This deep dive expands on the Loop Asia conversation with Joseph Yap, founder of Otonata.
Most people think about network security as a straight line: device, router, internet. Joseph Yap, who audits home networks through his firm Otonata, thinks that model is out of date — the blind spot he's gathering evidence for is physical proximity.
Researchers trace an attack by following the network path — IP address to IP address, hop to hop. That's how Cloudflare tracks Singapore as the world's second-largest source of DDoS traffic. Joseph's hypothesis is that a second path runs underneath the first: not network to network, but Wi-Fi point to Wi-Fi point, in physical space. In a dense city, your device sits in range of dozens, sometimes hundreds, of other people's networks — and yours sits in range of theirs.
That attack has a name now: the nearest-neighbor attack, coined by a researcher late last year. The logic is straightforward — go after a target directly and you get noticed, attack it constantly from an obvious source and you get blocked. So instead you compromise something nearby, the house next door or the office downstairs, and use its Wi-Fi as a foothold. As Joseph put it: "Who turns off their Wi-Fi?" A router is one of the only things in a home that's genuinely on 24/7 without anyone thinking twice about it.
This is what makes proximity a more durable weakness than any single vulnerable device. You can patch a router. You can't patch geography. Live in a dense apartment block, work in a shared office building, or park in a public garage, and you're within range of devices you don't control and can't see — some belonging to people who have never thought about their own security.
Joseph has quantified this himself: scanning for a client, he routinely finds upwards of 800 different Wi-Fi devices within range at a single location over 24 hours. Most belong to ordinary neighbors. But run the math the way Joseph does — Cloudflare's roughly 2,500 attacking IP addresses out of Singapore work out to about 0.2% of the population, call it two in a thousand Wi-Fi points already compromised — and 800 devices in range isn't hypothetical. Statistically, some of them are already somebody else's foothold.
The clearest illustration Joseph raised wasn't even about home Wi-Fi — it was cars. Singaporean researchers presented findings at Black Hat showing that roughly one in five dashcams they tested were easily accessible over nearby wireless connections. In the time it takes to order at a drive-through and pull forward to collect it, an attacker in range could pull the dashcam's stored audio and video and run it through AI transcription — producing a readable summary of what was said in the car and where it had been driven. No network breach, no password guessing — just proximity and a short window.
The practical takeaway isn't paranoia about parking near strangers — it's a shift in how you think about exposure. Corporate security spent two decades building a model around network perimeters: firewalls, VPNs, segmented subnets. Home security inherited a scaled-down version of the same model — lock the router, use a decent password, done. But a home network sits inside a physical building, surrounded by other buildings full of insecure devices, broadcasting and listening within reach of each other. Joseph's scanning work is an attempt to make that second, invisible layer of exposure visible — because right now, almost nobody is looking at it.
Thinking about exposure only in network terms, not physical proximity?
Otonata's own work is a reminder that the boundary of your risk isn't always where you think it is — the same principle applies well beyond home networks.