4 ms·
Is this that big of a deal? Surely by the time someone has hardware access, the game is over. The keys need to be decrypted into memory to use them, and nothing
by an_ko 4y ago
Is this that big of a deal? Surely by the time someone has hardware access, the game is over. The keys need to be decrypted into memory to use them, and nothing stops someone with hardware access from dumping that memory. No amount of encryption beats a soldering iron.
- tinus_hn 4y agoEven worse, that hashed key they are proposing is plaintext equivalent, it has the same access as the password (actually it is the real password, the PSK). And while for normal passwords there is the argument the password is more valuable because people reuse them, that doesn’t really apply for WiFi unless people use the same password for different SSIDs
- voxadam 4y agoIt seems that it could be a pretty big deal to people who toss their old devices in their curbside trash to upgrade or otherwise discard their old Echo devices. Most people don't have the background to understand that attacks like this are possible. Hell, the other day I almost chucked a couple of old 11n era APs flashed with OpenWRT into the trash until I remembered that there's some incredibly sensitive data (SSID, key, logs, etc.) stored in a manner that likely wouldn't hold up to a physical attack. I do have the understanding of attacks like this and in a moment of haste to decluter my home office I nearly opened myself up to an attack like the one described in this post.
- josephg 4y agoAre wireless network passwords really that important? What is the threat model here? I’m trying to figure out the downside risk. Someone finds out your wireless password, figures out your address via an AGPS lookup and then … drives to your house and what? Steals your internet? Projects something on your smart tv? Turns your insecure smart lights on and off? I can imagine that being effective as part of a complex spear phishing attack against a celebrity or something. But if someone dumpster dives and ends up finding my wifi password, why should I care?
- tspike 4y agoIdentity theft is the first thing that comes to mind
- squarefoot 4y agoThat's why old devices must be properly cleaned of personal data before being sold or discarded. I buy most of my devices (network stuff, APs, laptops, etc) either as refurbished or at flea markets. If I was a malicious actor I could have easily taken advantage of many people who didn't delete their data, including WiFi settings, from a device they gave away, so although devices are used in relatively safe places like home or workplace where it would be impractical if not impossible to gain physical access for the time necessary to exfiltrate sensitive data, that becomes trivial if the device is discarded/sold without taking proper measures to delete any sensitive data it could still contain.
- oceanplexian 4y agoJust don’t assume WiFi is a form of security. My WiFi network is no different than a hotspot at a coffee shop, anything important lives in another VLAN and has tight access controls. Someone could get access to my network, and they’d have zero ability to do anything useful other than access the public Internet. This also protects against sketchy apps like TikTok and proprietary devices (like voice assistants).