Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As I said originally, just change the BSSID periodically. The network name is the network identity, and people deal with collisions just fine. Also, this is back to the case of non-WPA2 (otherwise the user would have to enter the secret K anyway, merely changing the process slightly).


> Also, this is back to the case of non-WPA2...

Okay, I'm a little confused, please bear with me.

Are you designing two half systems, one of which periodically changes BSSID but provides no other anonymity protection, and the other which hashes the BSSID with the WPA2 PSK?

Or are you designing one system with a rotating BSSID that transmits -in cleartext- the BSSID and the hashed BSSID?


I'm pointing out existence certificates of each independent property. View them as two systems, or assume they can be merged into one system.

It's obviously impossible to have a publicly-available network that hides its existence to the public (while a private network can obviously hide its existence to the public completely), so each problem will obviously have different ideal solutions.


> View them as two systems, or assume they can be merged into one system.

It's the merging and the details of the same that's the complicated bit, and the only thing worth talking about in this sub-thread.

You made the assertion that the "the committees designing [wireless communications] protocols don't think [that things screamed on the street corner are public data]". [0] This is simply not true. The folks who designed 802.11 had to make several key-management-complexity/computational-power/ease-of-use tradeoffs.

> ...while a private network can obviously hide its existence to the public completely...

Not if it's a relatively-high-performance radio network operating in a relatively tiny slice of spectrum, [1] it can't.

[0] https://news.ycombinator.com/item?id=10950276

[1] As 802.11b/g/n does


Merging them really only means merging the concepts for a common model of administration. Public and private are two completely different modes, and don't exist simultaneously.

A high-bandwith radio transmitter obviously gives its presence up, but that doesn't mean it needs to identify itself. Of course the FCC likes transmitters to do this, but that too is an anti-feature with respect to public-use spectrum.

There were obviously tradeoffs involved for 802.11, which is how we got WEP. I'd just be surprised if having a (semi-)fixed MAC address was ever questioned, given that it's the basis for 802.3 and leaking some associated identity is basically a forgone conclusion in today's world of license plates, etc. But with the obvious effects of mechanized tracking and aggregation, it really shouldn't be. So I stand by my assertion that the designers would have benefited from a perspective where being pushed to do the equivalent of continually shouting/showing one's identity is a very bad thing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: