Re: encryption options for public networks?

Rob Flickenger <[email protected]>
Newsgroups gmane.network.wireless.seattle.devel
Message-ID <[email protected]>
On Jan 22, 2005, at 7:54 PM, Jim Thompson wrote:

> Yes, but this is also possible without 802.1x/WPA.  It becomes 
> non-possible (I'm fairly sure) with EAP-TLS, but this requires 
> distributing certs, by hand, (or at least not at the location over 
> wireless) if you really want to protect against spoofed APs.

You could do that.  Distribute your cert over the Internet using an SSL 
server signed by a trusted CA (say, https://socalfreenet/cert) and tell 
your users (portal?) to install it when they're ready to use 
encryption.  We're back to needing somewhat knowledgeable users again, 
but at least you could provide per-client link layer crypto without 
risking a man in the middle, and they could install it securely over an 
open access point.  The portal could even give them instructions on how 
to do it, all without having to click "Yes" on any dangerous dialog 
boxes.

> I didn't know this was a design point for SWN's network.  I stand 
> corrected. (?)

I don't believe protecting against spoofed APs should be the design 
goal of any open network, at least not until the protocols mature.  My 
point is that providing a free encryption service that *could* be 
spoofed is much, much less desirable than providing an open AP and 
leaving the crypto to the users.  From a cracker's point of view, 
there's much less to be gained by spoofing an open network than there 
is spoofing WPA and seeing all of the traffic that users believe is 
private.

In Michael Mee's case, I still think the best bet is to leave it open.  
Creating an expectation of privacy will only lead to heartache unless 
you can do it right.

> The above (a hacked RADIUS server combined with WPA, or at least 
> 802.1x) would serve to avoid all those Microsoft "This network is not 
> secure, are you sure you want to connect?" warnings.

Indeed.  Michael, if you think the users care, that might be important. 
  From the users I've met, they don't give a damn about warnings.  Most 
of them run IE and don't even realize when their box starts spewing 
viruses and DoS'ing the intarweb.

--Rob

_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.