Question re session hijacking in dual stack environments w/MacOS

Connor Wilkins connorwilkins at ruggedinbox.com
Sun Sep 27 15:25:25 UTC 2015


On 2015-09-27 03:34, Dovid Bender wrote:
> But when you're seeing the same session being used from two wildly
> different places (in this case, IPv4 and IPv6) at the SAME TIME, that
> does seem rather suspicious in the absence of other information.

iOS 9 has a new feature called "Wi-Fi Assist" that will "automatically 
use cellular data when Wi-Fi connectivity is poor".

This will most likely cause those pesky IP checks to fail (even if you 
use a /24 or AS check). Geolocation checks will also fail in some cases.

My geolocation when connected to WiFi and when using cellular data are 
widely different. WiFi reports the city I'm in while cellular reports 
the city that their HQ is in.

-- 
“Simply stated, we have a new formula for Coke.” --- Roberto C. 
Goizueta, Company Chairman, Coca-Cola



More information about the NANOG mailing list