Obviously this is true, and hotels providing wifi services want to charge for them rather than allowing users to use their own (much cheaper) systems. No question.
That aside, what is the solution to rogue access points in a public space? We all know that it's pretty easy to set up camp in a public space, broadcasting a friendly-looking but dangerous wifi network. Let's says you've got someone sitting in the Marriott lobby, creating the "Marriott Free Wifi" network. A bunch of people will connect to it, and some information will leak.
Is there any reasonable way to deal with this issue? Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there.
Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there.
Agreed on the security hole on public wifi, though it's probably about less "sensitive" data as HTTPS is becoming more of a standard, especially after the Snowden revelations.
Most services/apps speak HTTPS nowdays and a lot more will (hopefully) follow: https://letsencrypt.org/
Is there any reasonable way to deal with this issue?
Another thing to consider is how it looks. Hotel patron sees hotel's free wifi (why should they care that it's not the real thing), but everytime they try to connect, the connection fails. "Man, this hotel wifi sucks, full signal but I can't connect!"
On the other hand, you're also saying that people shouldn't care as much about security if they are on the proper wifi network, which is a little ludicrous. Just hope on a vpn either way, and you're safe.
Comments
Obviously this is true, and hotels providing wifi services want to charge for them rather than allowing users to use their own (much cheaper) systems. No question.
That aside, what is the solution to rogue access points in a public space? We all know that it's pretty easy to set up camp in a public space, broadcasting a friendly-looking but dangerous wifi network. Let's says you've got someone sitting in the Marriott lobby, creating the "Marriott Free Wifi" network. A bunch of people will connect to it, and some information will leak.
Is there any reasonable way to deal with this issue? Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there.
Agreed on the security hole on public wifi, though it's probably about less "sensitive" data as HTTPS is becoming more of a standard, especially after the Snowden revelations.
Most services/apps speak HTTPS nowdays and a lot more will (hopefully) follow: https://letsencrypt.org/
So, yes with HTTPS
Another thing to consider is how it looks. Hotel patron sees hotel's free wifi (why should they care that it's not the real thing), but everytime they try to connect, the connection fails. "Man, this hotel wifi sucks, full signal but I can't connect!"
On the other hand, you're also saying that people shouldn't care as much about security if they are on the proper wifi network, which is a little ludicrous. Just hope on a vpn either way, and you're safe.
You call the police and they arrest the person. WiFi is short ranged. Not every problem needs a technical solution.
You call the police and they arrest the person. WiFi is short ranged.
Yes, but it doesn't need constant attention. A small router can be dropped anywhere and route the information to the attacker long after (s)he's gone.
That said, finding the AP and disabling it is better than randomly throwing deauth packets.
You can't just arrest someone for having a wifi hotspot. You'd have to prove that they're doing something illegal with it, which is much harder to do.
It could use a solution that isn't racist or anything tho