top | item 33817989

(no title)

johnny_b_g | 3 years ago

While the OP is referring to a "work" machine, I feel their setup is besides the point - it's the fact that it's auto-joining a synced-in Wifi that's the issue...

Essentially, what happened to me is that on my iOS device I was setting up an IoT device (which, similar to the OP, I keep IoT stuff on a different network segment from the rest on my home network by having their own 'IoT devices only Wifi'), which you can only do so via an app, by joining an 'ad-hoc' network created by the IoT device. And that's where all that began; the sequence of events:

1. joined the IoT's Wifi network from my iOS device to set it up; doing this records that Wifi connection in iOS, and the default is that 'auto-join' is enabled for newly joined networks

2. this new Wifi network is synced to my Mac(s) (all personal machines) since I have iCloud Keychain sync enabled

3. Later on, my Mac lost its primary network connection (from router reboot, or other event, etc.); Mac goes "Hmm, network down. Oooh! There's this other new Wifi that's available, lemme join that one automatically!"

4. Me later, after noticing my internet doesn't seem to work on my mac, even though it shows having a network connection: "WTF is this connected to that network?!? I don't want anything else connecting to that!!"

So essentially my mac(s) joined a new network not meant for them, automatically, without my explicit action. That potentially opens it up to security issues of the IoT device because of this auto-join it does behind one's back.

discuss

order

No comments yet.