Heh, with the government using stuff like IMSI catchers, I would not be surprised at all if using a faked AP is a common tool in the box of the 3-letter agencies.
I'm fine with Marriott using deauth jamming against rogue APs with their SSID (or a similar impersonating one, e.g. "Mariott Wifi" instead of "Marriott Wifi"), or operating on their specific wifi channel (thus downgrading the experience of the customers), but they absolutely have to leave APs alone which have a different channel/ssid.
I'm fine with Marriott using deauth jamming against [...] or operating on their specific wifi channel
While they might have a justification that a "Mariott Wifi" ESSID on a Mariott hotel is theirs, how can they say a specific wifi channel is "theirs"? Wifi runs in unlicensed bands, any device which meets certain technical requirements is allowed on any channel in these bands, no matter who the device owner is. The 802.11 protocol is designed to share wireless channels between APs with different owners (while it also assumes that APs with the same ESSID have the same owner).
And what would be "their" channel? A well-designed wireless network for a large enough area will use several channels. Unless they have a single AP (unlikely) or their network is not well designed, they are probably using all the non-overlapping channels in the 2.4 GHz band and many channels in the 5 GHz band, including all the non-DFS ones.
No, the real hotel access points, including at Marriott, are part of their attack strategy. They get hacked, sometimes via physical means, and commandeered to launch high-grade targeted malware.
The South Korean government has done that quite regularly, for one (known as DarkHotel), and I do believe GCHQ does it over here from time to time. Several others too, I expect. Intelligence agencies just like hotels, I guess, between the visitors of diplomatic, political and economic interest, the public access, potentially lowered guard, and things left unattended in hotel rooms locked by surprisingly forgeable master keys?
Comments
Heh, with the government using stuff like IMSI catchers, I would not be surprised at all if using a faked AP is a common tool in the box of the 3-letter agencies.
I'm fine with Marriott using deauth jamming against rogue APs with their SSID (or a similar impersonating one, e.g. "Mariott Wifi" instead of "Marriott Wifi"), or operating on their specific wifi channel (thus downgrading the experience of the customers), but they absolutely have to leave APs alone which have a different channel/ssid.
While they might have a justification that a "Mariott Wifi" ESSID on a Mariott hotel is theirs, how can they say a specific wifi channel is "theirs"? Wifi runs in unlicensed bands, any device which meets certain technical requirements is allowed on any channel in these bands, no matter who the device owner is. The 802.11 protocol is designed to share wireless channels between APs with different owners (while it also assumes that APs with the same ESSID have the same owner).
And what would be "their" channel? A well-designed wireless network for a large enough area will use several channels. Unless they have a single AP (unlikely) or their network is not well designed, they are probably using all the non-overlapping channels in the 2.4 GHz band and many channels in the 5 GHz band, including all the non-DFS ones.
No, the real hotel access points, including at Marriott, are part of their attack strategy. They get hacked, sometimes via physical means, and commandeered to launch high-grade targeted malware.
The South Korean government has done that quite regularly, for one (known as DarkHotel), and I do believe GCHQ does it over here from time to time. Several others too, I expect. Intelligence agencies just like hotels, I guess, between the visitors of diplomatic, political and economic interest, the public access, potentially lowered guard, and things left unattended in hotel rooms locked by surprisingly forgeable master keys?