# WI-FI evesdropping

**URL:** <https://boards.straightdope.com/t/wi-fi-evesdropping/714251>\
**Category:** Factual Questions\
**Created:** [March 5, 2015, 5:34am UTC](https://boards.straightdope.com/t/wi-fi-evesdropping/714251 "2015-03-05T05:34:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkbites](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pkbites/32/204_2.png) [@pkbites](https://boards.straightdope.com/u/pkbites)\
**Post date:** [March 5, 2015, 5:34am UTC](https://boards.straightdope.com/t/wi-fi-evesdropping/714251/1 "2015-03-05T05:34:45Z")

</div>

if you have WI-FI in your house and you’re using it, can somebody else in the house use a different computer and see what you’re doing online?

If so, how? And is there a way to prevent it?

---

<div class="post-metadata">

**Author:** ![bob\_2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bob_2/32/3341_2.png) [@bob\_2](https://boards.straightdope.com/u/bob_2)\
**Post date:** [March 5, 2015, 12:19pm UTC](https://boards.straightdope.com/t/wi-fi-evesdropping/714251/2 "2015-03-05T12:19:17Z")

</div>

Yes - They can use an analyser like this - [professional wifi analyzer](https://www.acrylicwifi.com/en/wlan-software/acrylic-professional-wifi-analyzer/)

You might also like to read [this](http://www.pcworld.com/article/2043095/heres-what-an-eavesdropper-sees-when-you-use-an-unsecured-wi-fi-hotspot.html)

> [@](#):
>
> Keep in mind that private networks have similar vulnerabilities: Anyone nearby can eavesdrop on the network. Enabling WPA or WPA2 security will encrypt the Wi-Fi traffic, obscuring the actual communications, but anyone who also has that password will be able to snoop on the packets traveling over the network. This is particularly important for small businesses that don’t use the enterprise (802.1X) mode of WPA or WPA2 security that prevents user-to-user eavesdropping.

There is also a load of useful stuff [here](http://www.makeuseof.com/tag/dirty-rotten-thieves-stealing-wifi-find-3-apps/)

---

<div class="post-metadata">

**Author:** ![Francis\_Vaughan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/francis_vaughan/32/3093_2.png) [@Francis\_Vaughan](https://boards.straightdope.com/u/Francis_Vaughan)\
**Post date:** [March 5, 2015, 1:46pm UTC](https://boards.straightdope.com/t/wi-fi-evesdropping/714251/3 "2015-03-05T13:46:06Z")

</div>

The critical point is in the box **bob++** quotes above.

There is a simple hierarchy of possibilities with a WiFi setup.

[ol]  
[li] Open. No password. No encryption. Everything is trivially visible to anyone within range.[/li][li]WEP. Long since cracked, with a typical laptop able to crack the encryption in seconds. No more secure than an open WiFi for all useful purposes. WEP is little more than a speed-hump.[/li][li]WPA2 with PSK. This is the most typical set-up for home users. PSK means pre-shared key. They key needed to encrypt the session is given to each computer that accesses the WiFi. Since the key is the same, any computer can decrypt any other computer’s traffic.[/li][li]WPA2 Enterprise. This uses a separate server (a RADIUS server) that provides a protocol by which each computer must authenticate itself, and is then issued with a one time session encryption key. These keys are different each time, and provide a per-computer secure link over the WiFi.[/li][/ol]

Given most home setups are either 1, 2, or 3 - that answer is that indeed one computer can usually sniff the traffic of another.

---

<div class="post-metadata">

**Author:** ![Baffle](https://avatars.discourse-cdn.com/v4/letter/b/dec6dc/32.png) [@Baffle](https://boards.straightdope.com/u/Baffle)\
**Post date:** [March 5, 2015, 2:48pm UTC](https://boards.straightdope.com/t/wi-fi-evesdropping/714251/4 "2015-03-05T14:48:16Z")

</div>

Even without sharing your WPA2 key, your traffic can be decrypted. There exist tables of billions of pre-hashed common passwords and, given a decent amount of traffic to play with, your password can be found fairly quickly.

(You can protect yourself effectively by using an uncommon password like a random 1024 bit hexadecimal string, but most people don’t.)
