Re: encryption options for public networks?
Jim Thompson <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
its going to be trivial to hack a RADIUS server to always allow authentication, and hand back the keying material necessary to run WPA. therefore, whatever is used at work/home (other than PSK) will 'work' at a SWN node And, oh yeah, VPN solutions without full signed RSA are subject to MIM attacks. On Jan 21, 2005, at 10:34 AM, Matt Westervelt wrote: > Assuming that everyone can use 802.1x, how would you set up the > credentials for public users? > > -matt > > > Jim Thompson wrote: > >> Nearly everyone should be able to use 802.1x now. >> >> On Jan 20, 2005, at 12:40 PM, Michael Mee wrote: >> >>> Thanks HK and Casey for the specific info and new options for me to >>> explore and to others for suggestions about ssh and similar end to >>> end solutions. >>> >>> We can all (possibly?) agree on end-to-end encryption being the >>> optimal solution and our group already recommends this in solution >>> scenarios that the average end user can adopt such as email (see >>> www.socalfreenet.org/safesurfing ). But let's face it, anyone who >>> can drive ssh and/or setup both ends of a tunnel are already singing >>> in the choir! >>> >>> Its cliched and stereotyped, but think about how you'd set this up >>> for your mother, just using email or a website to communicate with >>> her. Also thnk about the risks we're trying to mitigate. Sure, >>> employees at the the DSL company can sniff traffic as it goes by, >>> but I'm more worried about the gal (Eve) in the corner of the coffee >>> shop running <insert fav sniffer her> watching passwords go by. >>> >>> The *pragmatic* solution makes it hard enough for Eve to crack that >>> she goes somewhere easier to sniff traffic, but easy enough for your >>> mother to read the web page, configure her computer and use the >>> solution routinely. Various VPN-like solutions are the most obvious >>> as that's their raison d'etre, but as always the devil is the >>> details like client support, overhead (both traffic and CPU), >>> implementation (central box vs distributed connected via VPN links, >>> etc. etc. >>> >>> Thanks again for all your input! Per usual, I'll be sure to write >>> up and distribute whatever we end up doing or not doing. >>> >>> cheers, michael >>> _______________________________________________ >>> Dev mailing list >>> [email protected] >>> http://seattlewireless.net/mailman/listinfo/dev >> >> >> _______________________________________________ >> Dev mailing list >> [email protected] >> http://seattlewireless.net/mailman/listinfo/dev > > > _______________________________________________ > Dev mailing list > [email protected] > http://seattlewireless.net/mailman/listinfo/dev _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev