But they are going onto your spoofed network your not going onto theirs, and if theyre on your network, they wont be able to even get a login page since the cameras are on their network, and if they think they are local, they will use a local ip not external ip, if they type that into your network they will get nothing. And if already logged into your spoofed AP, why would they retype their WPA security key for you to grab? Theyre already in. Every password and user sniffed has to be typed in, I cant see why they would type their WPA key again if they are already onto your spoofed network.