8 ms·
So, there is no security feature that prevents a phone from connecting to a cloned wifi network??
by marcod 3y ago
So, there is no security feature that prevents a phone from connecting to a cloned wifi network??
- dhosek 3y agoHow can you tell a wifi network is cloned if the SSID/password match? After all, it might legitimately be a new legitimate access point in the network.
- redox99 3y agoObivously using certificates and TOFU. APs would share the certificate. (That's how it should work, not how it does in practice)
- cj 3y agoI’ve always wondered how commonly black hats clone and exploit mass deployed public SSIDs like the “xfinitywifi” network you see in all major US cities with xfinity. Presumably you could get a lot of random devices to automatically connect and then hijack DNS to cause trouble.
- deleted 3y ago[deleted]
- solardev 3y agoEven if you hijacked DNS, most things are HTTPS now and you'd have to get a copy of a certificate from a trusted CA.
- lazide 3y agoAt least 50% of such APs I ran across didn’t work right. I chalk it up to broken implementation on the ISP side, but a decent number may be issues like this.
- lxgr 3y agoIt's not that easy, unfortunately: Many networks span more than one access point, either simultaneously or across time (mediocre CPEs are notoriously being swapped out all the time by cable providers, in my experience). Initially loading and then synchronizing certificates across APs would be anything but trivial. I've surprised my friends a few times by keeping my SSID + password constant over the years and across several moves within the city (and across ISPs) and even internationally – whenever they come to my place, they have Wi-Fi the second they step through the door :) It's also nice not having to re-configure various embedded devices, many without a sane user interface to type a passphrase or even accept a new TOFU public key, every time I set up a new router at my family's place.
- lxgr 3y agoExactly, if the SSID and password match, it is the same network by definition.
- rkachowski 3y agoThe BSSID won't match
- nineteen999 3y agoIf the SSID and password are the same, how would the phone tell the difference? I don't know. My Fitbit has a "find my phone" feature that uses Bluetooth to tell the Fitbit app on the phone to make a loud whistle. It's kind of handy and ive made use of it several times around my house, but obviously isn't useful outside Bluetooth range.
- flashback2199 3y ago> If the SSID and password are the same, how would the phone tell the difference MAC address, but devices don't care, by design they will connect if the SSID and encryption type are the same, actually, you can create a mesh wifi network at your house with regular routers or access points by doing so, connecting them with wired ethernet.
- HPsquared 3y agoMAC address can of course be spoofed easily as well.
- eternityforest 3y agoWhich is a very good thing, otherwise you wouldn't be able to replace a router and have stuff just work.
- dclowd9901 3y agoOrrrrr the protocol would just be smart enough to say “hey, we are thinking of connecting to this network but the MAC address is different — did you recently switch base stations?”
- eternityforest 3y agoAs long as screenless devices and other unattended things like light bulbs didn't need manual intervention, and it was easy to turn off the checks on a Linux server, it would be cool. But it would probably be an annoyance in large multi hotspot environments, and could become another thing to train people to mindlessly click through like cookie prompts.
- ruined 3y ago802.1x eap
- solardev 3y agoYeah, back in the day before HTTPS was common, this used to be a viable attack where people would set up rogue hotspots at cafes and whatnot and intercept all your traffic.
- lxgr 3y agoThat's only possible for unencrypted networks/SSIDs, though.
- solardev 3y agoI think that's a different attack, where you could passively sniff wifi traffic from networks without WEP. I meant more just hosting your own hotspot with a popular name, forcing clients to connect to it via disconnect/reconnect attacks, and then you're essentially a tiny MITM ISP that can monitor all their unencrypted traffic
- lxgr 3y ago> hosting your own hotspot with a popular name, forcing clients to connect to it via disconnect/reconnect attacks You can only do that for unencrypted networks or those for which you know the passphrase, though.
- solardev 3y agoYes, like most public hotspot in cafes, schools, libraries, etc where the password is readily shared.
- deleted 3y ago[deleted]
- LordShredda 3y agoAssuming you kept the password a secret, how would you create an identical wifi clone?
- addandsubtract 3y agoLAX_FREE_AIRPORT_WIFI
- brink 3y ago99.9% of people don't consider this an issue, I'd rather there not be one in the spec. It's just unnecessary complication. If you're the genuinely paranoid 0.1%, write a script.
- darkarmani 3y ago802.1x. At least that was what could be used 12 years ago. I don't know about state of the art now.
- lxgr 3y agoThere's not really such thing as a cloned wifi network conceptually: If you set up a new access point using the same SSID and encryption settings, you didn't clone a network – you just extended it by one more access point/location where it's available! A Wi-Fi network is the abstract concept of "all access points using the same name and passphrase", not an individual instance of an access point. If you connect the two access points (e.g. using wired Ethernet), clients can actually roam between the two fairly seamlessly without any other setup required, and this even works across brands!
- progman32 3y agoOne thing to keep in mind re: roaming - devices tend to "stick" with their current AP even though there's a perfectly good same-SSID AP with much better strength available. There are protocols that can orchestrate between APs to "kick" stubborn devices to better APs: 802.11r, 802.11k, and 802.11v.
- JCharante 3y agoEnterprise networking hardware has protections against this by attacking other access points. Example from cisco: https://community.cisco.com/t5/wireless/wlc-quot-rogue-containment-quot-what-does-it-actually-do/td-p/1012588 https://community.cisco.com/t5/wireless/wlc-quot-rogue-conta...
- jeroenhd 3y agoEither "enterprise" WiFi or, if your device supports it, locking down the MAC address. That'll give you range issues if you use mesh wifi, range extenders, or additional access points, though. I don't know why more devices don't support WPA Enterprise, it's not _that_ complicated a protocol. I can imagine a "secure router" product with a normal WPA3 network for management and an "enterprise" network with a simple username/password list selling quite well in some niche circles. You can build such a network yourself, though, with almost any OpenWRT device, though it's clearly not something most end users can manage themselves: https://github.com/ouaibe/howto/blob/master/OpenWRT/802.1xOnOpenWRTUsingFreeRadius.md https://github.com/ouaibe/howto/blob/master/OpenWRT/802.1xOn...