Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

181–190 of 232 posts

Re: WiFi deauthentication attacks and home security

#181
post #178
post #133

Earlier quoted context omitted.

And what about the people who don't/can't use the institution's network? Why should the institution be allowed to effectively monopolize the unlicensed airwaves?

If I was in some kind of debate club or moot court or something like that and got assigned to side that is supposed to argue for allowing this, I'd probably look into some kind of property rights approach and make a distinction between radio waves transiting the property and radio waves that originate on the property. The property owner could make not operating an access point on the property a condition of granting…

>If they choose to exercise this monopoly by using technical measures to stop other access points from working, rather than by physically evicting those access points, why should that make a difference as long as those technical measures do not interfere with access point not on their property?

By the same argument, can I also ban cellphones from my property and set up cellphone jammers to enforce this ban? You're free to set up arbitrary "rules" and ban people from your property for it, but that doesn't mean you're deputized by the government to do whatever you want to enforce those rules.

Re: WiFi deauthentication attacks and home security

#182

Earlier quoted context omitted.

they want privacy?

I can't see how screwing up the internet for everyone else improves your own privacy.

Really, you can't? While I don't think this is what GP meant, I sure can! We all had a lot more privacy before the internet.

Re: WiFi deauthentication attacks and home security

#183
post #54

Earlier quoted context omitted.

Pointing a permanent security camera at a public space as a private person really is illegal. This is different from occasionally using a handheld camera. Because one is surveillance that is meaningfully different from what you could do just by watching someone, and the other is not (this is my argument, not sure whether this is the legal argument in NL)

Well that scenario is prohibited by the GDPR (though I’m not sure if different authorities would have differing views on that). But the statement that you cannot film public scenes or the people who happen to be in them is simple false.

Most of Western Europe has pretty strict surveilance laws. The GDPR applies even when recording people in private space, e.g. visitors, employees or ATMs inside bancs. Recording public space on a permanent base is a big nono. Accidentally recording strangers for a one off video is no problem.

Then again, after the Brussels terrorist attacks, the police managed to reconstruct the path of a terrorist pretty well by puzzling together all kinds of recordings, so my impression is enforcement is lax as long as nobody complains.

Re: WiFi deauthentication attacks and home security

#184

Earlier quoted context omitted.

It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.

This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.

I am not incorrect.

Record audio at your peril: (This is re: New York)

http://www.dmlp.org/forum/newsgathering-law/new-york-recordi...

“...it is possible to violate the Wiretapping Act (and thereby commit a felony) by pointing a camera at a person speaking on a cell phone and creating an audio recording of part of the telephone conversation.”

Recording audio is always fraught with risk. You should avoid it, especially in indoor locations that you do not control.

Re: WiFi deauthentication attacks and home security

#185

Earlier quoted context omitted.

It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.

This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.

That depends on the state. In Florida, I had to put up notices that audio was being recorded in one room in order to hook up a microphone to a surveillance camera.

Re: WiFi deauthentication attacks and home security

#186

Earlier quoted context omitted.

Use the guide I posted here to locate the device responsible using the signal-strength in Wireshark (search for NKOM). Could be you can break the device by flooding it with fake SSID, using AirPlay-ng. A bit more technical but should be possible with every Mac or most WIFi dongles that support monitor-mode (could be illegal).

I did follow it and found roughly where it is. But, have not talked to that landlord. It is a 3 story building with a handful of apartments in an old stone and brick building locked at the ground floor (i.e. refection is a problem but I imagine signal strength outside the door would be a good indicator once inside). Not sure about breaking the device by flooding with SSIDs? Sorry, not my area here. From what I know,…

Look for the one SSID that is unaffected and I'd bet you'd find the culprit. It's possible that someone set it up solely to screw up WiFi for everyone else but I'd bet money that the reason why they did that is specifically so that the spectrum is left wide open for themselves. WiFi in an apartment right next to a bunch of businesses generally sucks because of the density, it's probably just some selfish script kiddy thinking they're some uber l33t hacker and thinking they can't be caught screwing over their neighbor's WiFi.

Re: WiFi deauthentication attacks and home security

#187

Earlier quoted context omitted.

Did you talk to the FCC? Eg. https://www.fastcompany.com/3050060/company-that-blocked-wi-...

Yes, I told the people about this precedent. And the FCC. Not really my place to get them to call. I think people don't believe a technical glitch is a real world problem. I've tried to tell them that it is definitely impacting their business (restaurants and cafes) and so there is in addition, a monetary impact, just as if someone was causing damage to their business that drove away customers.

Actually, numerous studies have shown that restaurants that offer wifi spend a surprising amount of time assisting customers with logging in, and the average sit time skyrockets when people are checking email instead of consulting the menu. If these aren't designated cyber cafes we're talking about, it could be good for business. On the other hand, the situation described here would drive me crazy and I would be fantasizing about picking locks and climbing on rooftops trying to find the evil little device.

Re: WiFi deauthentication attacks and home security

#188

Earlier quoted context omitted.

In America, as a rule, anything in public can be filmed.

It can be filmed, but audio may not be unless you are a party to the conversation. Doing so is a felony is many places.

depends on the state

Re: WiFi deauthentication attacks and home security

#189

Earlier quoted context omitted.

This is incorrect, it is not a felony to record audio from a security camera in the US. Two party /all party consent only applies to confidential communications.

I am not incorrect. Record audio at your peril: (This is re: New York) http://www.dmlp.org/forum/newsgathering-law/new-york-recordi... “...it is possible to violate the Wiretapping Act (and thereby commit a felony) by pointing a camera at a person speaking on a cell phone and creating an audio recording of part of the telephone conversation.” Recording audio is always fraught with risk. You should avoid it, especiall…

Isn't recording video equivalent to recording audio, as long as a potato chip bag is in view? (https://arstechnica.com/science/2014/08/researchers-reconstr...)

Re: WiFi deauthentication attacks and home security

#190

Earlier quoted context omitted.

I called the police once when I noticed a wifi AP that was MiTM'ing traffic at the local Kroger. They sent someone out and said it was a misconfigured system in the Deli. Guy was real nice and seemed to understand what I was worried about.

In the US, what law makes it illegal to MitM network traffic using a WiFi evil twin or other technique? I'm genuinely curious because I was under the impression there are generally no such statutes and that the only thing that would be illegal is if the MitM used found credentials.

It doesn't have to be illegal for the cops to check it out. Sometimes it scares people off.

I had an officer acquaintance who said he pulled over a car with a shotgun in the back seat and asked who it belonged to, nobody was willing to claim it. He impounded it as abandoned property despite it being perfectly legal to possess.

Post reply on HN