Re: encryption options for public networks?
Rob Flickenger <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
On Jan 22, 2005, at 7:54 PM, Jim Thompson wrote: > Yes, but this is also possible without 802.1x/WPA. It becomes > non-possible (I'm fairly sure) with EAP-TLS, but this requires > distributing certs, by hand, (or at least not at the location over > wireless) if you really want to protect against spoofed APs. You could do that. Distribute your cert over the Internet using an SSL server signed by a trusted CA (say, https://socalfreenet/cert) and tell your users (portal?) to install it when they're ready to use encryption. We're back to needing somewhat knowledgeable users again, but at least you could provide per-client link layer crypto without risking a man in the middle, and they could install it securely over an open access point. The portal could even give them instructions on how to do it, all without having to click "Yes" on any dangerous dialog boxes. > I didn't know this was a design point for SWN's network. I stand > corrected. (?) I don't believe protecting against spoofed APs should be the design goal of any open network, at least not until the protocols mature. My point is that providing a free encryption service that *could* be spoofed is much, much less desirable than providing an open AP and leaving the crypto to the users. From a cracker's point of view, there's much less to be gained by spoofing an open network than there is spoofing WPA and seeing all of the traffic that users believe is private. In Michael Mee's case, I still think the best bet is to leave it open. Creating an expectation of privacy will only lead to heartache unless you can do it right. > The above (a hacked RADIUS server combined with WPA, or at least > 802.1x) would serve to avoid all those Microsoft "This network is not > secure, are you sure you want to connect?" warnings. Indeed. Michael, if you think the users care, that might be important. From the users I've met, they don't give a damn about warnings. Most of them run IE and don't even realize when their box starts spewing viruses and DoS'ing the intarweb. --Rob _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev