4 ms·
The defence is definitely to not use public wifi. This technology works because they can identify small target windows (e.g. you just accessed a URL to login to
by danielhooper 10y ago
The defence is definitely to not use public wifi. This technology works because they can identify small target windows (e.g. you just accessed a URL to login to your bank account) in which to make and process these measurements. Any kind of abnormal obfuscation of your device should introduce enough noise to prevent this attack from generating any meaningful data from the victim, but I'm running on assumption.
- zrm 10y agoCouldn't this work against any wifi? Impersonating a public access point gives you some extra unencrypted information so you know the server IP and can more easily infer when a password is being entered, the same things you conceal by using a VPN over public wifi. But what stops a passive wifi observer who can guess those things or already knows them?