11 ms·
Since marketing and selling jamming devices is illegal, I would like to know what the FCC is going to do about the supply chain. We know these are all using wel
by nuxi7 11y ago
Since marketing and selling jamming devices is illegal, I would like to know what the FCC is going to do about the supply chain. We know these are all using well known advertised features of enterprise wireless gear. Are they working on a consent decree with Cisco/Aruba/etc to stop including this feature? Or are they going to play whack-a-mole with end users for the next decade?
- Someone1234 11y agoIndeed jamming is illegal. Anti-rogue AP tech' is a grey area. It doesn't jam the spectrum in the traditional sense. Instead it transmits packets telling the AP and client to disconnect from one another for WiFi networks it doesn't "own." That within itself isn't technically "jamming" and is also likely legal in some cases. The whole point of the tech is: If you own a network called "CorpWiFi," someone can come along, set up their own AP, and call their WiFi "CorpWiFi" to try and trick clients into connecting to it with the goal of stealing information. Cisco's anti-rogue AP tech attacks these hotspots and causes continuous disconnects. That is likely legal. What is not legal is using this same tech' to disconnect ALL WiFi hotspots within range. So instead of using it to go after "CorpWiFi" you also disconnect "MyWiFi" and "FreeWiFi" which are networks you don't run. That's what has got these guys into trouble. The technology itself is legal. Using the technology in the US is also legal in some cases. Using it to effectively corner the market for WiFi in certain areas is illegal.
- jellicle 11y ago> Cisco's anti-rogue AP tech attacks these hotspots and causes continuous disconnects. That is likely legal. Why would it be legal to order your computing device to disrupt someone else's computing services? Just for reference here, under US Federal law: > knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; > the term “damage” means any impairment to the integrity or availability of data, a program, a system, or information; A protected computer is any computer connected to the internet. Taking any action to impair the availability of data, a program, or a system to any computer connected to the internet is a felony in the United States.
- morcheeba 11y agoThat's the Computer Fraud and Abuse act -- not the FCC's domain of wireless spectrum.
- jellicle 11y agoYou're right! It is also a crime under the FCC laws. If you manage to interfere with internet-connected computers, using radio communication, you're breaking multiple laws at once. Better hope you have a good lawyer.
- Dylan16807 11y agoYou could make an argument that if they set the SSID to CorpWiFi that they have joined the CorpWiFi network, and it's perfectly okay for other parts of that network to decide what connects to what. There's probably a way to use the CFAA against someone setting up a fake AP, too.
- wahsd 11y agoI don't see how anti-rogue AP tech can be legal either unless it is within the confounds of your own property. Where WiFi jamming is technically also legal if it does not affect any external party. What gives you, company xyz, the right to essentially DoS an AP just because they share the SSID? Just because you call something CorpWiFi, doesn't really make it legal to DoS someone else's SSID that is also called CorpWiFi. There does not seem to be any kind of legal framework that would allow you do so, but inversely, you are essentially then not only committing multiple types of crimes, but you are also violating free speech. I get the reason, but the solution really needs to be something else, even if that something else is some sort of change to the WIFI spec and inclusion of some kind of authentication or security layer.
- notacoward 11y agoAccording to their response, it was within the bounds of their (leased) property. Not saying that makes it right, but FYI.
- FireBeyond 11y agoYeah, still doesn't give them legal claim to 'This Wifi SSID'. Also, there are trespass statutes for people behaving as you don't wish within private property. "Within the bounds" - so their walls are RF shielded, then?
- notacoward 11y ago> Yeah, still doesn't give them legal claim to 'This Wifi SSID' Nobody has a legal claim to any wifi SSID. They don't have an exclusive claim to the conference SSID, and you don't have a legal claim to your hotspot's SSID (the one that's actually at issue here). Conflicts can occur, and the law has nothing to say about them. > Also, there are trespass statutes for people behaving as you don't wish within private property. Yes, there are, but it's not the FCC's role to enforce those particular statutes (nor should it be). The real question is whether the FCC should be unilaterally setting policy regarding interference at the MAC level where things like de-auth packets come into play. That's being discussed in another sub-thread, so I won't repeat the points here. > Within the bounds" - so their walls are RF shielded, then? No more that the average corporate HQ, but there seems to be a consensus here that doing the same thing in that context would be A-OK. Why the different treatment for two situations that are equal under the law?
