pwnagotchi
pwnagotchi copied to clipboard
Disable deauth and PMKID attacks by default
Description
The deauth and PMKID attacks can be disruptive and possibly illegal in some circumstances. It should not be enabled by default.
Motivation and Context
Devices have been observed in the wild causing disruption. The deauth behaviour is particularly disruptive and the memory of seen clients may be too small. If someone wants to run this, they should explicitly choose to do so.
This also needs some discussion in https://pwnagotchi.ai/configuration/
The example configuration file is extremely lacking in detail and the associate and deauth options should explicitly be mentioned with the potential implications for disrupting network operation.
It’s also not clear to users whether the AI takes over these settings. From the code it appears they are respected but there are questions regarding this on discourse.
Yeah my point was stupid