Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Am I right in thinking that the user has to have attempted to connect to the network before the bug has triggered (I'm assuming so, since AFAIK iOS doesn't randomly download SSL certs from WiFi APs). If that is the case, calling it a 'no iOS zone' seems a bit much. The title makes it sound like some kind of iOS Specific "Cyber-EMP" ;)


Carriers pre-populate iOS 8 phones to automatically connect to their wifi signals. This hack involves spoofing official AT&T and Sprint wifi hot spots that the carrier has forced you to trust.

This earlier bug called WiFiGate has a list of pre-populated trusted wifi networks. From the same group https://www.skycure.com/blog/wifigate-how-mobile-carriers-ex...


I don't use any iOS devices anymore but I have many friends that do, is there a convenient way to disable these preconfigured wifi hotspots permanently?

Edit: according to the article you linked (under the consumers section), iOS has no interface for doing this. I find this pretty appalling.


Yes, it does. You just choose the SSID and tap 'forget this network'. You can also disable the 'automatically connect' functionality.

I 'forgot' the attwifi SSID long ago, and I have never had my phone try to auto-connect to one, even though they are everywhere.

The article ignores this because it weakens the headline.


Only possible when the wifi is in range.


So first you need to spoof the SSID ...


The Apple store wifi is also on the default trust list.


actually you can use a pineapple (https://www.wifipineapple.com/) or a similar device to force user to connect to your wifi.


The impression that I got from the article was that there was a separate, known iOS bug which would cause devices to connect to a wireless network without user intervention.


The article says it uses a second vuln that forces the device to connect to a specific network.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: