home.social

#airsnitch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #airsnitch, aggregated by home.social.

fetched live
  1. 🛜 "W skrócie: 25 lutego 2026 r. naukowcy z Uniwersytetu Kalifornijskiego w Riverside i Uniwersytetu Katolickiego w Leuven zaprezentowali narzędzie AirSnitch podczas sympozjum NDSS w San Diego. Jest to zestaw narzędzi do ataków, które omijają „izolację klienta” — funkcję Wi-Fi, która ma zapobiegać wzajemnym atakom użytkowników w tej samej sieci. Przetestowano 11 routerów firm Cisco, Netgear, D-Link, ASUS, TP-Link, Ubiquiti, Tenda i LANCOM, a także oprogramowanie open source DD-WRT i OpenWrt. Każdy z nich był podatny na co najmniej jeden atak. WPA2, WPA3, sieci korporacyjne z indywidualnymi loginami — nic z tego nie miało znaczenia. Jeśli osoba atakująca połączy się z tą samą siecią Wi-Fi co Ty, może przechwycić Twój ruch, odczytać Twoje dane i przeprowadzić ataki typu „man-in-the-middle”. Rozwiązaniem nie jest poprawka oprogramowania sprzętowego. Jest to problem architektoniczny, który wymaga zmian w samym standardzie IEEE 802.11."

    Całość [EN]:
    stateofsurveillance.org/news/a

    #wifi #security #AirSnitch

  2. So … #AirSnitch is just hot air?
    Actionable thing for anyone: Don't bridge trusted/untrusted networks (if you don't know whether your router properly separates both networks, run).

    And going forward, don't assume public (password protected) hotspots are safe for unencrypted connections - which they never were, because the entire internet is not safe for unencrypted connections.

  3. "New research shows that behaviors that occur at the very lowest levels of the network stack make encryption—in any form, not just those that have been broken in the past—incapable of providing client isolation, an encryption-enabled protection promised by all router makers, that is intended to block direct communication between two or more connected clients.

    The isolation can effectively be nullified through AirSnitch, the name the researchers gave to a series of attacks that capitalize on the newly discovered weaknesses. Various forms of AirSnitch work across a broad range of routers, including those from Netgear, D-Link, Ubiquiti, Cisco, and those running DD-WRT and OpenWrt.

    AirSnitch “breaks worldwide Wi-Fi encryption, and it might have the potential to enable advanced cyberattacks,” Xin’an Zhou, the lead author of the research paper, said in an interview. “Advanced attacks can build on our primitives to [perform] cookie stealing, DNS and cache poisoning. Our research physically wiretaps the wire altogether so these sophisticated attacks will work. It’s really a threat to worldwide network security.” Zhou presented his research on Wednesday at the 2026 Network and Distributed System Security Symposium.

    Paper co-author Mathy Vanhoef, said a few hours after this post went live that the attack may be better described as a Wi-Fi encryption “bypass,” “in the sense that we can bypass client isolation. We don’t break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;)” People who don’t rely on client or network isolation, he added, are safe."

    arstechnica.com/security/2026/

    #CyberSecurity #Wifi #Encryption #AirSnitch

  4. AirSnitch: “nowy atak na WiFi omijający szyfrowanie”.

    Tego typu nagłówki mogą być trochę mylące (a pojawiają się już w zachodnich mediach). Zobaczmy wiec co właśnie ujawnili badaczo-hackerzy ;) Atak umożliwia podsłuch ruchu w sieci WiFi (atak Man in The Middle). Brzmi groźnie? No tak, ale: W badaniach ataki wykazywały się wysoką skutecznością – blisko 100% (tj. nie...

    #WBiegu #Airsnitch #Ataki #Mitm #Podsłuch #Wifi

    sekurak.pl/airsnitch-nowy-atak

  5. #AirSnitch umgeht zentrale Schutzmechanismen in WLAN-Netzen und ermöglicht Man-in-the-Middle-Angriffe. Betroffen sind zahlreiche Router-Modelle, auch mit #OpenWrt. winfuture.de/news,157151.html?

  6. New #AirSnitch attack breaks Wi-Fi #encryption in homes, offices, and enterprises

    It’s hard to overstate the role that Wi-Fi plays in virtually every facet of life. The organization that shepherds the #wireless protocol says that more than 48 billion Wi-Fi-enabled devices have shipped since it debuted in the late 1990s. One estimate pegs the number of individual users at 6 billion, roughly 70 percent of the world’s population.
    #wifi #security #privacy

    arstechnica.com/security/2026/

  7. #AirSnitch sounds wild, hopefully more details will be released soon

  8. Oh, I'm curious. #AirSnitch breaks #WiFi encryption. From the paper:
    In summary, we make the following contributions.
    • We introduce novel MitM primitives that break client isolation, which was commonly believed to protect Wi-Fi clients from one another, enabling MitM attacks relating to both uplink and downlink traffic.
    • We show that Wi-Fi client isolation in single-BSSID networks (e.g., home networks) is fundamentally broken for all WPA versions.
    • We extend our bypasses to multi-AP and multi-SSID networks, common in enterprises, analyze their root cause, and sometimes even leak traffic in plaintext.
    • We show that our attacks can also intercept traffic of internal wired devices, allowing higher-layer attacks previously thought impractical, which we illustrate by breaking weak back-end RADIUS passwords.
    • We evaluate our attacks on various devices and networks including two real university networks, discuss defenses, and open-source our code for reproducibility of our tests.


    Read more:


    #security #hacking
  9. As I understand it, the #AirSnitch attack does require connectivity to the same shared network infrastructure. For example hosting a guest Wi-Fi AP on the same gear can make clients connected via 802.1X + RADIUS vulnerable to attacks.

    Whether a specific setup is vulnerable or not depends on how the system has been set up. Many home and SOHO systems share guest and other SSIDs and are vulnerable as they host the networks on the same devices.

    Separate guest networks that are not sharing any network equipment are safe.

    If unsure you should disable Guest APs and other unauthenticated access to your network.

  10. You should always consider network transport just that: a transport. It's not a security control. You should always use encryption on top of the transport, no matter the type. HTTPS is good, VPN is even better.

    @arstechnica
    "New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises"

    arstechnica.com/security/2026/

    paper: ndss-symposium.org/wp-content/

    #infosec #cybersecurity #airsnitch

  11. 🔒💥 "AirSnitch" sounds like a Harry Potter character who broke into your Wi-Fi to tell everyone your cat memes are outdated. Meanwhile, Ars Technica continues the tradition of hyping tech apocalypse scenarios that no one asked for. 😱📡
    arstechnica.com/security/2026/ #AirSnitch #TechApocalypse #WiFi #Security #CatMemes #ArsTechnica #HackerNews #ngated