Hacker News new | past | comments | ask | show | jobs | submit login

> An attacker can't create a different network with the same SSID and trick existing devices to connect to it, right?

Can't he? Wouldn't the existing devices just try to connect to whatever broadcasts that SSID.




Some devices actually verify the MAC of the sender, but that’s probably the exception and not the rule.


That wouldn't help - Its trivial to configure an access point to advertise a user-selected MAC address, and the MAC address of an AP is broadcast in the clear even on WPA2 encrypted networks.


I think the parent post is referting to a Message Authentication Code not a mac address which an attacker couldn't forge.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: