Tom Morris



2009.07.01

Why Pre-Shared Keys Suck 2009-07-01T20:45:50ZPermalink

1. Guest comes to Owner's place and asks for wifi key.

2. Owner tells Guest that the password is "flibble".

3. Guest logs on.

4. Guest leaves and tells the world that Owner's wifi key is "flibble".

5. Owner must now change his wifi key from "flibble" to something else and then inform everybody else who uses the wifi (both humans and devices which store the pre-shared key) what the new key is.

6. Goto (1)

The alternative to pre-shared key systems is to have a user account system.

1. Guest comes to Owner's place and asks for wifi key.

2. Owner logs onto administration panel, taps in username and generates a password, then gives that to Guest.

3. Guest uses.

4. If Guest tells the world his wifi username and password combo, you revoke the password.

There is no reason why this setup should not be used in consumer wifi routers, except for the fact that the existing standards for wifi authentication are designed for mouth-breathing idiots who share their fucking MySpace passwords with each other and then wonder why their account gets "hacked".

And before anyone says FreeRADIUS, that's too complex. Yes, I can set up FreeRADIUS on my Linux box. But username/password authentication with integration at the OS level with Windows and UNIX (including OS X and Linux) should ship on consumer-level wifi routers. That wouldn't suck. Pre-shared keys do suck and are actually worse than useless.

Another thing I don't understand about wifi: why is it that the only way to get encryption of your packets across the air is to turn on authentication? Sometimes I want unauthenticated wifi but that doesn't mean I don't want my packets encrypted. Think of it like a club: just because there's no guest list doesn't mean that you don't need security. In fact, you probably need more security.

Links from del.icio.us

 — 

No. 969
Tom Morris 9f4907d871750fd4c9b9bad7086701b51d6abd10 bd9f81a05283ed85e699175ed057b4a497f20b77 802c68123e12bf69d99a25a87cef360f18813fe4
Currently in: East Sussex, England
Usually in: East Sussex, United Kingdom
AIM: tommorris
YIM: tom.morris

I am a , an , like to code in and (and Java, but let's not talk about that), and noodle about with and the .

I have an MA in philosophy from Heythrop College, University of London. My philosophical interests are in analytic metaphysics, ontology, modality, the work of , , , and . I have a strange, unfulfilled interest in . I've been influenced by Gadamer, by , , and .

Musically, I like jazz fusion, soul and P-Funk. My musical nirvana would be a mixture of Beethoven, Miles Davis and George Clinton topped with a side-serving of Erykah, Jill and Angie.

I also write for the Citizendium, an online encyclopedia project. If you know about stuff, you should join in. I occasionally produce audio recordings for The Pod Delusion.

Elsewhere:

  • GPG Key
  • del.icio.us
  • Flickr
  • Twitter
  • Jaiku
  • LinkedIn
  • ma.gnolia
  • blip.tv
  • upcoming.org
  • MetaFilter
  • LiveJournal
  • CiteULike
  • Technorati Profile

RSS Feed Subscribe:

RDF

« July 2009 »
SuMoTuWeThFrSa
 1234
567891011
12131415161718
19202122232425
262728293031 

View in month context

On this day in: 2006 2007 2008