November 12, 2004


Watching Them, Watching Us

It is astonishing that anybody would design a piece of critical infrastructure such as this kind of sensot network which relies on 2.4 GHz WiFi radio protocols.

This is fundamentally vulnerable to accidental or deliberate Denial of Service attacks - which is all that anyone wanting to smuggle illegal nuclear or radiological weapons wants i.e. for the detectors not to work, or for them to be "offline" so frequently that they are treated as forever "crying wolf" with false alarms.

It does not matter how strong the encryption or how effective the Cyclic Redundancy Checks which initiate data re-transmission are, the 2.4 Ghz Industrial Scientific Medical portion of the radio spectrum is licence free in most countries and there are no legal penalties for accidental or deliberate interference or jamming, from the millions of other radio devices using this part of the spectrum.

There is fundamentally no way to prevent several different protocol based Denial of Service attacks becuase the control frames which determine session handshakes etc. are not authenticated or encrypted and can be easily spoofed or forged.

This problem has not been sorted out even in the newer 802.11i version of the protocols which introduce better encryption etc.

It is bad enough when various sensor manufacturers plan to use this technology for simple industrial monitoring, which may have environmental or health and safety consequences if it goes wrong, but to use rely on Wi-Fi radio protocols for a critical security related task, is utter madness.

