iOS14 and iPadOS14 WiFi - Private Address setting circumvents parental controls and possibly QOS
I've noticed a new feature of iOS14 which is to enable a wifi private address. This gives the iphone and ipad a random and regularly renewing Mac address. This is done to make it harder to track devices when connected to wifi networks. Sounds good but it has it's implications.
Each time my son's ipad decides to use a new Mac address the Deco identifies this as a new device connecting to the network, and of course is no longer registered as one of his devices that has parental controls enabled (both website blocking and time limits).
I can see this is going to be a problem for many people and all router manufactures that use Mac address to restrict devices.
Thought everyone might want to have a think about this one.
P.S Additional thought : Presumably this will affect QOS as well where you have a prioritised device and the Mac address changes.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
TP Link team - This needs to be fixed urgently!
There needs to be a default profile for any new device that connects to the network. This is a security hole regardless of the "private address" feature of iOS 14.
Even my Windows 10 Home PC has this feature.
- Copy Link
- Report Inappropriate Content
I worked around this limitation by:
1. Turning off private addresses on all the iPads and iPhones for our home network and took a note of the actual device MAC of every device.
2. Switching the network to Whitelist mode in Advanced -> Security -> Access Control and then added all the devices in the house with their actual MAC address.
This way, only devices that have been added by me can be connected and I can now control them properly with the normal Parental Controls.
If the kids turn on private addresses again, they simply cannot connect to the network at all.
it also increased the security of the network in general because you can't just have random devices connect.
- Copy Link
- Report Inappropriate Content
@PatrickB123 I don't see any Security option under Advanced in the Deco app that I have downloaded from the App store. What app are you using?
- Copy Link
- Report Inappropriate Content
Sorry, i just saw that the thread was specific to the Deco system. I had the same problem on my Archer VR2100 WIFI DSL router and my solution is for that.
I'm not using an app or anything. I'm logging directly into the router.
When I log into my WiFi router, I get the menu below. That allows me to whitelist devices.
I had assumed that all TP-Link devices would have a similar operating system and menu structure.
- Copy Link
- Report Inappropriate Content
@PatrickB123 That's good to know, but won't help with some routers. Deco X20 has rudimentary web interface allowing only to check its status and update firmware, and there's no Whitelist setting in the Deco app.
TP-Link, please do something about the issue.
- Copy Link
- Report Inappropriate Content
Thanks for your patience.
We have recorded all the feedback here about the web UI and whitelist and they would be forwarded to the senior engineers for further evaluation.
Thank you very much for your understanding and support.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@Terminator extremely frustrating that TPLINK Has left this gap in it's parental controls feature,
- Copy Link
- Report Inappropriate Content
@TP-Link_Deco Very poor solution as it can be bypassed very easily by children using the toggle feature on their own iOS device which is not
- Copy Link
- Report Inappropriate Content
Information
Helpful: 8
Views: 9055
Replies: 26