2009.07.01

Why Pre-Shared Keys Suck 2009-07-01T20:45:50ZTitled entry permalink

1. Guest comes to Owner's place and asks for wifi key.

2. Owner tells Guest that the password is "flibble".

3. Guest logs on.

4. Guest leaves and tells the world that Owner's wifi key is "flibble".

5. Owner must now change his wifi key from "flibble" to something else and then inform everybody else who uses the wifi (both humans and devices which store the pre-shared key) what the new key is.

6. Goto (1)

The alternative to pre-shared key systems is to have a user account system.

1. Guest comes to Owner's place and asks for wifi key.

2. Owner logs onto administration panel, taps in username and generates a password, then gives that to Guest.

3. Guest uses.

4. If Guest tells the world his wifi username and password combo, you revoke the password.

There is no reason why this setup should not be used in consumer wifi routers, except for the fact that the existing standards for wifi authentication are designed for mouth-breathing idiots who share their fucking MySpace passwords with each other and then wonder why their account gets "hacked".

And before anyone says FreeRADIUS, that's too complex. Yes, I can set up FreeRADIUS on my Linux box. But username/password authentication with integration at the OS level with Windows and UNIX (including OS X and Linux) should ship on consumer-level wifi routers. That wouldn't suck. Pre-shared keys do suck and are actually worse than useless.

Another thing I don't understand about wifi: why is it that the only way to get encryption of your packets across the air is to turn on authentication? Sometimes I want unauthenticated wifi but that doesn't mean I don't want my packets encrypted. Think of it like a club: just because there's no guest list doesn't mean that you don't need security. In fact, you probably need more security.

Links from del.icio.us

 

Login with your OpenID:
No. 969
Tom Morris
Currently in: East Sussex, England
Usually in: East Sussex, United Kingdom
AIM: tommorris
YIM: tom.morris

I am a , an , like to code in and noodle about with and the . I also have a BA in philosophy from London, and am studying for an MA. My philosophical interests are in Victorian-era German philosophy, Kierkegaard, Robert Nozick, hermeneutics and current approaches to the demarcation problem in the philosophy of science. Musically, I like jazz fusion, soul and P-Funk. My musical nirvana would be a mixture of Beethoven, Miles Davis and George Clinton topped with a side-serving of Erykah, Jill and Angie.

I also write for the Citizendium, an online encyclopedia project. If you know about stuff, you should join in.

Elsewhere:

  • GPG Key
  • del.icio.us
  • Flickr
  • Twitter
  • digg
  • Jaiku
  • LinkedIn
  • ma.gnolia
  • blip.tv
  • upcoming.org
  • MetaFilter
  • LiveJournal
  • CiteULike
  • Technorati Profile

RSS Feed Subscribe:

RDF

« July 2009 »
SuMoTuWeThFrSa
 1234
567891011
12131415161718
19202122232425
262728293031 

View in month context

On this day in: 2006 2007 2008