Re: encryption options for public networks?

Jim Thompson <[email protected]>
Newsgroups gmane.network.wireless.seattle.devel
Message-ID <[email protected]>
On Jan 22, 2005, at 10:07 AM, Rob Flickenger wrote:

> On Jan 22, 2005, at 3:03 AM, Jim Thompson wrote:
>
>> its going to be trivial to hack a RADIUS server to always allow 
>> authentication, and hand back the keying material necessary to run 
>> WPA.
>>
>> therefore, whatever is used at work/home (other than PSK) will 'work' 
>> at a SWN node
>
> Interesting hack.  But as a user, how do I know that the node is a 
> "good guy" and not spoofed?  Can't I still MIM by bringing my own AP 
> and handing out my own WPA keys?

Yes, but this is also possible without 802.1x/WPA.  It becomes 
non-possible (I'm fairly sure) with EAP-TLS, but this requires 
distributing certs, by hand, (or at least not at the location over 
wireless) if you really want to protect against spoofed APs.

I didn't know this was a design point for SWN's network.  I stand 
corrected. (?)

The above (a hacked RADIUS server combined with WPA, or at least 
802.1x) would serve to avoid all those Microsoft "This network is not 
secure, are you sure you want to connect?" warnings.

>> And, oh yeah, VPN solutions without full signed RSA are subject to 
>> MIM attacks.
>
> Right.  Signed by a key you have previously elevated to "trusted".  
> Funny how we're back to key distribution again, isn't it?

Its all the same song.

> I'd still prefer to just leave the thing open and leave the crypto to 
> the apps (or the semi-educated users).

To be sure, but what do the users want?


_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.