4 ms·
This threat vector is interesting, but is it really a huge deal? I don’t think many company devices restrict the networks you can connect to (certainly not ones
by EdJiang 6y ago
This threat vector is interesting, but is it really a huge deal? I don’t think many company devices restrict the networks you can connect to (certainly not ones you bring on Caltrain) so why even target a corporate pre-shared-key network and instead host xfinitywifi or another popular public SSID?
- db48x 6y agoBecause the people working for the target of your attack might never connect to an xfinity wifi network, but they are pretty likely to connect to the wifi at their office.
- jsjohnst 6y agoExactly, this would likely work fairly well for a targeted attack. Yes, shared Wi-Fi names might work for some employees, but using the employee’s work’s Wi-Fi SSID/psk is virtually guaranteed to work (if they use WPA PSK anyway).