- drzaiusapelord 11y ago>The whole point of the tech is: If you own a network called "CorpWiFi," someone can come along, set up their own AP, and call their WiFi "CorpWiFi" to try and trick clients into connecting to it with the goal of stealing information. Then contact law enforcement. Building out some vigilante feature into AP's is completely asinine. This is like me seeing someone speed on the expressway and trying to pull them over myself. Of course, we'll abuse that power if given to us! The FCC needs to up its game. Either allow us to do whatever the hell we want or stop the bad guys. You either have police or you don't. This middle ground of outsourcing enforcement to Cisco and Aruba and other deep pocketed enterprise players was, predictably, abused by terrible corporate citizens and puts home users as a disadvantage as their equipment doesn't have these features. Or heaven forbid the FCC get off the big donors/money train and strongarm some spectrum so we have more for wifi in the ISM band. How much spectrum is wasted right now on analog radio or other dinosaur services that can be downsampled into bandwidth efficient digital transmissions? Its incredible we have so few bands for our most used infrastructure. Hell, give us channel 14 at least. Figure out a safe way to do this here. We're dying for spectrum yet deep pocketed players buy all they need (mobile networks, clear channel, etc). That's the core problem hereand until we get more wifi spectrum, these shenanigans will continue in one form or another. Smart City isn't knocking you offline because you're some kind of wifi pirate, they're doing it because they want to hog the limited spectrum for their convention customers. If pirating ssid's were a real problem, we'd all be proposing an ssl-cert like system to verify identities or at least some kind of web of trust to avoid rogue AP's. But its not, its a complete red herring. The real issue is the stingy amount of spectrum allocated to us.
- superuser2 11y ago>Then contact law enforcement. Building out some vigilante feature into AP's is completely asinine. This is like me seeing someone speed on the expressway and trying to pull them over myself. Of course, we'll abuse that power if given to us! No, it's like any corporation's private security asking you to leave. (Which they absolutely will.)
- drzaiusapelord 11y ago
- superuser2 11y agoThose features are legitimate when the targeted AP is illegally on the corporate LAN, impersonating the legitimate APs, and/or a personal hotspot in an environment where data exfiltration is a concern. In places where the public goes (hotels, convention centers) they are absolutely wrong but they're still important to enterprise security on corporate campuses.
- jellicle 11y ago"Legitimate" here may mean that you agree with the use in those cases, but don't mistake it for "legal", which it is not, at least in the last two instances. Corporate LAN is an interesting one.
- notacoward 11y agoYou raise an interesting point. As far as I know, the law doesn't recognize concern about exfiltration as a factor distinguishing "legitimate" vs. "illegitimate" use of these features. It just makes a public vs. private distinction, and the convention spaces in question were considered private. In Smart City's response, they point out that they also provide service in public spaces, and took pains to ensure that users there weren't affected. Is that "illegitimate" in your book? How would you even craft a law that would prohibit them from doing this, without also preventing the "legitimate" corporate use you mention? Where I think Smart City's argument falls down is not that managing the network within their private space is generally wrong or illegal. Their failure seems to have been that the users whose hotspots they were killing had entered into no agreement not to bring or use those devices. Had that been a part of the event registration, I for one might have declined to attend, but I also think the FCC might then have been right - per the law - to have decided differently.
- jsprogrammer 11y agoJust because some people consent to you interfering with WiFi signals, doesn't mean you are allowed to do it. You'd need to completely wrap your transmitters in a Faraday cage and hold the entire convention inside it, only allowing people who have signed your bizarre and draconian contract, that allows you to interrupt their WiFi signals, in to the venue.
- radisb 11y agoHypothetical question: I buy some land to host conventions. I make the buildings and enclose them in a big faraday cage. Then I make deals with anyone that agrees: Whoever wants to host a convention in my center, they will accept that inside the convention center, there will not be any kind of transmission, except my own wifi. Leaving aside the ways I could accomplish this, is what I want legal?
- lstamour 11y agoNot sure. If someone has a cell phone and needs to call 911, would you be held liable for their inability to make that call?
- radisb 11y agoI dont know, but it's my property and it seems logical that as long as they know they cant make that call, the decision is theirs and so is the liability.
- meepmorp 11y ago> If someone has a cell phone and needs to call 911, would you be held liable for their inability to make that call? I've been in plenty of buildings with terrible-to-nonexistent cell reception. I somehow doubt that they'd be held liable if I wasn't able to get reception to make a 911 call. I can't see that the large Faraday cage example is appreciably different.
- RogerL 11y agoThe FCC begs to differ: https://www.fcc.gov/document/warning-wi-fi-blocking-prohibited https://www.fcc.gov/document/warning-wi-fi-blocking-prohibit...
- radisb 11y agoSo it is illegal. So basically I am not free to block hot spots in my own area if I use it for public access, which essentially amounts to "Even if you own an area, whenever it is publicly accessible, you do not own its 'air'". I find it a bit too restrictive.
- mmanfrin 11y agoDifficulty in enforcing a prohibition is not an argument against the prohibition itself.