10 ms·
AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]
- bell-cot 7mo agoOn the one hand, a seems-solid article by an author I mostly trust. OTOH... with the recent journalistic scandal at Ars Technica, perhaps Dan should have made sure that he spelled "Ubiquity" correctly? (5th para; it's correct further down.)
- John23832 7mo agoThat's an easy autocorrect issue. As someone who write Ubiquiti more often than most. I don't even think most editors would know the difference. That's the problem with using corruptions of real words as your name.
- bookofjoe 7mo agoI once suggested HN implement auto-correct because there are so many misspellings here. I was quickly downvoted.
- bell-cot 7mo ago> I don't even think most editors would know the difference. We're talking about Ars Technica, not USA Today. Kinda like MotorTrend editors should know what a Z-rated tire is. And I assume you've heard about the their AI fabrication scandal? - https://arstechnica.com/staff/2026/02/editors-note-retraction-of-article-containing-fabricated-quotations/ https://arstechnica.com/staff/2026/02/editors-note-retractio... Not a great look, if Ars either doesn't know, or can't control what they're actually publishing.
- pinkmuffinere 7mo agoIMO spelling mistakes have always been a relatively weak indicator of writing quality, let alone truthiness.
- g-b-r 7mo agoI was indeed very surprised to see that it's from Dan Goodin I only read his articles occasionally, but they always impressed me favorably; this one instead... the paper is probably clearer even for less technical people.
- jeroenhd 7mo agoPaper discussed in this article: https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/ https://www.ndss-symposium.org/ndss-paper/airsnitch-demystif...
- ProllyInfamous 7mo agoA paper author is here, discussing this bypass: <https://news.ycombinator.com/threads?id=vanhoefm https://news.ycombinator.com/threads?id=vanhoefm>
- madjam002 7mo agoDoes anyone know of any good firewalls for macOS? The built in firewall is practically unusable, and if client isolation can be bypassed, the local firewall is more important than ever. I often have a dev server running bound to 0.0.0.0 as it makes debugging easy at home on the LAN, but then if I connect to a public WiFi I want to know that I am secure and the ports are closed. "Block all incoming connections" on macOS has failed me before when I've tested it.
- runjake 7mo agoLittle Snitch is probably the most popular one, written my devs who deeply understand macOS firewall architecture. https://obdev.at/products/littlesnitch/index.html https://obdev.at/products/littlesnitch/index.html
- mrexcess 7mo agoLittle Snitch is commercial. If you want largely similar features (focused on egress), check out LuLu: https://github.com/objective-see/LuLu https://github.com/objective-see/LuLu
- runjake 7mo ago+1 Thanks, I forgot about LuLu!
- ProllyInfamous 7mo agoLittle Snitch is a user-friendly, software-level blocker, only – use with caution. Just FYI: LittleSnitch pre-resolves DNS entries BEFORE you click `Accept/Deny`, if you care & understand this potential security issue. Your upstream provider still knows whether you denied a query. Easily verifiable with a PiHole (&c). I liken the comparison to disk RAIDs: a RAID is not a true backup; LittleSnitch is not a true firewall. You need isolated hardware for true inbound/outbound protection.
- gruez 7mo ago
- cs702 7mo agoOriginal source (should replace the current link): https://www.ndss-symposium.org/wp-content/uploads/2026-f1282-paper.pdf https://www.ndss-symposium.org/wp-content/uploads/2026-f1282... Summary: https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/ https://www.ndss-symposium.org/ndss-paper/airsnitch-demystif... (hat tip: https://news.ycombinator.com/item?id=47167975 https://news.ycombinator.com/item?id=47167975)
- andrewstuart2 7mo agoYeah, this is a much clearer source and the abstract gets pretty directly to the point. The first paragraph tells you pretty much everything you need to know before you read more. The Ars article took 4 paragraphs to mention "client isolation" and even longer to get into the meat.
- amiljkovic 7mo agoArs is a very fitting name
- JumpCrisscross 7mo ago@dang, can we get the link and title changed?
- cwillu 7mo ago@dang doesn't do anything; email hn@ycombinator.com and they'll do something quite responsively.
- deleted 7mo ago[deleted]
- tomhow 7mo agoUpdated, thanks!
- sippeangelo 7mo agoBit of a sensational title? This doesn't "break WiFi encryption", only device isolation if the attacker is already in the same network.
- iamnothere 7mo agoMany businesses and universities, and likely some government offices, rely on client isolation for segmenting their networks. It’s a big deal.
- john_strinlai 7mo agoyou are definitely correct that it is potentially a big deal because it breaks expectation around network segmentation and isolation however, most people will read "breaks wi-fi encryption" and assume that it means that someone can launch this attack while wardriving, which they cant.
- ProllyInfamous 7mo ago>assume that it means that someone can launch this attack while wardriving, which they cant. As a former wardriver (¡WEPlol!), it only makes this more difficult. In my US city every home/business has a fiber/copper switch, usually outside. A screw-driver and you're in. Granted, this now becomes a physical attack (only for initial access) — but still viable. ---- >the next step is to put [AirSnitch] into historical context and assess how big a threat it poses in the real world. In some respects, it resembles the 2007 PTW attack ... that completely and immediately broke WEP, leaving Wi-Fi users everywhere with no means to protect themselves against nearby adversaries. For now, client isolation is similarly defeated—almost completely and overnight—with no immediate remedy available. ---- I think the article's main point is that so many places have similarly-such-unsecured plug-in points. Perhaps even a user was authorized for one WiFi network segment, and is already "in" — bless this digital mess!
- deleted 7mo ago[deleted]
- iamnothere 7mo agoOnce again I feel justified in hard wiring all connections. I do have a wireless network for a couple of portable devices, but everything else has a plug and a VLAN. It’s very difficult to have too much network security.
- NetMageSCW 7mo agoCounterpoint: it is trivial to have too much network security - don’t provide power. It is difficult to have just enough network security.
- benlivengood 7mo agoAs far as I can tell, all of these attacks require the attacker to already be associated to a victim's network. Most of these attacks seem similar to ones expected on shared wifi (airports, cafes) that have been known about for a while. The novel attacks seem to exploit weaknesses in particular router implementations that didn't actually segregate traffic between guest and normal networks. I'm curious if I missed something because that doesn't sound like it allows the worst kind of attacks, e.g. drive-by with no ability to associate to APs without cracking keys.
- wat10000 7mo agoThat’s my read as well. It’s not good, but it’s not nearly as bad as the headline makes it sound.
- strongpigeon 7mo agoThat's my read as well. It's bad for places that rely on client isolation, but not really for the general case. I feel like this also overstates the "stealing authentication cookies": most people's cookies will be protected by TLS rather than physical layer protection. Still an interesting attack though.
- NetMageSCW 7mo agoI think that places that rely on client isolation might be the general case - every public space that has a guest network - e.g. retail stores, doctor’s offices, hotels, hospitals - is probably using client isolation on their wireless network.
- tialaramex 7mo agoThe attacker doesn't need to be connected to the victim's network, only to the same hardware, the hardware's loss of isolation is the unexpected problem. Their University example is pertinent. The victim is an Eduroam user, and the attacker never has any Eduroam credentials, but the same WiFi hardware is serving both eduroam and the local guest provision which will be pretty bare bones, so the attacker uses the means described to start getting packets meant for that Eduroam user. If you only have a single appropriately authenticated WiFi network then the loss of isolation doesn't matter, in the same way that a Sandbox escape in your web browser doesn't matter if you only visit a single trusted web site...
- stebalien 7mo agoThe article is hot garbage, here's the abstract from the paper (https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/ https://www.ndss-symposium.org/ndss-paper/airsnitch-demystif...): To prevent malicious Wi-Fi clients from attacking other clients on the same network, vendors have introduced client isolation, a combination of mechanisms that block direct communication between clients. However, client isolation is not a standardized feature, making its security guarantees unclear. In this paper, we undertake a structured security analysis of Wi-Fi client isolation and uncover new classes of attacks that bypass this protection. We identify several root causes behind these weaknesses. First, Wi-Fi keys that protect broadcast frames are improperly managed and can be abused to bypass client isolation. Second, isolation is often only enforced at the MAC or IP layer, but not both. Third, weak synchronization of a client’s identity across the network stack allows one to bypass Wi-Fi client isolation at the network layer instead, enabling the interception of uplink and downlink traffic of other clients as well as internal backend devices. Every tested router and network was vulnerable to at least one attack. More broadly, the lack of standardization leads to inconsistent, ad hoc, and often incomplete implementations of isolation across vendors. Building on these insights, we design and evaluate end-toend attacks that enable full machine-in-the-middle capabilities in modern Wi-Fi networks. Although client isolation effectively mitigates legacy attacks like ARP spoofing, which has long been considered the only universal method for achieving machinein-the-middle positioning in local area networks, our attack introduces a general and practical alternative that restores this capability, even in the presence of client isolation.
- strongpigeon 7mo agoA tad sensationalist perhaps, but "hot garbage" is a bit much.
- stebalien 7mo agoMaybe I've just lost all patience for fluff, but I gave up trying to figure out what the attack was from the article pretty quickly where the abstract answered all my questions immediately.
- ProllyInfamous 7mo ago>Unlike previous Wi-Fi attacks, AirSnitch exploits core features in Layers 1 and 2 and the failure to bind and synchronize a client across these and higher layers, other nodes, and other network names such as SSIDs (Service Set Identifiers). This cross-layer identity desynchronization is the key driver of AirSnitch attacks. >The most powerful such attack is a full, bidirectional machine-in-the-middle (MitM) attack, meaning the attacker can view and modify data before it makes its way to the intended recipient. The attacker can be on the same SSID, a separate one, or even a separate network segment tied to the same AP. It works against small Wi-Fi networks in both homes and offices and large networks in enterprises. ---- I wardrove back in the early 2000s (¡WEP lol!). Spent a few years working in data centers. Now, reasonably paranoid. My personal network does not implement WiFi; my phone is an outgoing landline; tape across laptop cameras, disconnected antenna; stopped using email many years ago... Technology is so fascinating, but who can secure themselves from all the vulnerabilities that radio EMF presents? Just give me copper/fiber networks, plz. ---- >the next step is to put [AirSnitch] into historical context and assess how big a threat it poses in the real world. In some respects, it resembles the 2007 PTW attack ... that completely and immediately broke WEP, leaving Wi-Fi users everywhere with no means to protect themselves against nearby adversaries. For now, client isolation is similarly defeated—almost completely and overnight—with no immediate remedy available.
- JKCalhoun 7mo agoYou would like the film The Conversation (1974).
- ProllyInfamous 7mo agoFor a second I thought this was the Mel Gibson movie where he proves a Conspiracy Theory (1997)... but Gene Hackman, post-Watergate — with an ensemble cast of eavesdroppers?! — tonight's movie, decided. Thank you for your recommendation - it be crazy up in here (head, country, world).
- jasomill 7mo agoDirected by Francis Ford Coppola, Palme d'Or at Cannes, three Oscar nominations including Best Picture (which, amusingly, it lost to The Godfather Part II). Great movie.
- zekica 7mo agoThis only works for one SSID. Even then, one thing that can mitigate this is using Private-PSK/Dynamic-PSK on WPA2, or using EAP/Radius VLAN property. On WPA3/SAE this is more complicated: the standard supports password identifiers but no device I know of supports selecting an alternate password aside from wpa_supplicant on linux.
- supernetworks 7mo agoHostapd now has support for multi pass SAE /WPA3 password as well. We have an implementation of dynamic VLAN+per device PSK with WPA3 (https://github.com/spr-networks/super https://github.com/spr-networks/super) we've been using for a few years now. Ironically one of the main pain points is Apple. keychain sync means all the apple devices on the same sync account should share a password for wireless. Secondly the MAC randomization timeouts require reassignment. The trouble with SAE per device passwords is that the commit makes it difficult to evaluate more than one password per pairing without knowing the identity of a device (the MAC) a-priori, which is why it's harder to find this deployed in production. It's possible for an AP to cycle through a few attempts but not many, whereas in WPA2 an AP could rotate through all the passwords without a commit. The standard needs to adapt.
- bburky 7mo agoIs that the same feature as vlanid= in openwrt's wpa_psk_file? https://openwrt.org/docs/guide-user/network/wifi/basic#wpa_psk_file https://openwrt.org/docs/guide-user/network/wifi/basic#wpa_p... I was leaning towards using this configuration for splitting devices into VLANs while using one SSID. Yeah, dynamic VLAN+per device PSK would be best, but I'm probably happy enough with a shared PSK per VLAN to isolate a guest or IoT network. Would this VLAN isolation have prevented this attack? At least to prevent an attacker from jumping between VLANs? (I assume shared PSK per VLAN might be vulnerable to attacking client isolation within the VLAN?)
- zekica 7mo agoYes, VLAN isolation prevents this - devices in different VLANs use different GMK keys even when connected to the same network.
- this-is-why 7mo agoEven if they can rewrite the MAC and force a new one via ping, which are usually already disabled, they still can’t eavesdrop on the TLS key exchange. I fail to see how this is a risk to HTTPS traffic? It’s a mitm sure but it is watching encrypted traffic.
- amiljkovic 7mo agoThe Ars article mentions: “Even when HTTPS is in place, an attacker can still intercept domain look-up traffic and use DNS cache poisoning to corrupt tables stored by the target’s operating system.” Not sure, but I think this could then be further used for phishing.
- jcalvinowens 7mo agoDNSSEC prevents that if set up properly.
- tptacek 7mo agoThis is an on-path attacker. In end-user DNS configurations, attackers can simply disable DNSSEC; it's 1 bit in the DNS response header ("yeah, sure, I verified this for you, trust me").
- jcalvinowens 7mo agoNo, modern resolvers like systemd-resolved actually check the dnssec signatures on the client.
- akerl_ 7mo agoCan you link to a distro config that defaults to that?
- jcalvinowens 7mo agoNo, it's experimental. But I run it on all my machines, the only time I've had a problem is when it caught a typo in a DS record.
- deleted 7mo ago[deleted]
- _slih 7mo agoevery tested router was vulnerable to at least one variant. that's what happens when a security feature gets adopted industry-wide without ever being standardized, not a bug.
- g-b-r 7mo agoTangentially, does anyone know why so many of the (enormous amount of) papers accepted at this San Diego conference is from Chinese researchers? (https://www.ndss-symposium.org/ndss2026/accepted-papers https://www.ndss-symposium.org/ndss2026/accepted-papers) Has China become so prominent in security research?
- direwolf20 7mo agoChina has surpassed the USA in almost every metric except freedom (so far). They already do, or are close to doing, the most and best research in every field, producing the best and cheapest of every product category, and providing the best living standards for their Han Chinese citizens. Europe has a huge amount of catching up to do, and the US is basically a lost cause.
- vxxzy 7mo agoHad to read through all the cruft to get: "If the network is properly secured—meaning it’s protected by a strong password that’s known only to authorized users—AirSnitch may not be of much value to an attacker."
- nixpulvis 7mo agoIIUC the issue is, you could have a "secure" network and a guest network sharing an AP, and that guest network can access clients on the secure network. Someone did mention the xfinity automatic guest network, which might be a pain to disable? This is likely not a big deal for your home network, if you only have one network, but for many enterprise setups probably much worse.
- jcalvinowens 7mo agoThis is a big deal: it means a client on one wifi network can MITM anything on any other wifi network hosted on the same AP, even if the other wifi network has different credentials. Pretty much every enterprise wifi deployment I've ever seen relies on that isolation for security. These attacks are not new: the shocking thing here that apparently a lot of enterprise hardware doesn't do anything to mitigate these trivial attacks!
- Waterluvian 7mo agoLike as in me being on the Guest network at a business can then read traffic of the Corporate network?
- jcalvinowens 7mo ago> Like as in me being on the Guest network at a business can then read traffic of the Corporate network? Exactly.
- daneel_w 7mo agoYes, if they host the guest network on the same hardware, same transmission path etc. Network "hygiene" will obviously differ from one place to the other.
- winstonwinston 7mo agoYes, though do all of these wifi devices actually have a formal assurance (as in written specification) of network L2/L3 isolation between virtual APs? I have some of those wifi APs that do not even provide any sort of isolation besides just implementing multiple SSID on the same wifi radio aka Guest SSID. No guarantee, no isolation.
- economistbob 7mo agoI just read the paper, and my take is that practically every home wifi user can now get pwned since most WiFi routers use the same SSID and 2.4 and 5Ghz. It can even beat people using Radius authentication, but they did not deep dive on that one. I am curious about whether the type of EAP matters for reading the traffic. Essentially everyone with the SSID on multiple access point MAC addresses can get pwned. Neighhood hackers drove me to EAP TLS a few years ago, and I only have it on one frequency, so the attack will not work. The mitigation is having only a single MAC for the AP that you can connect to. The attack relies on bouncing between two. A guest and regular, or a 2.4 and 5, etc. I need to research more to know if they can read all the packets if they pull it off on EAP TLS, with bounces between a 2.4 and 5 ghz. It is a catastrophic situation unless you are using 20 year old state of the art rather that multi spectrum new hotness. It might even get folks on a single SSID MAC if they do not notice the denial of service taking place. I need to research the radius implications more. TLS never sends credentials over the channel like the others. It needs investigation to know if they get the full decryption key from EAP TLS during. They were not using TLS because their tests covered Radius and the clients sending credentials. It looks disastrous if the certificates of EAP TLS do not carry the day and they can devise the key. That is my take.
- Sytten 7mo agoThey still need to be able to connect to one of the network no? So a home network without guest would be fine is my understanding?
- economistbob 7mo agoIt requires disassociating and reassociating to the MAC so it requires two, which would cause a denial of service one would notice while watching it. Whether they can denial of service their way to the key, while someone is not actively watching, was not addressed. The paper is about essentially getting data from clients when there are two MACs. They glossed over the one MAC situation by saying someone would notice it so it was not useful. My concern is doing it asynchronously against things when no one is watching. Basically it takes turn being the client and the AP both so that it can get the traffic from both. It is an evil twin attack doubled. It might have broken EAP TLS. If your wifi is off when you are not using it and you are not getting denial of serviced while using it and you have only one Mac for your SSID, this attack is not occuring.
- ErneX 7mo agoThe attacker needs to be connected to a wireless network if I understood this correctly?
- ProllyInfamous 7mo agoFor all users reading this on their own home network: DISABLE ALL GUEST NETWORKS It seems as if approved guest access now == system-wide access (at the hardware level). User compartmentalization no longer works.
- pluralmonad 7mo agoIs this still true if the guest network is on its own isolated vlan?
- ProllyInfamous 7mo agoCorrect; this appears to be a hardware-level problem.
- mlhpdx 7mo agoIt seems like this attack would be thwarted by so called “multi PSK” networks (non-standard but common tech that allows giving each client their own PSK on the same SSID). Is that true?
- supernetworks 7mo agoThis attack exploits multi PSK networks precisely. If it's all one PSK the attacker can already throw up a rogue AP for WPA3 or just sniff/inject WPA2 outright. The back half of a secure multi PSK setup is deploying VLANs for segmentation, to block these attacks. WiFi provides half-way measures with client isolation features that break down when the packets hit L3, or in some cases the broadcast key implementations are deficient allowing L2 attacks. The paper is about all of the fun ways they could pivot across networks, and they figured out how to enable full bidirectional MITM in a wider class of attacks than commonly known or previously published.
- jwr 7mo agoIncidentally, this client isolation thing can be extremely annoying in practice in networks you do not control. Hardware device makers just assume that everything is on One Big Wi-Fi Network and all devices can talk to all other devices and sing Kum-Ba-Yah by the fire. Then comes network isolation and you can no longer turn on your Elgato Wi-Fi controlled light, talk to your Bose speaker, or use a Chromecast.
- Chihuahua0633 7mo agoAdding exceptions for certain protocols, IP ranges (maybe multicast, even) are certainly ways around this, but I imagine with every hole you poke to allow something, you are also opening a hole for data to leak.
- c0nsumer 7mo agoClient isolation is done at L2. You can't add exceptions for IP ranges / protocols / etc this way because that's up the stack. Even if devices can learn about each other in other ways, isolation gets in the way of direct communication between them.
- oasisbob 7mo agoThe paper makes the point that you need to consider L3 in client isolation too - they call this the gateway bouncing attack. If you can hairpin traffic for clients at L3, it doesn't matter what preventions you have at L2
- wtallis 7mo agoEven when not using client isolation, I've run into similar problems simply from having a computer connected over Ethernet instead of WiFi, and whatever broadcast method a gadget uses for discovery didn't get bridged between wired and wireless. (Side note: broadcast traffic on WiFi can be disproportionately problematic because it needs to be transmitted at a lowest common denominator speed to ensure all clients can receive it. IIRC, that usually means 6Mbps.)
- 7mo ago
- blobbers 7mo agoIf you're a panicking IT guy, from the original paper: "WPA2/3-Enterprise. These attacks generally do not work against WPA2/3-Enterprise networks..." So this is a protocol attack, not an encryption attack. If you're using proper encryption per client, there is no attack available.
- ProllyInfamous 7mo agoOnly WPA2/3-Enterprise networks which offer no guest network access.
- aspenmayer 7mo agoI think this might be the repo? https://github.com/zhouxinan/airsnitch https://github.com/zhouxinan/airsnitch Edit: it’s the same repo as linked in the paper, so it seems likely to be the correct repo, though I didn’t originally find it via the paper.
- fabioyy 7mo agomacsec can encrypt data in ethernet for lan, maybe it can solve this
- api 7mo agoClient isolation is helpful in the real world, but it's yet another band aid for the deeper more fundamental problem. If a device is insecure when placed directly onto the Internet with no firewall, it is insecure. Full stop. Everything else is a hack around that fact. Sometimes you have to do that since you can't fix broken stuff, but it's still broken.
- NetMageSCW 7mo agoJust like it isn’t normal to buy one UPS per server, it is sensible to have one more capable firewall for all your servers, even if it does put you in a M&M situation.
- sgalbincea 7mo agoI'd like to see more enterprise-grade equipment tested.
- kittikitti 7mo agoOther members of my household frequently invite people to my own place that have malicious intent against me. They don't like me for reasons like not being a fan of Trump, Drake, or N3on. Unfortunately, this is a risk that many people other than me have to face. This is an eye-opening article as I do provide my guest password to them. I plan on disabling the guest network entirely and utilizing a completely different router for the guest network. As the paper states, an isolated guest network isn't standardized. I plan on revisiting my network security once it is.
- andsoitis 7mo ago> Other members of my household frequently invite people to my own place that have malicious intent against me. Are you being abused or something? This sounds ridiculous
- kittikitti 7mo agoYou might have extended family and friends who are Trump supporters and wish to own the libs. This is something many people in the US have to deal with. It's not even hard to find even on YCombinator, I just had a reply flagged for comparing Israel to Nazi's.
- champtar 7mo agoJust being able to inject traffic is already huge as it allow you to send IPv6 router advertisement, which sometimes allows you to change the DNS config
- fdefitte 7mo ago[dead]
- genie3io 7mo ago[dead]
- paulnpace 7mo agoVery encouraging to see they are testing the open source projects like OpenWrt. Too often these types of tests target the most popular off-the-shelf products, "enterprise" products, and obscure knock-off products.