wtf. Were these protocols designed to be insecure? Reading that page, how can you mitigate against it?
Why do phones/laptops continually broadcast a list of all SSIDs they have ever connected?
https://blog.spacehuhn.com/probe-request
https://www.theatlantic.com/technology/archive/2016/08/wi-fi...
I'll see your conspiratorial bent and raise you: why is iPXE enabled by default?
It's not really "secure" in the academic sense of the word, but many devices record the BSSID along with the SSID to be a little more safe from hijacking.
It's trivial to spoof the BSSID if you're an attacker since it's something that's just advertised wirelessly.
maybe a form of planned obsolescence to sell routers with WPA3 support
intelligence agencies plugging agents into standards bodies is also not unheard of