4 ms·
A few years ago I was trying out mdk3's FakeAP feature. It had the ability to create thousands of fake APs and crash some devices. I was playing around with it
by _andrei_ 3y ago
A few years ago I was trying out mdk3's FakeAP feature.
It had the ability to create thousands of fake APs and crash some devices.
I was playing around with it on a MacBook that didn't have OS X for a few months, as I completely erased it and installed a Linux distro on it.
I started toying around with the FakeAP, pretty impressed by the huge list of networks with random names that were now appearing and dissapearing.
But then, I was struck with horror. Something must've happened inside the hardware, because the network names were not random anymore. It was still advertising new networks like crazy, but they had the SSIDs of the networks I had connected to in the past. From the work network, to all the coffee places I went to, friend networks, etc.
I have my beef with Apple, and the fact that they store the networks you connect to on a chip is just a part of it. There's no good reason (for the users) to do this, and it shows a complete disregard for privacy.
- deleted 3y ago[deleted]
- staplers 3y agoThere's no good reason (for the users) to do this Apple has compromised user privacy in the past (China) to avoid govt crackdown. I wouldn't be surprised if high-level agencies routinely mandate specific "functionality".
- zelon88 3y agoI abused this "feature" once to get a machine that had fallen out of MDM to connect to a network I controlled. The SSID I used was "Apple Store".
- Fnoord 3y agoYeah, I witnessed this as well. macOS too, at least previous version (not sure if still). I know this from installing a Pineapple (which has the same feature [1]) and seeing my SSID from home in it while the machine was at that point connected to wired, and not at home at all. This was approx 4 years ago, a few months before Covid pandemic. Either way, don't have Auto Join on. And, wired as much as possible. I guess in some point in future we only end up using mmWave and no more 2.4 GHz. [1] Nowadays you can do this too with a Flipper Zero e.g. with wlan dev board.
- rootusrootus 3y ago> Yeah, I witnessed this as well. Did you? Sounds like you're using MacOS. GP said he wiped MacOS and installed Linux, but sees SSIDs which persist from MacOS. Like those SSIDs got saved in hardware. I am convinced there is definitely a Reality Distortion Field but that it works both ways.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- rootusrootus 3y ago> they store the networks you connect to on a chip That is the first I've ever heard of such a thing, and it sounds implausible.
- walterbell 3y agoSome Apple Intel Macbooks came with an Arm T2 chip that controls security-related functions, e.g. disk encryption. With Apple Silicon, that capability is part of the M1/M2 SoC. If network SSID history is/was stored on the T2 chip, then it could likely be removed using MacOS settings before installing another operating system.
- chadcatlett 3y agoOlder Intel macs stored the SSIDs as UEFI vars, I think even the T2 ones did too but I might be wrong.
- walterbell 3y agoInteresting, I wonder if Windows does something similar.
- pxeboot 3y agoThis really is a feature on Macs. It works for Bluetooth too, apparently to allow network/keyboard/mouse functionality to work in recovery mode and to unlock an encrypted disk.
- rootusrootus 3y agoWhat I find especially weird is that even if there is a hardware level feature, why would that become available to a non-MacOS operating system?
- Nextgrid 3y agoIt's still stored in NVRAM, which the OS (or EFI firmware) has to consciously parse and then give to whatever process manages network connections. Nothing is stored in the wireless chip itself - those are generally stateless.
- NetworkPerson 3y agoThis likely had nothing to do with your Mac specifically. All wireless devices basically broadcast a statement out for anything to hear which goes like “Hey, here’s a full list of every SSID I’ve ever connected to, any of them available right now?” It’s very likely the program you were using caught one of those broadcasts from another one of your devices.
- oynqr 3y agoNowadays this only happens for "hidden" networks, because of the obvious privacy implications.
- NetworkPerson 3y agoMore devices still do than you might think. Had someone needing access into an Android phone recently. Wireless attacks proved easier than wired for that one. It broadcasted its list and from there was just a matter of spinning up SSID’s until I hit one that didn’t have a PW.
- somat 3y agoI have no idea what apple is doing but I will note that "fullmac" style radios have most of their operation internal to the device. The downside is now you have some strange insecure os running on the radio. The upside, the driver is simpler, and the system more power efficient. that is, you don't need an 802.11 stack. https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html https://blog.quarkslab.com/reverse-engineering-broadcom-wire...