![]() |
|
|
|
Did you get the memo?
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,368
|
iPhone & WiFi - What Can "They" See?
Im aware of the concerns surrounding the transmitting of private data while on public wifi, as it's easy for hackers to steal your passwords, account numbers, etc. I'm curious about using a device like an iPhone on a public network, and how much data is transmitted by the phone while connected. For instance, can the network owner see private information such as phone number and the name assigned to the phone? It occurred to me as I was browsing the Internet in a restaurant with free wifi, how much could an unscrupulous network admin find out about me just by being connected?
|
||
![]() |
|
Get off my lawn!
|
That is a good question. It will be interesting to see any facts. I suspect you will hear from the tin foil hat group that "they" can see everything.
I find myself using the 3G service on my phone more than many free internet connections for any sensitive things. I figure AT&T has better security than a local sandwich shop. No doubt AT&T could see everything on my phone already.
__________________
Glen 49 Year member of the Porsche Club of America 1985 911 Carrera; 2017 Macan 1986 El Camino with Fuel Injected 350 Crate Engine My Motto: I will never be too old to have a happy childhood! |
||
![]() |
|
I'm with Bill
Join Date: Jun 2005
Location: Scottsville Va
Posts: 24,186
|
Just look at your phone by accessing your router (on another device) that should answer your question.
I name my devices strange things so that anybody looking at my on the wifi gets a real wtf. For instance I am typing on the Porn-O-Matic-XL-7000 right now
__________________
Electrical problems on a pick-up will do that to a guy- 1990C4S |
||
![]() |
|
Did you get the memo?
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,368
|
Let's narrow down "they" to the network admin/resident IT guy. The real "they" gather data by black helicopter, everybody knows that!
![]() |
||
![]() |
|
Registered
|
Should of went to defcon. (http://www.defcon.org/) One of my guys went. He now powers everything down on his cell phone and knows that his phone is not secure, especially in the arena of it being used by someone else to do things w/o your knowledge.
And this is the stuff that people are willing to talk about. There's so much more that is never discussed; true cutting edge stuff. |
||
![]() |
|
Moderator
|
Well, for starters, look at the log on your home wireless router. In the least, they can see that same information (websites visited per device IP).
Keep in mind that https:// websites only encrypt from the physical router out. So anything travelling in the air between your device and the router is theoretically accessable, unless you have some form of encryption between the device and the router (WEP or WPA, for example) -Z
__________________
2010 Cayman S - 12-2020 - 2014 MINI Cooper S Coupe - 05-17 - 05-21 1989 944S2 - 06-01 - 01-14 Carpe Viam. <>< |
||
![]() |
|
![]() |
I'm with Bill
Join Date: Jun 2005
Location: Scottsville Va
Posts: 24,186
|
Quote:
![]()
__________________
Electrical problems on a pick-up will do that to a guy- 1990C4S |
||
![]() |
|
Registered
|
If you're talking about your average IT admin - most couldn't figure out an SSID unless it was actually broadcasting the SSID name.
If you're talking about someone above average or exceptional then I wouldn't connect to any OPEN wifi - they are absolutely not secure on the local network and everyone within listening range can capture everything you do and see it in clear text. If they are using a password to secure things then you want to make sure it is a WPA connection at the very least. If they use TKIP encryption then it is crackable but if they use AES you're better off and pretty secure. WPA2 is better. If it is WEP with a password it might as well be open. From a wifi perspective the encryption is between the end station (your phone) and the router. The packets can still be captured but with the right encryption (AES) they are pretty safe. The keys are random and generated individually between the end station and the wifi access point or router. If you want to talk about black hat stuff where some guy in the coffee shop has turned his laptop into an access point and he is catching everything including the key generation then you're screwed. He/She has it all and you can't really tell. That's the reader's digest version. Let me know if you would like me to do more. If you have a windows computer and spend any time at a starbucks or what not using their wifi - download netstumbler and just run it to see what is going on from a wifi perspective around you. Heck, do it at your house to see how many of your neighbors are stupid. Then find the ones with open wifi networks - find their printers and print out some girls in bikinis for them.
__________________
-The Mikester I heart Boobies |
||
![]() |
|
canna change law physics
|
I have enough trouble remembering to print things to the local printer instead of the office, when I'm at home.
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Did you get the memo?
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,368
|
So does a device like the iPhone transmit the device name, phone number, your name, or device SN?
|
||
![]() |
|
Back in the saddle again
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,915
|
Quote:
|
||
![]() |
|
Registered
|
Quote:
Assuming the cert is not compromised...
__________________
-The Mikester I heart Boobies |
||
![]() |
|
![]() |
AutoBahned
|
it sounds like they could potentially grab enuff info to get into your machine and grab any info on it -- difficult? maybe easier if you go to the same coffeeshop all the time?
I have no idea whether they access you and then be able to see Uranus |
||
![]() |
|
Registered
Join Date: Mar 2008
Location: Chicagoland
Posts: 2,695
|
Quote:
WPA2 has been shown to be cracked in reasonable time. if yer at defcon, yea turn everything off. |
||
![]() |
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
|
Care to back that one up with facts?
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
![]() |
|
Moderator
|
Quote:
That said, when the first handshake occurs between the https site and the end device, the encryption key is passed to the device. If a sniffer is there to capture the key, then it doesn't matter how secure the website is... So - surfing Pelican on a public wifi - I will do. Banking or credit card transactions I won't. -Z
__________________
2010 Cayman S - 12-2020 - 2014 MINI Cooper S Coupe - 05-17 - 05-21 1989 944S2 - 06-01 - 01-14 Carpe Viam. <>< |
||
![]() |
|
least common denominator
Join Date: Aug 2001
Location: San Pedro,CA
Posts: 22,506
|
I'm looking at your phone now and you are a very naught naughty boy!
__________________
Gary Fisher 29er 2019 Kia Stinger 2.0t gone ![]() 1995 Miata Sold 1984 944 Sold ![]() I am not lost for I know where I am, however where I am is lost. - Winnie the poo. |
||
![]() |
|
Did you get the memo?
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,368
|
Quote:
![]() |
||
![]() |
|
Slackerous Maximus
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,163
|
At minimum, the local wi-fi hot spot would have your MAC address. It could be used to prove that you were in the area. So make sure you don't dump the bodies there, mkay?
__________________
2022 Royal Enfield Interceptor. 2012 Harley Davidson Road King 2014 Triumph Bonneville T100. 2014 Cayman S, PDK. Mercedes E350 family truckster. |
||
![]() |
|
Registered
|
It's not exactly WPA2 that's being cracked, but there's an exploit with WPS that can get you into WPA/WPA2 protected wifi systems.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs. '84 Targa - Arena Red - AX #104 '07 Toyota Camry Hybrid - Yes, I'm that guy... '01 Toyota Corolla - Urban Camouflage - SOLD |
||
![]() |
|