Re: encryption options for public networks?

Rob Flickenger <[email protected]>
Newsgroups gmane.network.wireless.seattle.devel
Message-ID <[email protected]>
On Jan 22, 2005, at 3:03 AM, Jim Thompson wrote:

> its going to be trivial to hack a RADIUS server to always allow 
> authentication, and hand back the keying material necessary to run 
> WPA.
>
> therefore, whatever is used at work/home (other than PSK) will 'work' 
> at a SWN node

Interesting hack.  But as a user, how do I know that the node is a 
"good guy" and not spoofed?  Can't I still MIM by bringing my own AP 
and handing out my own WPA keys?

> And, oh yeah, VPN solutions without full signed RSA are subject to MIM 
> attacks.

Right.  Signed by a key you have previously elevated to "trusted".  
Funny how we're back to key distribution again, isn't it?

I'd still prefer to just leave the thing open and leave the crypto to 
the apps (or the semi-educated users).

--Rob

_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.