Live data from Hacker News

AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

ndss-symposium.org

171–180 of 204 posts

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#171
post #168

Earlier quoted context omitted.

I'm a co-author on the paper: I would personally indeed not use the phrase "we can break Wi-Fi encryption", because that might be misinterpreated that we can break any Wi-Fi network. What we can do is that, when an adversary is connected to a co-located open network, or is a malicious insider, they can attack other clients. More technically, that we can bypass client isolation. We encountered one interesting case whe…

So if you're running multiple SSIDs on a single router, but all of them use encryption and require a passphrase (i.e., none of them are open), the attacks you are describing don't work? To clarify, the passphrase for each SSID is different, and the question is whether, first, an client that doesn't know any of the passphrases can somehow attack other clients who do, and second, whether a client that knows the passphr…

My interpretation:

First, they can't attack a WiFi access point for which they do not know any password(s). Thus your multi-SSID access point with multiple passwords is "safe" from this particular attack.

However, second, they can attack an access point for which they know any password, gaining access to clients on the other SSIDs. This means your security is now effectively only the security of your worst SSID's password. It also may defeat your purpose in having multiple SSIDs/passwords in the first place.

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#173
post #2

On the one hand, a seems-solid article by an author I mostly trust. OTOH... with the recent journalistic scandal at Ars Technica, perhaps Dan should have made sure that he spelled "Ubiquity" correctly? (5th para; it's correct further down.)

That's an easy autocorrect issue. As someone who write Ubiquiti more often than most. I don't even think most editors would know the difference. That's the problem with using corruptions of real words as your name.

> I don't even think most editors would know the difference.

We're talking about Ars Technica, not USA Today. Kinda like MotorTrend editors should know what a Z-rated tire is.

And I assume you've heard about the their AI fabrication scandal? - https://arstechnica.com/staff/2026/02/editors-note-retractio...

Not a great look, if Ars either doesn't know, or can't control what they're actually publishing.

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#174

As far as I can tell, all of these attacks require the attacker to already be associated to a victim's network. Most of these attacks seem similar to ones expected on shared wifi (airports, cafes) that have been known about for a while. The novel attacks seem to exploit weaknesses in particular router implementations that didn't actually segregate traffic between guest and normal networks. I'm curious if I missed som…

I'm a co-author on the paper: I would personally indeed not use the phrase "we can break Wi-Fi encryption", because that might be misinterpreated that we can break any Wi-Fi network. What we can do is that, when an adversary is connected to a co-located open network, or is a malicious insider, they can attack other clients. More technically, that we can bypass client isolation. We encountered one interesting case whe…

>Of course it's you / partially you

Absolutely love your work, go strong. I click these thread and always expect your name to pop up

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#175

Earlier quoted context omitted.

Yeah, that commercial-grade hardware didn't actually isolate at the PHY-MAC layer is a bit surprising. How would they have working VLANs at the AP?

Fun story, back in uni, if you would spin up a webserver ($ python -m http.server 8000 for example) one could access it from other campuses. We never tried it across countries, but it might (have) worked

That's usually just because it's the same network, it's not a loss of isolation.

It is possible for your university to run a single WiFi network that is multi-campus, and so some "local" packets have to be sent between campuses, whether that's a good idea doesn't necessarily affect whether it's how it was set up.

If your university has campuses in other countries (as mine does) it is not likely they use a single WiFi LAN though it isn't impossible. However the fact that the networks operated by UCLA, Manchester University and the Sorbonne are all named "eduroam" is just for the pragmatic reason that WiFi devices connect by name, those aren't the same WiFI LANs, any more than the guy I know named "Steve Harris" is the bassist from Iron Maiden just because they share the same name.

[The Eduroam name has more significance than the coincidence of name, but that's all the name is doing here, WiFi devices which trust your local cafe "Coffee WiFi" will also connect to the "Coffee WiFi" offered in a completely different store.]

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#176
post #140

Earlier quoted context omitted.

That seems less annoying than a hotel full of people who can play whatever they want with my Chromecast. No malice is required for this to happen; it is completely possible to do by mistake. Words like " I've been trying to use the Chromecast! " "The Living Room Chromecast?" "Yes! It says it's playing, but I don't see anything on the TV screen!" "You hit the play button, right?" "Yeah, and then it keeps stopping on i…

Will a travel router like this prevent this sort of attack?

well, next day you unplug it and move on.

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#177
post #140

Earlier quoted context omitted.

That seems less annoying than a hotel full of people who can play whatever they want with my Chromecast. No malice is required for this to happen; it is completely possible to do by mistake. Words like " I've been trying to use the Chromecast! " "The Living Room Chromecast?" "Yes! It says it's playing, but I don't see anything on the TV screen!" "You hit the play button, right?" "Yeah, and then it keeps stopping on i…

Will a travel router like this prevent this sort of attack?

Yes.

It's a real router with a stateful firewall, just like you use at home. Such devices protect you from the nefarious goings-on of the hotel wifi, just as they protect you from the nefarious goings-on of the big bad Internet on the other side of the cable modem at home.

A travel router differs only in that it is designed to be physically small.

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#178
post #42

Tangentially, does anyone know why so many of the (enormous amount of) papers accepted at this San Diego conference is from Chinese researchers? ( https://www.ndss-symposium.org/ndss2026/accepted-papers ) Has China become so prominent in security research?

China has surpassed the USA in almost every metric except freedom (so far). They already do, or are close to doing, the most and best research in every field, producing the best and cheapest of every product category, and providing the best living standards for their Han Chinese citizens. Europe has a huge amount of catching up to do, and the US is basically a lost cause.

Re: AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]

#180

Other members of my household frequently invite people to my own place that have malicious intent against me. They don't like me for reasons like not being a fan of Trump, Drake, or N3on. Unfortunately, this is a risk that many people other than me have to face. This is an eye-opening article as I do provide my guest password to them. I plan on disabling the guest network entirely and utilizing a completely different…

> Other members of my household frequently invite people to my own place that have malicious intent against me. Are you being abused or something? This sounds ridiculous

You might have extended family and friends who are Trump supporters and wish to own the libs. This is something many people in the US have to deal with. It's not even hard to find even on YCombinator, I just had a reply flagged for comparing Israel to Nazi's.
Post reply on HN