4 ms·
The AP needs to know your network exists to send deauth packets - if you lower the power on your device so that your network is only accessible to you, you'll e
by thomaskcr 11y ago
The AP needs to know your network exists to send deauth packets - if you lower the power on your device so that your network is only accessible to you, you'll end up fine. So the argument for the other side would basically be that you're not operating a private device if it's broadcasting so their customers may attempt to connect to it. I think many companies' security groups would have a problem with you saying that someone needs to be able to run a publicly accessible access point in their building.
I think the complication comes here from the fact that they were charging for internet and then preventing people from using their own. If there were hotspots trying to mimic the network, I don't think there would be any problem with deauthing them since that's a security risk but it seems like in this case it was just a money grab.
I guess the question becomes for other companies not doing it for the money grab, if you are offering wifi, do you have a duty to protect your customers from rogue hotspots or is it their problem?
- revelation 11y agoThat is not a distinction the law makes. You are not allowed to operate a GPS jammer for your home safety, either. There are exceptions, prisons can operate cellphone jammers for example. I don't think there are any for private enterprises.
- thomaskcr 11y agoWhy would you need to? I'm not sure I understand the point. You're not indiscriminately preventing wifi from working. If your network is broadcasting with enough power to reach the AP, and therefore customers besides yourself, they would be preventing that. If someone sets up a wifi access point outside your building with the same name as your wifi, you should be able to prevent people from accidentally connecting to that rogue access point. That's why basically every enterprise AP comes with that ability. I can't imagine if this were actually illegal the FCC would allow the sale of systems with the ability to do that. The distinction here is that it was done as a money grab and not for security reasons.
- mikeash 11y agoWhy are you talking about "with the same name as your WiFi"? That might change things (the people setting up the rogue network would be deliberately interfering with your network, after all), but as far as I can see that's not what anybody is doing here.
- thomaskcr 11y agoBecause I'm not trying to defend what they did -- they were wrong and just trying to grab money. I am saying that using deauth packets to prevent wifi from operating does not seem to be outright illegal and there are valid reasons to be able to do it. Considering basically every high end AP has the ability to target rogue APs and the FCC takes a dim view on people selling jammers, it seems like the context of the application of this determines whether you are jamming or not and not the use of deauth packets by itself.
- vonmoltke 11y agoI'm aware that nearly every enterprise AP has the ability to detect rogue access points. I am not aware of any with the ability to attack them. Also, as far as I know, none of them can target devices that are not actually attached to their network.
- oasisbob 11y agoIt's a common feature. IIRC, in Cisco WLC land the feature is referred to as active rogue containment: http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/70987-rogue-detect.html#Determination http://www.cisco.com/c/en/us/support/docs/wireless-mobility/... As someone who has experienced the fallout firsthand from a neighboring tenant in a downtown Seattle office building who used it, I'd challenge the idea that there are valid reasons to do this. If you control the physical network - don't allow rogue APs on your network. If you control the client and care about them connecting to access points that aren't under your control, then manage that instead.
- 11y ago
- bradyd 11y ago> There are exceptions, prisons can operate cellphone jammers for example. It is not legal for prisons to jam cell phones. "The Communications Act prohibits non-Federal entities from using cell jammers. The FCC cannot waive this statutory prohibition absent a change in the law by Congress." [1] There was an attempt to add an exception for prisons, but it was never passed (Safe Prisons Communications Act of 2009[2]). [1] http://www2.fcc.gov/pshs/docs/summits/Combating-Contraband-Cell-Phones-in-Prison-Handout-v4.pdf http://www2.fcc.gov/pshs/docs/summits/Combating-Contraband-C... [2] https://www.govtrack.us/congress/bills/111/s251 https://www.govtrack.us/congress/bills/111/s251
- nmrm2 11y agoCould the federal government set up a contracting arm that sells jamming services to state facilities? Or does non-Federal entity mean something else?
- chris_wot 11y agoLook up the Communications Act of 1934, specifically 47 USC 302a: "(c) Exceptions The provisions of this section shall not be applicable to carriers transporting such devices or home electronic equipment and systems without trading in them, to devices or home electronic equipment and systems manufactured solely for export, to the manufacture, assembly, or installation of devices or home electronic equipment and systems for its own use by a public utility engaged in providing electric service, or to devices or home electronic equipment and systems for use by the Government of the United States or any agency thereof. Devices and home electronic equipment and systems for use by the Government of the United States or any agency thereof shall be developed, procured, or otherwise acquired, including offshore procurement, under United States Government criteria, standards, or specifications designed to achieve the objectives of reducing interference to radio reception and to home electronic equipment and systems, taking into account the unique needs of national defense and security." (Emphasis mine) That's a very clear exception.
- chris_wot 11y agoHmmm... I'm a bit of a goose and misread that. The bit I got wrong is: "under United States Government criteria, standards, or specifications designed to achieve the objectives of reducing interference to radio reception and to home electronic equipment and systems, taking into account the unique needs of national defense and security." Sorry about that.
- mikeash 11y agoI would hope that those security groups you mention would know that, under the law, they do not own the airwaves in their buildings, and therefore it doesn't matter what their opinion is on whether somebody "needs" to run a hotspot. All that matters is that a hotspot is an authorized device and intentionally interfering with the operation of an authorized device is against the law.