Re: encryption options for public networks?
Rob Flickenger <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
On Jan 22, 2005, at 3:03 AM, Jim Thompson wrote: > its going to be trivial to hack a RADIUS server to always allow > authentication, and hand back the keying material necessary to run > WPA. > > therefore, whatever is used at work/home (other than PSK) will 'work' > at a SWN node Interesting hack. But as a user, how do I know that the node is a "good guy" and not spoofed? Can't I still MIM by bringing my own AP and handing out my own WPA keys? > And, oh yeah, VPN solutions without full signed RSA are subject to MIM > attacks. Right. Signed by a key you have previously elevated to "trusted". Funny how we're back to key distribution again, isn't it? I'd still prefer to just leave the thing open and leave the crypto to the apps (or the semi-educated users). --Rob _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev