Re: WiFi deauthentication attacks and home security

#145
post #123

Earlier quoted context omitted.

Anywhere you don't have reasonable expectation of privacy.

Strange example - in a hotel, with an open window, on the 45th floor. If paparazzi with a telephoto lens can see you, it is considered fair game.

Not a Lawyer, but it looks like it varies by state. CA penal code 647 j makes this illegal even without entering the property, but mississippi code 97-29-61 does require entering the property.

Re: WiFi deauthentication attacks and home security

#146
post #131

Earlier quoted context omitted.

>so it’s legal to send whatever packets you like within certain power constraints. No. https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jam... >No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government. https://www.law.cornell.edu/uscode/text/47/333

I really disagree with that ruling and interpretation of that quoted part of the law. Jamming to me means radio interference via indiscriminate analog noise. If we expand the definition of jamming to the protocol level like exemplified here, the law gains broad authority to interpret any online interaction that makes your experience worse as "jamming." The law should really should stick to radio frequency enforcement…

>Jamming to me means radio interference via indiscriminate analog noise

So according to you, denying everyone usage is worse than denying everyone else usage to improve your usage?

>If we expand the definition of jamming to the protocol level like exemplified here, the law gains broad authority to interpret any online interaction that makes your experience worse as "jamming." The law should really should stick to radio frequency enforcement, and stay out of protocol-level concerns - it's just too big a can of worms.

This is a fundamental misunderstanding of how the legal system works. It's not an algorithm. Intent matters. Going back to the originally quoted text, it says "willfully or maliciously", so maxing out your WLAN to transfer files 24/7 is probably not going to get a knock on the door by the FCC. Intentionally jamming your neighbor's wifi (deauth packets or otherwise) is.

Re: WiFi deauthentication attacks and home security

#147
post #133

Earlier quoted context omitted.

And what about the people who don't/can't use the institution's network? Why should the institution be allowed to effectively monopolize the unlicensed airwaves?

Why not? It's unlicensed, so it's a free-for-all. If we don't like that, the answer is to license it. Which doesn't seem better to me.

>Why not? It's unlicensed, so it's a free-for-all.

Unlicensed doesn't mean no rules. For example, even though 2.4 Ghz is unlicensed, you're still subject to transmission power limits. In the US at least, there's also statues against interference.

https://www.law.cornell.edu/cfr/text/47/15.5

https://www.law.cornell.edu/uscode/text/47/333

Re: WiFi deauthentication attacks and home security

#148
post #131

Earlier quoted context omitted.

>so it’s legal to send whatever packets you like within certain power constraints. No. https://boingboing.net/2014/10/03/fcc-fines-marriott-for-jam... >No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government. https://www.law.cornell.edu/uscode/text/47/333

I really disagree with that ruling and interpretation of that quoted part of the law. Jamming to me means radio interference via indiscriminate analog noise. If we expand the definition of jamming to the protocol level like exemplified here, the law gains broad authority to interpret any online interaction that makes your experience worse as "jamming." The law should really should stick to radio frequency enforcement…

That's because you are ignorant of radio frequency technology, circa 1940. The only reason a shared frequency band like 2.4 GHz works at all is because we have invented technology that can implicitly synchronize with other senders through avoiding collisions with ongoing transmissions, e.g. through CSMA/CA. Obviously a band like 2.4 GHz will simply not work if devices were allowed to transmit permanently like an analog radio. And so out of simple necessity the regulation for shared bands has very broad language to the effect that you can not interfere in any way with others operating on the same band.

Re: WiFi deauthentication attacks and home security

#149

Earlier quoted context omitted.

Maybe an unethical Wi-Fi manufacturer thought they were clever to deauth clients of APs with MACs not in their own range, to clear other traffic off the band they use and have their products perform better than others by means of sabotage.

That surely would be noticed in any sort of rigorous certification program.

You mean the kind not used by any vendor on Alibaba?

Re: WiFi deauthentication attacks and home security

#150
post #86

I am NOT a laywer, but I checked how much of what the article describes is illegal in Germany. The answer is just about everything. Installing a doorbell with a camera that looks into the hallway is illegal. You may not record what happens in public spaces on security cameras. And even inside your home, you still have to ask for consent to make an audio recording. Otherwise, this constitutes a crime. Also, sniffing W…

Only the ring owner would get caught though
Post reply on HN