Exploiting WPA2 in a City Wide Wi-Fi
tripwire.com
tripwire.com
This is well known and even documented in wiresharks guides. see Gotchas -> "WPA and WPA2 use keys derived from an EAPOL handshake,..." https://wiki.wireshark.org/HowToDecrypt802.11
http://mobilesociety.typepad.com/mobile_life/2016/01/wifi-ce...
For example, EAP-TLS, unlike the TLS used in HTTPS, requires a client to provide a X.509 certificate signed by an AP-side trusted authority. This is because people like Jouni Malinen (hostapd/wpa_supplicant), in all their wisdom, decided to spurn RFC 5216 ("While the EAP server SHOULD require peer authentication, this is not mandatory, since there are circumstances...") and completely disallow any and all configuration to disable the client-cert requirement, regardless of any circumstances (such as those behind HTTPS). NYC DoITT is no more equipped to provision X.509 certs for free wifi users than the NYS DMV is to provision X.509 certs for $80 DL/ID card holders (so people can securely prove their identity everywhere).
As trollian stated, Wi-Fi Alliance's "Passpoint" (Hotspot 2.0) does allow for such setups, technically. E.g., the vendor-specific WFA-UNAUTH-TLS version of EAP-TLS does not do client-side authentication at the WPA-level, as per RFC 5216. But WFA-UNAUTH-TLS, even among Passpoint-aware devices, is likely not widely supported.
I'm not convinced that is really true. Sure, some sort of client authentication is technically required, but I think you can configure the authentication server to accept any authentication without compromising the link security. Or you could auto-provision users on first login or something like that depending on what sort of access you want to give.
It this supported anywhere? Hence the mention of HS2.0 and my jab at Jouni. (In Jouni's defense, hostapd has made really good progress on this.)
> Or you could auto-provision users on first login or something like that depending on what sort of access you want to give.
This may be supported by Hotspot 2.0 Release 2 (IEEE 802.11u) Online Sign Up (OSU) Server-Only Authenticated L2 Encryption Network (OSEN). I would like to know if OSEN is usable for this scenario.
> It this supported anywhere?
Yes. FreeRADIUS can do it. The clients don't notice. I've seen it work. The configuration is a bit tricky though. Not sure about hostapds radius server.
I've seen it in place at the Chaos Communication Congress in 2014, I used it with a couple of clients without issues. Not sure what was used or how much effort the configuration was.
Authentication in one direction (or lack of authentication entirely) is what leads to this attack, since the fake access point can just say "OK" to anybody trying to connect.
The internet is not trustworthy. It doesn't matter how you connect to it.
It looks to be using Wi-Fi Passpoint "online sign up" (OSU) setup for client cert provisioning. Unfortunately, it does NOT look like it uses OSEN (WFA-UNAUTH-TLS type EAP-TLS) for the OSU WLAN, but instead chooses the option for an open OSU WLAN (using the same SSID as the non-private network) with a HTTPS captive portal. I would assume that this is the mechanism behind the reports of certificate downloads on iPhones.
LinkNYC and Hotspot 2.0:
https://medium.com/@LinkNYC/secure-browsing-on-linknyc-s-wi-...
https://www.globalreachtech.com/deployments/link-nyc/
Wi-Fi Passpoint aka Hotspot 2.0:
https://www.wi-fi.org/downloads-public/Passpoint_R2_Deployme...
http://www.cisco.com/c/en/us/td/docs/wireless/controller/8-2...
Reports of cert provisioning:
http://blog.alexflor.es/post/137705262900/linknyc-secure-gig...
http://www.engadget.com/2016/01/19/linknyc-gigabit-wifi-hand...