![]() |
iPhone & WiFi - What Can "They" See?
Im aware of the concerns surrounding the transmitting of private data while on public wifi, as it's easy for hackers to steal your passwords, account numbers, etc. I'm curious about using a device like an iPhone on a public network, and how much data is transmitted by the phone while connected. For instance, can the network owner see private information such as phone number and the name assigned to the phone? It occurred to me as I was browsing the Internet in a restaurant with free wifi, how much could an unscrupulous network admin find out about me just by being connected?
|
That is a good question. It will be interesting to see any facts. I suspect you will hear from the tin foil hat group that "they" can see everything.
I find myself using the 3G service on my phone more than many free internet connections for any sensitive things. I figure AT&T has better security than a local sandwich shop. No doubt AT&T could see everything on my phone already. |
Just look at your phone by accessing your router (on another device) that should answer your question.
I name my devices strange things so that anybody looking at my on the wifi gets a real wtf. For instance I am typing on the Porn-O-Matic-XL-7000 right now |
Let's narrow down "they" to the network admin/resident IT guy. The real "they" gather data by black helicopter, everybody knows that!:D
|
Should of went to defcon. (http://www.defcon.org/) One of my guys went. He now powers everything down on his cell phone and knows that his phone is not secure, especially in the arena of it being used by someone else to do things w/o your knowledge.
And this is the stuff that people are willing to talk about. There's so much more that is never discussed; true cutting edge stuff. |
Well, for starters, look at the log on your home wireless router. In the least, they can see that same information (websites visited per device IP).
Keep in mind that https:// websites only encrypt from the physical router out. So anything travelling in the air between your device and the router is theoretically accessable, unless you have some form of encryption between the device and the router (WEP or WPA, for example) -Z |
Quote:
|
If you're talking about your average IT admin - most couldn't figure out an SSID unless it was actually broadcasting the SSID name.
If you're talking about someone above average or exceptional then I wouldn't connect to any OPEN wifi - they are absolutely not secure on the local network and everyone within listening range can capture everything you do and see it in clear text. If they are using a password to secure things then you want to make sure it is a WPA connection at the very least. If they use TKIP encryption then it is crackable but if they use AES you're better off and pretty secure. WPA2 is better. If it is WEP with a password it might as well be open. From a wifi perspective the encryption is between the end station (your phone) and the router. The packets can still be captured but with the right encryption (AES) they are pretty safe. The keys are random and generated individually between the end station and the wifi access point or router. If you want to talk about black hat stuff where some guy in the coffee shop has turned his laptop into an access point and he is catching everything including the key generation then you're screwed. He/She has it all and you can't really tell. That's the reader's digest version. Let me know if you would like me to do more. If you have a windows computer and spend any time at a starbucks or what not using their wifi - download netstumbler and just run it to see what is going on from a wifi perspective around you. Heck, do it at your house to see how many of your neighbors are stupid. Then find the ones with open wifi networks - find their printers and print out some girls in bikinis for them. |
Quote:
|
So does a device like the iPhone transmit the device name, phone number, your name, or device SN?
|
Quote:
|
Quote:
Assuming the cert is not compromised... |
it sounds like they could potentially grab enuff info to get into your machine and grab any info on it -- difficult? maybe easier if you go to the same coffeeshop all the time?
I have no idea whether they access you and then be able to see Uranus |
Quote:
WPA2 has been shown to be cracked in reasonable time. if yer at defcon, yea turn everything off. |
Quote:
|
Quote:
That said, when the first handshake occurs between the https site and the end device, the encryption key is passed to the device. If a sniffer is there to capture the key, then it doesn't matter how secure the website is... So - surfing Pelican on a public wifi - I will do. Banking or credit card transactions I won't. -Z |
I'm looking at your phone now and you are a very naught naughty boy!
|
Quote:
|
At minimum, the local wi-fi hot spot would have your MAC address. It could be used to prove that you were in the area. So make sure you don't dump the bodies there, mkay?
|
Quote:
|
All times are GMT -8. The time now is 02:22 PM. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website