Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m not asking for an explanation of what the problem is (and your explanation is wrong), I’m asking about why WiFi spec is designed with this very specific, seemingly obvious flaw (anyone can fake deauth to DoS anyone else). I doubt this wasn’t considered during the design process, and I don’t think the rationale is “screw you”, so there’s gotta be a reason.

Edit: According to other comments, it seems that “spoofed” deauth does have legit use cases (other than DoS’ing neighbor’s internet of shit devices).



The "legit" use cases people found for it were unlikely to be the reason the protocol was designed that way. Remember 802.11 came out in 1997. In 2004 WPA2 was released and allowed for protected management frames but no devices/users cared enough at the time. Now in 2019 users are more security aware and encryption is cheap so WPA3 requires it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: