Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Blocking the MAC in this case wasn't to stop some elite hacker from pwning you from the bushes outside your window it was to stop the system's default phone home type garbage from working.

That said if "attacking your adapter's/router's firmware flaws for an encryption/authentication vulnerability so they can hack in enough device control to fake being a valid client and further hack you from that launch point" is a real enough concern for you to be worried about then my first recommendation would be to stop using Wi-Fi in the first place, the entire design of the discovery and advertisement portion of the protocol is the anti-thesis to what you need.

However if you really think you can outdo everybody else by ground up building your own Wi-Fi system then a secure tunnel like wireguard or IPsec or so on will at least provide you a second layer that'd need to be attacked. That said such a layer is probably good for you in this case regardless and I'm not sure why you'd replace WPA* instead of use it as yet another layer of protection.



> I'm not sure why you'd replace WPA* instead of use it as yet another layer of protection.

Have you spent any time reading the source code of wpa_supplicant?

I still have nightmares from that.


I'd recommend iwd over wpa_supplicant but yes, it's not pretty. That said this still doesn't really answer the question of why avoid it as a layer, even a shitty layer is better than just not having one at all.


Wait till you see how bad embedded code is. I bet most modems on the market are hackable even when nominally offline. We saw this with the ESP32.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: