Re: encryption options for public networks?

Jim Thompson <[email protected]>
Newsgroups gmane.network.wireless.seattle.devel
Message-ID <[email protected]>
its going to be trivial to hack a RADIUS server to always allow 
authentication, and hand back the keying material necessary to run WPA.

therefore, whatever is used at work/home (other than PSK) will 'work' 
at a SWN node

And, oh yeah, VPN solutions without full signed RSA are subject to MIM 
attacks.

On Jan 21, 2005, at 10:34 AM, Matt Westervelt wrote:

> Assuming that everyone can use 802.1x, how would you set up the 
> credentials for public users?
>
> -matt
>
>
> Jim Thompson wrote:
>
>> Nearly everyone should be able to use 802.1x now.
>>
>> On Jan 20, 2005, at 12:40 PM, Michael Mee wrote:
>>
>>> Thanks HK and Casey for the specific info and new options for me to 
>>> explore and to others for suggestions about ssh and similar end to 
>>> end solutions.
>>>
>>> We can all (possibly?) agree on end-to-end encryption being the 
>>> optimal solution and our group already recommends this in solution 
>>> scenarios that the average end user can adopt such as email (see 
>>> www.socalfreenet.org/safesurfing ). But let's face it, anyone who 
>>> can drive ssh and/or setup both ends of a tunnel are already singing 
>>> in the choir!
>>>
>>> Its cliched and stereotyped, but think about how you'd set this up 
>>> for your mother, just using email or a website to communicate with 
>>> her. Also thnk about the risks we're trying to mitigate. Sure, 
>>> employees at the the DSL company can sniff traffic as it goes by, 
>>> but I'm more worried about the gal (Eve) in the corner of the coffee 
>>> shop running <insert fav sniffer her> watching passwords go by.
>>>
>>> The *pragmatic* solution makes it hard enough for Eve to crack that 
>>> she goes somewhere easier to sniff traffic, but easy enough for your 
>>> mother to read the web page, configure her computer and use the 
>>> solution routinely.  Various VPN-like solutions are the most obvious 
>>> as that's their raison d'etre, but as always the devil is the 
>>> details like client support, overhead (both traffic and CPU), 
>>> implementation (central box vs distributed connected via VPN links, 
>>> etc. etc.
>>>
>>> Thanks again for all your input!  Per usual, I'll be sure to write 
>>> up and distribute whatever we end up doing or not doing.
>>>
>>> cheers, michael
>>> _______________________________________________
>>> Dev mailing list
>>> [email protected]
>>> http://seattlewireless.net/mailman/listinfo/dev
>>
>>
>> _______________________________________________
>> Dev mailing list
>> [email protected]
>> http://seattlewireless.net/mailman/listinfo/dev
>
>
> _______________________________________________
> Dev mailing list
> [email protected]
> http://seattlewireless.net/mailman/listinfo/dev

_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.