Re: encryption options for public networks?
Jim Thompson <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
On Jan 22, 2005, at 10:07 AM, Rob Flickenger wrote: > On Jan 22, 2005, at 3:03 AM, Jim Thompson wrote: > >> its going to be trivial to hack a RADIUS server to always allow >> authentication, and hand back the keying material necessary to run >> WPA. >> >> therefore, whatever is used at work/home (other than PSK) will 'work' >> at a SWN node > > Interesting hack. But as a user, how do I know that the node is a > "good guy" and not spoofed? Can't I still MIM by bringing my own AP > and handing out my own WPA keys? Yes, but this is also possible without 802.1x/WPA. It becomes non-possible (I'm fairly sure) with EAP-TLS, but this requires distributing certs, by hand, (or at least not at the location over wireless) if you really want to protect against spoofed APs. I didn't know this was a design point for SWN's network. I stand corrected. (?) The above (a hacked RADIUS server combined with WPA, or at least 802.1x) would serve to avoid all those Microsoft "This network is not secure, are you sure you want to connect?" warnings. >> And, oh yeah, VPN solutions without full signed RSA are subject to >> MIM attacks. > > Right. Signed by a key you have previously elevated to "trusted". > Funny how we're back to key distribution again, isn't it? Its all the same song. > I'd still prefer to just leave the thing open and leave the crypto to > the apps (or the semi-educated users). To be sure, but what do the users want? _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev