Is looking for Wi-Fi access points purely passive?
superuser.com
superuser.com
If at one time you connected to an open network, your devices continues to scan for that network. I can spoof that network, you connect to it, and then I intercept all traffic. A full framework has been created for this, complete with the ability to fingerprint your browser/OS and send exploits to your device [1]. Even if you only connect to password protected networks, it's possible (without access to the real AP) to let your clients send parts of the EAPOL handshake, and then perform a bruteforce attack. Weak passwords are cracked, meaning I can again intercept all traffic and possibly exploit your device.
So you only connect to one single network, strong password. Good. I can still track your MAC address. Even with one single device I can estimate the distance and the angle of your signal [2]. Hence I know your location, at all times. So you prevent MAC address tracking by using an identifier-free link layer protocol [3] (this doesn't exist in practice, only researchers made a demo showing its possible). Though a lot better, even with such a system it's possible to track the movement of devices purely based on the fingerprint of the physical WiFi signal [4]. Given sufficient location data it's likely to again (automatically) de-anonimize the dataset and track your movements (it's more complicated, yes, but still possible).
[1] http://www.sensepost.com/blog/7557.html
[2] Avoiding Multipath to Revive Inbuilding WiFi Localization
[3] Improving Wireless Privacy with an Identifier-Free Link Layer Protocol Ben
[4] SecureArray: improving wifi security with fine-grained physical-layer information
Or you could just randomize your MAC occasionally. If you're not even connected to a network (which is the situation we're discussing), just scanning, there's no reason for keeping a static MAC.
There are exploits allowing an AP to dynamically switch SSID, in order to impersonate the "known AP" you were scanning for. (Looking for a reference...)
EDIT: reference (student paper) -> https://www.os3.nl/_media/2012-2013/courses/ssn/open_wifi_ss...
Well, now it'll probably go looking for that network wherever you go, since the device will basically go and broadcast "Where is SSID XYZ ?". Making it easy for anyone to switch the SSID on their AP, turn off authentication , and your phone connects to it - and probably starts pulling updates from your services. Just hope that's done over SSL/HTTPS and that the app validates the certificates.
If the target device is already connected, you just need to DoS the router it's connected to and the device will reset the connection and start looking again. There are probably more elegant ways to force a reconnect than a simple DoS attack too.
Then the attacker would at least have to try different auth modes until the device connects.
If we assume all connections are over SSL/SSH with certificate checking, what can a malicious AP do to you? (Another comment points out your location can be tracked by your device's radio; anything else?)
You could then war drive to amass a location of suspected karma APs.
You'll be able to track devices if you have multiple APs deployed, or just detect whether someone is within a ~100-meter radius.
If you are shop owner, you could pretty accurately know where are your customers living.
http://lifehacker.com/how-retail-stores-track-you-using-your...
They use it to track your movements in the store. I forget the name of the most popular provider.
It's pseudo-anonymous in that they can get a unique identifier for your device (and thus know how often the device returns to the store) but can't tie it to your real identity without more information.
And given the mediocre accuracy of the technology it would be hard to correlate it with, for example, their point of sale system (e.g. 'device XYZ was near checkout 3 at the same time that John Smith's loyalty card was used there, therefore device XYZ is owned by John Smith').
I think there's s some theoretical possibility that you could "see" the absorption of the RF energy in the antenna of a purely passive device but I think that would be extremely hard unless you're in an RF shielded box.
I'd answer the question "it can be purely passive but it's not usually done that way", which the top SU answer also states.
Ah the joys of a friday afternoon waiting for the next meeting to start ...
Now instead they now beacon on all the channels in order to connect faster (which gives you the included privacy issues.)
https://uhdspace.uhasselt.be/dspace/report?type=author&id=24...
http://stackoverflow.com/questions/17935197/authenticating-c...
Does anyone know a simple way to log this information via Python?
But it did get me to thinking about why this isn't exploited more often or that more people don't know about it. I thought of the example of having a home break in, and having my router log all the MAC ids of the devices nearby. Couldn't I effectively pinpoint the subject if I had a novel MAC id being logged at the time of the crime? Even better, log the name of the network it's looking for (or better yet a Wifi Pineapple), and maybe I could even track the guy down myself.