Live data from Hacker News

The Nearest Neighbor Attack

volexity.com

71–73 of 73 posts

Re: The Nearest Neighbor Attack

#71

Earlier quoted context omitted.

My conclusion is that being on the corporate Wi-Fi should not give you access to anything. There should not have been any advantage to getting on the Wi-Fi, it should be treated like the public internet. A separate VPN, with MFA, should be required to access anything.

My current org restricts wifi by user and by device in Active Directory. Thus you need to be whitelisted twice to get access. We use 2fa pretty much everywhere, but I don't think we use it there. But it certainly wouldn't hurt as yet another layer. Wifi adapters should be disabled via Group Policy for wired devices anyway.

Active Directory?

You are already powned.

Re: The Nearest Neighbor Attack

#72

Earlier quoted context omitted.

Final, final, final conclusion: Interacting with a computer makes it networked even if you're not intentionally using traditional networking technologies (TEMPEST attacks, arbitrary code execution through direct user input, etc).

Final, final, final, final conclusion: due to the complexity of computers, the only reliable way to achieve a moderate security in a system is to prevent it from being powered on.

"Pioneered method of keeping restrooms clean by keeping them locked during business hours."

Re: The Nearest Neighbor Attack

#73
post #46

Earlier quoted context omitted.

> These guys hacked into a machine connected by ethernet with an idle wifi adapter And having an idle wifi adapter like that is common nowadays. For some reason, many desktop PCs intended to stay in a single fixed place come from factory with a built-in wifi card and built-in antennas. You'd think that would make these PCs more expensive, but apparently wifi cards are cheap nowadays?

I worked for an MSP (Managed Service Provider) when the pan hit. A bunch of our clients took their workstations home (CAD designers) and couldn't get online because they had no wifi. I understand wanting to save a few bucks times dozens of employees, but I always thought my company was fucking stupid for letting them purchase those machines with no backup for if their network card failed. Turned out this was a much w…

> All that said, if you aren't using wifi to connect to the network, turn the damn thing off.

Sure, but as a hacker who just hacked that machine, i can just turn it back on and you probably won't even notice. i can probably make it hard for you even TO notice.

Post reply on HN