Re: AT&T WiFi at McDonalds, etc



On Thu, 01 Nov 2007 19:03:23 -0700, Jeff Liebermann <jeffl@xxxxxxxxxx>
wrote in <gg0li35j89eic0ni9ofrsfcmkit7hghcec@xxxxxxx>:

John Navas <spamfilter1@xxxxxxxxxxxxxx> hath wroth:

The real effort is support, because lots of people don't know what to
do, or simply forget their credentials (or worse, post their credentials
on a PostIt Note for everyone to see).

Passwords suck.

Yep!

I've degenerated into becoming a archive for my
customers passwords, a rather dangerous and wasted exercise.

My own policy is to have absolutely nothing to do with client passwords
-- too much liability. When a client forgets a password, I have a new
temporary one generated and sent, with a flag that forces the client to
change it, plus logic to prevent weak passwords.

I'm
somewhat of a fan of X.509 authentication, with a USB dongle
containing the certificates, but even that's become a mess, with my
medical office customers, when someone forgets their dongle at home.

That problem, plus the problem of security breach if the dongle is lost
or stolen, has discouraged me from using that approach.

I
have some hope that the growing use of thumbprint identification will
eliminate password management problem.

Me too, but only some hope, since it's still not completely reliable --
still fails too often, and the low end units are still pretty easy to
spoof.

What's really needed is to train users in authentication, but that just
ain't gonna happen, so there's really no point to messing that way.

Nope. You missed my point. The problem I'm trying to solve is
prevent wireless sniffing of hot spot traffic. If the traffic were
encrypted with a unique one time WPA key delivered by a RADIUS server,
sniffing would be impossible. I have a 2nd experimental access point
running this way at a customers, and so far, it's working.

Likewise, except my own preference is for VPN, which is universal (not
just limited to specific hotspots); can be configured once; and set to
work automatically. In addition, I don't have to depend on the local
infrastructure working properly or on the integrity of the local
infrastructure provider. (If possible, I recommend the client having
its own VPN server, as I do.)

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>
.



Relevant Pages

  • Re: Reverse agent forwarding architecture
    ... At that point he might save all the customers' passwords and use them for personal gains without our authorization. ... With the default authentication options of SSH only public keys seem to enable keeping the secret out of the hands of employees. ... That's why we're looking for a solution that would only require adding a row to the authorized_keys file on each new server we need access to and a private key that should never leave our trusted server but only be used for calculating responses to the authentication requests. ...
    (SSH)
  • Re: Someones knocking on my door
    ... It only seems to be aimed at business customers. ... easy retrieval of any of, say, 1000 passwords while you are using ... Forcing me to use either windows, or not have a portable service, would result in a ... closed account. ...
    (uk.comp.os.linux)
  • Re: Someones knocking on my door
    ... That's not even the same web-site with which I am familiar; ... what arrives in the post. ... It only seems to be aimed at business customers. ... easy retrieval of any of, say, 1000 passwords while you are using ...
    (uk.comp.os.linux)
  • Re: can ping, but cant ftp
    ... > A SETPARMS.arpa.sys file has never been included in a FTP ... > implementation of security/3000 passwords (instead of MPE ... >> I have customers from all over the world logging to my ...
    (comp.sys.hp.mpe)
  • Re: SBS2003 - Terminal Server - RWW too many steps
    ... Smartcard readers are compact, dirt cheap, and circumvent 95% of the concerns with exposing RDP on the internet at-large. ... Is the revenue from this client so important to your business that its worth putting your business at risk? ... >>> 2 requires the same port redirect, does not require a listening port ... >> passwords are about as weak as you can expect....and there is little ...
    (microsoft.public.windows.server.sbs)