FragAttacks: new security vulnerabilities that affect wi-fi devices
fragattacks.com
fragattacks.com
> In three years or so, the Wi-Fi specification is scheduled to get an upgrade that will turn wireless devices into sensors capable of gathering data about the people and objects bathed in their signals... When 802.11bf will be finalized and introduced as an IEEE standard in September 2024, Wi-Fi will cease to be a communication-only standard and will legitimately become a full-fledged sensing paradigm... tracking can be done surreptitiously because Wi-Fi signals can penetrate walls, don't require light, and don't offer any visible indicator of their presence.
IEEE 802.11bf paper: https://arxiv.org/abs/2103.14918
Papers on device-free wireless sensing (DFWS): https://dhalperi.github.io/linux-80211n-csitool/
Remote sensing with low-cost ESP32 and 802.11n: https://academic.oup.com/jcde/article/7/5/644/5837600
Scary times.
But, yes DVD players come with license agreements, EULAs.
Please tell me you're joking.
Other places I'm not sure, but I'd guess you'll get one anyway.
Will they hold up in court? Who knows. But look and you're likely to find one they'll at least pretend applies to you.
(And to be clear, yes I agree that this is _ridiculous_)
e.g. the Samsung QB65R on Amazon
So yeah it's like $100-200 more expensive, but hardly seems.. unapproachable?
If you're feeling especially crafty, open the back of your TV and disconnect the wifi/bluetooth board. It's a discrete board in all of my TVs of different brands. I assume they build them this way so they can use the same network board design/production for years and just upgrade the main logic board in newer models.
Amazon has a solution to this. If your tv is within wifi range of an amazon device, your TV will be able to connect to a network. It might even be your neighbors device.
Even if it isn't/hasn't happened, there's nothing to stop someone like Samsung sticking cellular modems in their TVs to work around you doing this.
If we think about it like Air-Tags too, popular enough product, it'll just connect to one of your neighbour's TV's which _is_ online.
I remember years ago, Vodafone gave me a "free" femtocell because signal in my home was poor. They neglected to mention the fact it broadcast a public cellular signal which allowed other Vodafone customers to use _my_ internet bandwidth.
True. Although, if they put that SIM card on the bluetooth/wifi network board that I'm disconnecting then I'll be ok.
I would be surprised if they used cellular technology for this though (from a cost perspective). I'd expect a lorawan/helium like implementation.
Imagine gradually choking as you wait for a friend to open their front door - oops, you forgot their air doesn't know you're allowed to use Oxygen, hope they get here in time to explicitly authorise you to breathe...
Because of the Network Effect the grand total number of Networks you care about will always be... one. So, it doesn't make sense to have a dozen fiercely independent WiFi networks in the same physical volume all of which are, in fact, just offering access to the same network (the Internet) but with separate credentials needed for each.
There have been very slow steps on the obvious way forward here. If you've been a student somewhere civilized in the last couple of decades you might have seen EduRoam. Under EduROAM your credentials from say, the University of Florida, or Stanford work at MIT and NYU, but also in Oxford, and in Tokyo. No more need to maintain separate "guest" networks so that the visiting lecturer's laptop works. But most of us, most of the time, are using dozens of little pointless fiefdoms.
OTOH the technology can move from private radios to the model of cellular networks, where you don't care which tower you connect to, and the security / authorization lives at a different level.
Also putting all your big-tech eggs in one basket isn't a great direction for the Internet.
Even radiuz was probably better.
https://wifinetnews.com/archives/2004/06/radiuz_combines_wpa...
What does everyone think is going to happen with capabilities like that?
> We identify a number of critical issues that need to be addressed in this space... First, individuals should be provided the opportunity to opt out of SENS services – in other words, to avoid being monitored and tracked by the Wi-Fi devices around them.
Bad news, the paper proposes remote human identification by every Wi-Fi device.
> This would require the widespread introduction of reliable SENS algorithm for human or animal identification.
Would opt-in be legally easier than requiring human body scan registration for opt-out of Wi-Fi remote sensing?
Or, better yet, make it totally opt in.
And if $CAFE tracks you regardless of you not ticking the box or connecting to the network, how do I detect that as a regular customer?
In order to not be tracked you must consent to be tracked so we know you don't want to be tracked.
This should not be done or allowed. Period. It's a huge invasion of privacy.
Unfortunately these will be everywhere, far beyond any existing camera surveillance network.
2012 article on a military use case, https://www.popsci.com/technology/article/2012-07/seeing-thr...
2017 video on an industrial use case, https://www.digitaltrends.com/cool-tech/wi-fi-radiation-tran...
https://www.theatlantic.com/politics/archive/2015/10/the-nyp...
The cost of those devices should fall with 802.11bf Wi-Fi.
> the vans deliver a radiation dose 40 percent larger than delivered by a backscatter airport scanner; bystanders present when the van is in use are exposed to the radiation that the van emits… there may be significant health risks associated with the use of backscatter x-ray devices as these machines use ionizing radiation, a type of radiation long known to mutate DNA and cause cancer.
Could this radiation meter detect the presence of such a van?
https://www.gqelectronicsllc.com/comersus/store/comersus_vie...
e.g. lockpicks are regulated, how about wallpicks-via-WiFi?
you think?
http://lockwiki.com/index.php/Legal_Issues
https://unitedlocksmith.net/blog/the-locksport-travel-guide-...
> In Japan if you are found with lock picks you will be subject to a fine of 500,000 yen and a year in prison. In Poland, it is illegal to possess any picks without being able to show that your profession requires it ... In Hungary ownership of lock picks is completely illegal. The only people in Hungary that are allowed to have these tools are the military, and as a result lock picks are classified as military equipment. For travel within the United States or even traveling to the US, you should consult the lock pick laws in the state you are visiting.
I've been looking into this for a while, should be mature enough in a year or so. there are already dozens of companies in this space
Personally, I'd like it if my devices knew what room I was in. Back in 2013, I'd started working on a home automation project with that goal in mind, but then all these closed source devices came out that were incredibly cheap and convenient and I haven't revisited the idea since.
I do look back with a bit of regret that more hasn't been done to push for reverse engineering these devices or somehow encouraging companies to open source their routers to support third-party operating systems, etc. We take for granted that we've open source smartphones and standard PC specifications when we don't yet have a standard that could let me run YouTube TV on my Echo Show 8, for example, or add lossless FLAC playback to my smart speaker...
I have screens on my windows so I can have them open yet not have bugs wandering in and out - just pick wire mesh and ground it. Done!
From chicken wire to mesh with 1/8, or less, inch rectangles.
I imagine the whole room would have to be covered with lathe. In good construction the lathe is covering every sq. inch of a room before the the base coat is put on.
Plaster wall are not typical anymore. Stucco is still used on exterior walls, but it usually just covers up ap the foundation, and might extent up the wall a few feet.
Plaster walls in a bathroom are the best walls though. The house I'm in has 1" thick plaster walls, and they hold up to a lot of abuse.
A well plastered plaster room would need screen on the door too, but that's doable.
If I was building a house, it would have stucco walls. Maybe only the exterior walls, and the ceilings? Then my signals could go room to room, but the world is locked out.
No one uses chicken wire, but it works just as well as the new smaller holed lathe sheets.
I still have no clue if modern sheets of lathe would act as a Faraday Cage?
I have fooled around with Faraday Cages, and tiny openings matter.
(I remember hearing about a guy who stole a vechicle with lowjack. He covered the vechicle with chicken wire, and the cell signal with through? He was caught.)
I am not excusing the privacy implications, which will be abused to the extreme. However, it will be used also for health reasons, like monitoring respiration, and activity.
> her work on X-ray vision was chosen as one of the "50 ways that MIT has transformed computer science."
And the housing market.
https://groups.csail.mit.edu/netmit/sFFT/soda_paper.pdf
The sparse fourier transform : theory & practice - Haitham Al-Hassanieh (thesis, 2016 MIT) - Dina Katabi (thesis advisor)
Honestly I don't see any purely technical solution to this. At some point we have to demand that laws be written to outlaw this.
Reclaimyourface.eu
For home, chicken wire in the walls and wired networks. A Faraday cage is the simple solution, but unfortunately for this case is unlikely to be in most interior walls in modern buildings.
I find it equally ridiculous to try to outlaw software radio that might listen to "unapproved" radio bands, or listening to clear-text WiFi, baby monitors and cell phones.
It's almost as stupid as people who would want brain implant computers to implement DRM so people can't record and share their own memory of a movie.
Another analogy would be a country of blind people trying to legislate sighted people wearing blindfolds, because all of their privacy fences have huge holes in them.
Technology improves people's abilities. Adapt.
Standing in someone's garden, peering through their window is dealt with via legislation.
Since the invention of video recording devices, rather than having everyone upgrade their windows, legislation was reinterpreted and updated to govern the recording of people in private places vs public places.
It doesn't seem unreasonable for the same to be done to keep up with other forms of technology.
Rebuilding all houses in the world because someone creates a totally superfluous gadget. Seems reasonable.
Also I do not agree on "technology improves people's abilities" statement. It is always based on how the technology is used. Famous example. Harnessing nuclear energy. You can use it to blow up cities or to generate power around the world.
One shouldn't develop technology for advancement's sake. Every new technology should be given thorough thought and analysis into it on why is it needed? and are the negatives outweigh the positives? or vice versa? and so on.
It's just not possible to make a wall that can't be seen through, at least without making them tens of meters thick, even using high density concrete, tungsten, or uranium.
Muons aren't photons, but cosmic muon tomography has been used to image the Great Pyramid of Giza and also several mountains. Exposure times for cosmic muon tomography are very long, but with enough exposure time, correlating 5-minute blocks across days, someone could work out mean density throughout your house and make low-res 3D video of your daily routine, even with 1 meter thick walls of reactor-grade high-density concrete with sheet steel cladding.
The technical solution is pretty simple: do not use Wi-Fi. I use wired connections for all of the devices in my household. The only non-technical aspect of the solution was an interior design-based one about unobtrusive cable wiring around the house.
Both partially funded by EU's Horizon2020 program.
Openwifi talk at FOSDEM 2020 https://www.youtube.com/watch?v=8q5nHUWP43U
Funnily, there are much easier ways to do that, although they require direct line of vision [1]. Another option would be to measure the vibrations on walls (think glass on the wall, but hitech).
[1] https://www.schneier.com/blog/archives/2020/06/eavesdropping...
yes, yes it was https://www.youtube.com/watch?v=IRELLH86Edo
Instead of going to such extreme lengths though, it's more sensible to lobby for political change. There is absolutely no legitimate reason this should be introduced as a general standard for all wifi divices. This sort of spying needs to be illegal unless specifically approved in limited cases.
> "It’s important to note that there is presently no evidence of the vulnerabilities being used against Wi-Fi users maliciously and these issues are mitigated through routine device updates once updated firmware becomes available.
> "Like many previous vulnerabilities, FragAttacks has been academically well-researched and responsibly reported in a manner allowing the industry to proactively prepare and begin to roll out updates that fully eliminate the vulnerabilities. This set of vulnerabilities requires a potential attacker to be physically within range of the Wi-Fi network (or user device) in order to exploit it. This significantly reduces the likelihood of actual exploitation or attack."
[1] https://www.commscope.com/blog/2021/wi-fi-alliance-discloses...
> these issues are mitigated through routine device updates once updated firmware becomes available.
Unless you are one of the millions upon millions of people who have an Android device that launched >3 years ago.
Is it a concern? It depends on what you're doing. It is absolutely a concern if your corporation is handling ultra-sensitive information. However, you should also question your physical barriers in that case and whether you should use Wi-Fi at all for some aspects of your operation. Is it a concern for the vast majority of office workers or someone at home? Probably not; there would be easier ways to find a valid credit card number that don't involve the time and effort for a hacker to travel to your place where they could be discovered. There's no need to replace all your AP's with new hardware, although the Wi-Fi Alliance would love for you to do that.
Does this exploit warrant its own fancy name and domain name? As was the case for KRACK, I don't believe so. That should be reserved for vulnerabilities that have a severe impact AND are extremely trivial to exploit with no proximity requirements. If not, the fancy-name-vulns risk being deprived of their ability to get the attention that is required.
Edit: injection can be used to punch a hole in the router's NAT so someone can directly try to attack your devices. As always there world isn't burning down. But I think it's interesting research :)
Although the proximity requirement severely limits the possible impact, it does make us think again about the security of our Wi-Fi networks, and as a result we may identify areas to improve, which is a benefit.
I don't. This sentence serves no purpose other than distraction and needs to stop being used: "there is presently no evidence of the vulnerabilities being used".
It's a standard sentence that is rolled out for any security event or breach usually to misdirect blame. It needs to go away.
Picking two potentially high impact announcements from the last month or so:
1. There is a severe flaw in the RSA cryptosystem. 2. There is a remote code exec vulnerability in Microsoft Exchange.
One of these was a sketch of an incremental improvement to an attack that remains mostly of theoretical interest. The other was being actively exploited, was tragically simple for 3rd parties to replicate post-announcement and resulted in widespread pain.
There is some (non-linear) scale here (theoretical flaw/poc/weaponized poc/public poc/public weaponized poc/exploited, but limited actors or targets/widely exploited/HAVOC). MS for example uses just "less likely to be exploited", "more likely to be exploited" "being exploited". It's coarse and somewhat subjective but there is value even so.
"This flaw is being actively exploited in the wild" is the best line I can take upstairs. I don't want that to go away just because some parties might misuse it.
When an sales busybody like the WiFi alliance makes that statement, it comes from ignorance and CYA.
How so? Even I have done it (on my own AP). Unless you own a big property that the WiFi signal cannot reach outside it's as easy as pressing GO in one of the hundreds of script kiddie tools.
In your mind, what kind of WiFi exploit is actually concerning?
After reading your reply, it seems you have ruled out all home networks and any exploit on a company not dealing with ultra-sensitive data. What's left?
Something as simple as a Pringles can will dramatically increase "proximity". If you are in (or as perceived as) a juicy enough target area why wouldn't someone use something like this? Great way to monitor people, find out which houses are ripe to break in, etc.
Yes, it’s annoying if an attacker can manipulate your DNS responses. But it’s unavoidable on the internet and your local network should not be your only defense against it.
I have troubles imagining an attack on wifi protocol where this doesn't apply :).
- Hijack TCP sessions very easily with IP hijacking, especially telnet
- DoS someone with a smurf attack
- Ping of death windoze
- Inject content into unencrypted pages (goatse everyone's web page backgrounds)
- Get hacked by running inetd services
- chargen ... nuf said
- Apply a zillion patches to a Solaris box but break 10 other things
Norton Personal Firewall: `startkeylogger` would boot you off of IRC
These would typically be combined into `DCC SEND startkeylogger 0 0 0` to grief a whole channel of people
So everyone that lives or works in a city? That can't be many people can it?
Why does this feel like Spectre? We're trying to speed things up in a way that eventually blows back into our face.
> several of the newly discovered design flaws have been part of Wi-Fi since its release in 1997!
And spectre is also based on a decades old documented flaw.
It's just not very practical to predict every feasible attack until a lot of people have real systems to explore.
Theo de Raadt did the right thing for KRACK. Shame it would be his only chance to do so before getting kicked out of Mathy Vanhoef's secret club.
Probably referring to the internet drama related to silent patching and disclosure embargo. There are some details here, and others on various mailing lists, including an airing of differences if you want to look for that sort of thing after making a bowl of popcorn.
Generally in the security sphere we consider it the most ethical and responsible to give vendors plenty of time to patch vulnerabilities, especially critical ones, before publishing details or anything that could lead to a working 0-day exploit.
Theo de Raadt was one of the people notified of a previous WiFi exploit, and there was a set length of time intended for the vulnerability to be made private, in order for the (inordinately slow) vendors to create and push/prepare patches. If the patches were released early, it'd be easy to determine what the original vulnerability was.
So, Theo de Raadt decided, in the interest of keeping OpenBSD secure, to push the patch early, effectively letting the whole cat out of the bag. I'm not going to get into the drama of whether that was right, wrong, foolish, wise, whatever, but because of that, he no longer receives these ahead-of-time notifications of vulnerabilities.
Mathy originally reported the vulnerability to OpenBSD on July 15 under embargo, and estimated it would be lifted by the end of August (1.5 months after disclosure). Theo argued that 1.5 months was too long, but didn’t push the patch. Then on August 14, Mathy said the final public disclosure date would be October 16 (three months after initial disclosure), but agreed to allow OpenBSD to patch early. Although he didn’t like it, and has since said he would not give such permission again, he agrees that OpenBSD did commit with his permission.
Direct quote from Mathy: “From my point of view, I sent one mail on 14 August where I mentioned the new disclosure date of 16 Oct. In that same mail I also gave the OK to quietly commit a fix.” https://marc.info/?l=openbsd-tech&m=152909822107104&w=2
People portray OpenBSD as a project that ignores embargoes, and point to KRACK as an example. But Theo didn’t ignore the KRACK embargo. Rather, Theo successfully persuaded Mathy to allow OpenBSD to patch the vulnerability a full month and a half after all vendors had been informed.
I’m commenting on this because I think simply pushing back against the length of an embargo should not be characterized as breaking an embargo.
There were a lot of vendors in the KRACK embargo. The risk of the vulnerability leaking to the black market or malicious governments is real. As the length of the embargo increases, this risk increases dramatically. Big vendors are incentivized to pressure researchers to extend the embargo as long as possible. Open source projects are forced to hold off on committing bugfixes, leaving their users potentially vulnerable. If a project pushes back against a long embargo, or through persuasion manages to finagle permission to release an unobtrusive fix “early,” that project is characterized as an untrustworthy embargo breaker and left out of future embargoes. So open source projects are incentivized to sit down, shut up, ignore the threat to their users, and let the big vendors dawdle in their bugfixes.
I have just one more thought on the matter. I'm still early in my career, but in the years I've spent so far working with small business-types on security, and watching my colleagues, a month and a half is practically no time at all. I have little love for the big vendors, especially for behavior like this, but the reality I've seen is they often take months to do anything, and it takes further months for customers to actually patch their systems.
So I'm a little sympathetic to the desire to have an embargo of half a year or even longer, even with the downsides mentioned. Still, Theo clearly didn't actually breach his trust with Mathy, that's my mistake.
A month and a half is plenty of time, but it requires (1) the company decides that fixing security bugs is top priority. (2) They need a senior engineer or two on hand who are smart enough to understand the issues involved and implement a fix. And (3) They need a decent release process which allows security fixes to be promptly rolled out to users.
I’m not sure where most companies fail here. It’s certainly easy to downplay and deprioritize security fixes from the inside, when you have a big deadline coming up, or your customers are yelling at you or a refactor is blocking other people from doing their job. Security issues from the inside never feel like the “all hands on deck” emergency situations that security researchers believe them to be. (And I’m not sure if this is right or wrong, just, the experience I’ve always had from the ground when security issues potentially affected us.)
And I mean, that's a part of why you release these vulnerabilities publicly anyway, to pressure them into fixing their crap. I just worry a bit that if the window is too small, they'll just shrug their shoulders and put out a PR piece about how the vuln isn't actually that big a deal or something.
If anything the security community should be steadily decreasing the amount of embargo time. I wouldn't be opposed to different classes/criticality of vulnerabilities having different timelines. But for vulnerabilities where everyone's collective ass is proverbially hanging out there the times should be VERY short.
Can you provide more context for this point? As somebody with some experience in infosec, I don’t think that’s actually so clear cut. There are people who believe coordinating with vendors is the right course, and people who believe embargoes compromise users’ ability to make safe choices. There are also people who think the right course depends on the individual vuln/system.
In Vanhoef's case, though, he's bound by standards his university has for this stuff, not just his own personal preferences.
I would reword this to say
>Generally in the security sphere we consider it the most obedient
The earlier wording severely disadvantages the end-user of the opportunity to know that they are working with broken software and to find an alternative.
Personally, I agree most with tptacek in another comment, that this is on a continuum, and depends on the vulnerability, situation, and who's involved. If there's a good faith effort to develop + push a patch to a very wide install base of hardware which realistically is being ignored by the sysadmins (no change of being replaced, and impacting people using them in e.g. public places), I think it can be ok to embargo details.
I'm not a believer in coordinated disclosure and long embargoes (I think P0 does it just about right, though I'd make it 45 days instead of 90). But if I was offered information about a protocol vulnerability under a long embargo, accepted it, and then broke the embargo terms, I wouldn't whine about it next time when I wasn't included. Honestly: I wouldn't whine about it under any circumstances, even if I studiously complied with the embargo. Because we're not entitled to other people's work.
> I think simply pushing back against the length of an embargo should not be characterized as breaking an embargo.
I didn’t like the “secret club” comment either.
I assume Microsoft would inform the NSA about such things, Huawei would inform the Chinese intelligence agencies and Siemens would inform the German BND.
*Assuming they didn't already know about it which is why fast disclosure is so important.
Embargoes prevent that the average cyber criminal knows about the problems, but the resourceful organizations already get the information before the public knows about them. I think even 90 days are pretty long.
For example 253 vendors were informed about the problem in dnsmasq about 3 months before it was published: https://www.kb.cert.org/vuls/id/434904 (all vendors listed here were informed) In each organization probably multiple people know about this.
That we have had embargo processes for decades is utterly ridiculous. It's time for these vulnerabilities - especially for the ones that literally break everything - to be treated with the urgency they should be.
That said, about being sitting ducks.. dunno how much the situation really changes like that. For example, was this really unknown before this particular discovery? And what other vulnerabilities aren't currently being reported, whether under embargo or not?
Seems like users ought to have reasonable expectations about how secure popularly practiced technology is. If someone believed that a vulnerability like this wasn't a possibility, then they may need to update their expectations.
This actually made me angry. How fucking long are we doing this already? This is so. basic. Why is this possible? This should incur liability, we know the IT environment is adversarial.
I understand one can make technical mistakes, or shoot oneself in the foot in low level languages that are difficult to handle correctly. But this is a conceptual mistake, involving crypto! How can you possibly have written this code for an issue like this to occur? What is the control flow that leads to this? I almost cannot imagine how someone could code this up by accident, this must be a backdoor. Just imagine:
if decrypt(encrypted) == false
{
memcpy(plaintext, encrypted); // lets try to use the encrypted data anyway, you never know!
}
handle_packet(plaintext);Not having any access to the firmware source (thanks FCC) does not help at all.
Might shock you but the for-profit Wifi Alliance repeatedly ignores best practice advice and has the garbage they push out owned all the time. At this point I'm half convinced they are compromised, see no reason why they should be writing the standards anymore. People tell them what they are doing wrong constantly and they just ignore it and push ahead until someone breaks it exactly as predicted, rinse, repeat. This has been going on for years.
Half? Sadly, it's hard to imagine these things not involving some well known 3-letter US agencies.
Some vendors aren't going to care about this in the least and won't offer any updates.
Some will only fix this in new and future devices.
And perhaps some will update all their devices going back several years.
Currently I buy used 802.11ac Airport Extremes for wireless for people because they're simple, they stay out of the way, and the last time there was a major update, Apple updated every Airport model all the way back to the Airport Express from 2008.
But I want to be able to buy new wifi devices, and how vendors handle this will inform me about which ones I'll buy going forward.
Time to get a newer piece of gear. This is the problem with software - it doesn't age like a fine wine; it has to be maintained - and that usually means someone is going to have to be paid to do the not so fun work of maintaining and fixing old stuff that is no longer "OoOh tEh sHiNeY!"
That reminds me of a thread [0] that came up a month ago mentioning discussion of packets in packets [1]. That paper was from 2011!
[0]: https://news.ycombinator.com/item?id=26778236
[1]: https://static.usenix.org/events/woot11/tech/final_files/Goo...
How likely are large manufacturers likely to react to this?
Meanwhile, your router will probably give any attacker root if they ask it nicely. TP-Link doesn't seem to care about device security at all if you're already paid for the device, so don't expect any updates and expect a whole range of vulnerabilities to be exploitable against your router.
Now, it must be said, TP-Link is no D-Link, a company that almost seems to add security problems to their software intentionally with their awful software quality, but if you're conscious about security, any consumer device will probably have a whole bunch of exploits that would work easier and more reliably.
EDIT: replaced the word "access" with "proximity" to avoid confusion.
What? You just need a high enough gain antenna and you can carry it out much further away than it appears your wifi reaches. Isn't physical access, being able to touch the computer?
Meanwhile, many consumer routers can be hacked by adding something similar to <img src=192.168.1.1/admin/changesettings.cgi/> to a page or malicious ad. I don't think general consumers should be worried about someone aiming a high gain antenna at your router unless you work at a company dealing with sensitive information or places like embassies. The alternatives are much easier and much cheaper to execute.
Ruckus has updates out already: https://support.ruckuswireless.com/fragattacks-ruckus-techni...
So yes, but as you say lots of things can override your explicit DNS settings. Even browsers can do it these days.
Run WireGuard. Effectively treat WiFi as untrusted and VPN over it. Have WireGuard send over your DNS on the other side, and have that DNS use D-o-T or D-o-H depending on your threat model.
Use Ethernet on stationary devices, and WiFi on mobile devices.
Do we even know at this point?