Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. That guest SSID you set up for your neighbors may not be as secure as you think

That guest SSID you set up for your neighbors may not be as secure as you think

Scheduled Pinned Locked Moved Uncategorized
10 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • dangoodin@infosec.exchangeD This user is from outside of this forum
    dangoodin@infosec.exchangeD This user is from outside of this forum
    dangoodin@infosec.exchange
    wrote last edited by
    #1

    That guest SSID you set up for your neighbors may not be as secure as you think

    Link Preview Image
    New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises

    That guest network you set up for your neighbors may not be as secure as you think.

    favicon

    Ars Technica (arstechnica.com)

    mansr@society.oftrolls.comM 0x76@fedi.xirion.net0 0x4d6165@transfem.social0 3 Replies Last reply
    2
    0
    • dangoodin@infosec.exchangeD dangoodin@infosec.exchange

      That guest SSID you set up for your neighbors may not be as secure as you think

      Link Preview Image
      New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises

      That guest network you set up for your neighbors may not be as secure as you think.

      favicon

      Ars Technica (arstechnica.com)

      mansr@society.oftrolls.comM This user is from outside of this forum
      mansr@society.oftrolls.comM This user is from outside of this forum
      mansr@society.oftrolls.com
      wrote last edited by
      #2

      @dangoodin Can someone please translate this quote into something meaningful?

      "Our research physically wiretaps the wire altogether so these sophisticated attacks will work."

      1 Reply Last reply
      0
      • dangoodin@infosec.exchangeD dangoodin@infosec.exchange

        That guest SSID you set up for your neighbors may not be as secure as you think

        Link Preview Image
        New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises

        That guest network you set up for your neighbors may not be as secure as you think.

        favicon

        Ars Technica (arstechnica.com)

        0x76@fedi.xirion.net0 This user is from outside of this forum
        0x76@fedi.xirion.net0 This user is from outside of this forum
        0x76@fedi.xirion.net
        wrote last edited by
        #3

        @dangoodin I feel like VLANs are really just the solution here?

        That's what I was planning on setting up at my home network in any case for IoT devices

        morattisec@infosec.exchangeM 1 Reply Last reply
        0
        • dangoodin@infosec.exchangeD dangoodin@infosec.exchange

          That guest SSID you set up for your neighbors may not be as secure as you think

          Link Preview Image
          New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises

          That guest network you set up for your neighbors may not be as secure as you think.

          favicon

          Ars Technica (arstechnica.com)

          0x4d6165@transfem.social0 This user is from outside of this forum
          0x4d6165@transfem.social0 This user is from outside of this forum
          0x4d6165@transfem.social
          wrote last edited by
          #4

          @dangoodin@infosec.exchange vlan tho

          1 Reply Last reply
          0
          • R relay@relay.mycrowd.ca shared this topic
          • 0x76@fedi.xirion.net0 0x76@fedi.xirion.net

            @dangoodin I feel like VLANs are really just the solution here?

            That's what I was planning on setting up at my home network in any case for IoT devices

            morattisec@infosec.exchangeM This user is from outside of this forum
            morattisec@infosec.exchangeM This user is from outside of this forum
            morattisec@infosec.exchange
            wrote last edited by
            #5

            @0x76 @dangoodin I mean, I think the interesting piece is client isolation is weird nonstandard and shouldn’t be relied on by itself.

            Adding VLANs adds additional layers of complexity. An attacker could still attempt VLAN Tagging packets.

            This could legitimately change a lot of network threat models. Many network issues/vulns have probably been downgraded in severity on the basis of “this doesn’t matter because Client Isolation exists”.

            0x76@fedi.xirion.net0 1 Reply Last reply
            1
            0
            • R relay@relay.infosec.exchange shared this topic
            • morattisec@infosec.exchangeM morattisec@infosec.exchange

              @0x76 @dangoodin I mean, I think the interesting piece is client isolation is weird nonstandard and shouldn’t be relied on by itself.

              Adding VLANs adds additional layers of complexity. An attacker could still attempt VLAN Tagging packets.

              This could legitimately change a lot of network threat models. Many network issues/vulns have probably been downgraded in severity on the basis of “this doesn’t matter because Client Isolation exists”.

              0x76@fedi.xirion.net0 This user is from outside of this forum
              0x76@fedi.xirion.net0 This user is from outside of this forum
              0x76@fedi.xirion.net
              wrote last edited by
              #6

              @morattisec @dangoodin yeah I'm definitely surprised even enterprise gear doesn't have more robust client isolation.

              morattisec@infosec.exchangeM 1 Reply Last reply
              0
              • 0x76@fedi.xirion.net0 0x76@fedi.xirion.net

                @morattisec @dangoodin yeah I'm definitely surprised even enterprise gear doesn't have more robust client isolation.

                morattisec@infosec.exchangeM This user is from outside of this forum
                morattisec@infosec.exchangeM This user is from outside of this forum
                morattisec@infosec.exchange
                wrote last edited by
                #7

                @0x76 @dangoodin True. A problem you can’t just throw money at to upgrade something is worse.

                Research like this is also rough because it’s entirely possible the response is just that hardware vendors do a PR response unless they get a lot of flak they can’t dodge.

                Cynically, I could see vendors saying, “what we’ve done is put VRAM on our newer switch and APs, and now frames/packets are dropped via AI model”. Then selling that to all the companies with a budget and leaving consumer-grade equipment saddled with needing defense-in-depth because “legacy” Client Isolation is now considered best effort.

                IMO, the money from fixing consumer protections isn’t going to be seen as worth it unless the fix is incredibly simple to dev and roll out retroactively.

                0x76@fedi.xirion.net0 1 Reply Last reply
                0
                • morattisec@infosec.exchangeM morattisec@infosec.exchange

                  @0x76 @dangoodin True. A problem you can’t just throw money at to upgrade something is worse.

                  Research like this is also rough because it’s entirely possible the response is just that hardware vendors do a PR response unless they get a lot of flak they can’t dodge.

                  Cynically, I could see vendors saying, “what we’ve done is put VRAM on our newer switch and APs, and now frames/packets are dropped via AI model”. Then selling that to all the companies with a budget and leaving consumer-grade equipment saddled with needing defense-in-depth because “legacy” Client Isolation is now considered best effort.

                  IMO, the money from fixing consumer protections isn’t going to be seen as worth it unless the fix is incredibly simple to dev and roll out retroactively.

                  0x76@fedi.xirion.net0 This user is from outside of this forum
                  0x76@fedi.xirion.net0 This user is from outside of this forum
                  0x76@fedi.xirion.net
                  wrote last edited by
                  #8

                  @morattisec @dangoodin yeah I'd see them quicker pull the feature entirely than some kind of proper fix. Do think it would be good it some kind of standard could be developed for client isolation in future, but that's likely far in the future

                  morattisec@infosec.exchangeM 1 Reply Last reply
                  0
                  • 0x76@fedi.xirion.net0 0x76@fedi.xirion.net

                    @morattisec @dangoodin yeah I'd see them quicker pull the feature entirely than some kind of proper fix. Do think it would be good it some kind of standard could be developed for client isolation in future, but that's likely far in the future

                    morattisec@infosec.exchangeM This user is from outside of this forum
                    morattisec@infosec.exchangeM This user is from outside of this forum
                    morattisec@infosec.exchange
                    wrote last edited by
                    #9

                    @0x76 @dangoodin I think the WiFi 8 spec is coming soon? Maybe the body for that might be able to at least add something into the spec (if it exists)

                    0x76@fedi.xirion.net0 1 Reply Last reply
                    0
                    • morattisec@infosec.exchangeM morattisec@infosec.exchange

                      @0x76 @dangoodin I think the WiFi 8 spec is coming soon? Maybe the body for that might be able to at least add something into the spec (if it exists)

                      0x76@fedi.xirion.net0 This user is from outside of this forum
                      0x76@fedi.xirion.net0 This user is from outside of this forum
                      0x76@fedi.xirion.net
                      wrote last edited by
                      #10

                      @morattisec @dangoodin would be curious to see if there's anything there, if not, how these things work will probably be a 9 thing

                      1 Reply Last reply
                      0
                      • R relay@relay.an.exchange shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups