Unencrypted public wifi should die
lcamtuf.blogspot.com
lcamtuf.blogspot.com
Even encryption does not solve this. How do you prevent someone from just setting up an accesspoint and then sniffing on all routed data?
In addition, for the operator of the wifi hotspot there is no incentive to setup a complicated encryption scheme: If you care about the security issues it's likely that you know how to solve them yourself (see below). If you don't care it's likely that you won't be able to setup a WPA password that is indicated in the SSID.
The only solutions for this are:
- Either you establish end-to-end security with each individual server you want to contact. Unfortunately this doesn't really work with HTTP today.
- You open a secure channel to a trusted entity (such as a VPN provider you trust) and then route all data over this channel. Such solutions are available for less than $10 a month.
If you think that option #2 is too hard for someone without any knowledge about security you've just identified a new business idea.
- Not being able to access the internet seriously sucks. It took a month to get DSL in my apartment, and every time I wanted to check my mail in that month, I had to go to a coffee shop, or to work. Nobody in my building had an open point.
- It's a legal hack: Since my ISP never sees the MAC addresses of the machines connected to my router, there's no way to prove what traffic came from what. This may prove handy if the government drops the hammer on people who accessed the wikileaks cables.
For these reasons, it would suck if public wifi was killed. A more elegant solution would be auto-negotiated SSL tunnel to the router, over which all traffic would be routed. Protection from eavesdropping, without denying access to users.
Alternatively: are you implying that a Tor node is "more deniable" than an open wifi? If so, why?
I do watch the connection regularly, and I block the MAC addresses of people that appear to be downloading large amounts of data, running torrents, etc (so far MAC blocking has been sufficient - I haven't had a persistent user switching addresses or trying to use my own).
I was under the impression that sniffing WPA encrypted traffic was difficult even if you know the passphrase.
It's been a while since I did it, but I do remember you need to listen to the initial negotiation for WPA, but not for WEP.
Just don't think your colleague (who hates you) or nearest BOFH at the job, technically can't stealthly plug out your cable while you're out, hook up his router performing a MitM attack, and have his fun and profit. Yeah, that's childish, much less probable, and incomparably more risky than just sitting with laptop at cafe, but the point is that every one of said attacks can still be carried out.
Just because the whole world's relying on the obscurity as a primary security measure.
When using an open, unencrypted wifi router, you should understand you are connecting your computer to a potentially hostile network with could be populated by lots of very bad computers.
- VPN-as-a-service: a free-to-download client with access to a secure access point. You download it, install it and pay as you go. It could even stand guard preventing you from joining unsafe networks.
- Where-do-you-want-to-pretend-you-are: very useful for geo-restricted services
Security on the web is broken in many technical ways.
Therefore, we should strive to change social practices regarding the use of a technology that is completely independent of the web, instead of actually fixing the problem itself.