虎嗅

If Tianjin Station had Wi-Fi, Yu Zecheng would probably have been exposed long ago.

原文:如果天津站有Wi-Fi,余则成恐怕早就暴露了

Summary of Key Points

This news article focuses on Wi-Fi security and addresses two main issues: first, new laboratory technologies can identify a person's gait through Wi-Fi signals (even when you don't have any electronic devices with you); second, the existing "evil twin" attack in public Wi-Fi networks (where fake hotspots steal account information). The article provides practical advice for ordinary people to protect themselves. The overall message is that while Wi-Fi is a useful tool for accessing the internet, it can also be a channel for privacy breaches. However, there's no need to panic excessively—new technologies have not yet become widespread, and existing risks can still be mitigated.

1. Can Wi-Fi even “see” you walking?

You might think that turning off your phone and disconnecting from Wi-Fi means the router can’t detect you, but researchers in Germany have found that Wi-Fi signals can be used to identify a person based on their walking posture. The principle is simple: Wi-Fi signals are electromagnetic waves that reflect and scatter when they encounter objects like people. Each person’s walking style (arm swing amplitude, step length, and body center of gravity changes) results in unique signal distortions. Researchers used the BFI signal (Beamforming Feedback Information) from Wi-Fi 5 to capture these distortions. Although BFI is designed to make Wi-Fi signals more precise (like a focused microphone), its transmission is not encrypted, making it easy to collect data.

Even more strikingly, they were able to detect signals from the next room; although the accuracy decreased slightly, it was still possible. It’s like walking in a room with a hidden Wi-Fi “listener” that can still identify you.

2. How far is this gait recognition technology from being practical?

Although it sounds alarming, this technology is not yet ready for widespread use due to two major barriers:

  • Data collection: To identify a person, the router needs to collect data on their Wi-Fi signal patterns while they are walking, which requires specialized efforts and is not easily obtainable.
  • Scalability issues: The experiment only involved 197 people. In larger settings like offices or subway stations with many users, signal interference would significantly reduce recognition accuracy.

Therefore, for now, ordinary people don’t need to worry about being tracked while using Wi-Fi.

3. The “evil twin” in public Wi-Fi: Fake hotspots are a real threat

The older risk of public Wi-Fi is more concerning than the new laboratory technologies. For example, “evil twin” attacks have been in use for several years, where attackers set up fake hotspots with names similar to legitimate ones (e.g., changing “Starbucks” to “Starbucls”) and adjust their signal strength to make them appear more reliable. Your phone will automatically connect to the stronger signal, leading you to the fake hotspot. From there, attackers can steal your email and password information.

The Australian suspect in the news article used this method to set up traps on planes and in airports for six years, stealing over 700 photos and videos from 17 women. A seemingly “free” Wi-Fi hotspot turned out to be a tool for surveillance.

4. How can ordinary people protect themselves?

To reduce the risks associated with public Wi-Fi, follow these simple tips:

  • Verify before connecting: In airports, hotels, and cafes, don’t just connect to any “Free XXX” hotspots. Ask staff for the official name of the Wi-Fi network (e.g., Starbucks Wi-Fi, not “Free Starbucks”).
  • Be cautious of Wi-Fi networks that require personal information: If you need to enter your phone number, email, or password to connect, it’s likely a fake. Legitimate public Wi-Fi networks either don’t require login or use verification codes (but make sure they are from the official source).
  • Turn off “automatic network connection”: Prevent your phone from automatically connecting to similar Wi-Fi hotspots. Manually select the network each time you use it for extra security.
  • Avoid sensitive activities on public Wi-Fi: For tasks like transferring money or logging into bank accounts, use your mobile data instead of public Wi-Fi.

In summary, the key to Wi-Fi security is to avoid cheap options (like free Wi-Fi) and stay vigilant. New technologies may be exciting, but they’re still far from being widely available. The more common risks are also the most likely to cause problems. By following these tips, you can significantly reduce the chances of falling victim to Wi-Fi-related threats.