They also use the dumbest access points- they don't support roaming and connect you to the least congested point regardless of speed. It used to be a morning ritual of mine to toggle wifi on and off again until I had a decent connection.
They also use the dumbest access points- they don't support roaming and connect you to the least congested point regardless of speed. It used to be a morning ritual of mine to toggle wifi on and off again until I had a decent connection.
Yes, the ideal, which we should all be actively working towards, is HTTPS. That doesn't mean that the world is already there.
I was going to complain to sched.com for you, but I can't replicate the problem:
https://ossna19.sched.com/password-reset is the default and http://ossna19.sched.com/password-reset redirects to it.
(I work for the Linux Foundation.)
But as others note, the main purpose of having a password at all is to stop casual passersby from leeching off your network.
Something like one of the 802.11 Enterprise modes that don't use a PSK and actually check against a user DB before handing out a session.
And how about when you’re having a meeting with outside people who need to get onto a network?
For guests you either generate guest account or just have a guest network. We don't care if guests fight over the guest network because there aren't that many of them around at any one time... the problem is that actual WeWork customers shouldn't be fighting over insecure APs.
Others do have separate networks of course and maybe that makes sense in the case of something like WeWork that probably has more people who aren't employees/paying customers coming in and out and getting on the network than the typical company office does.
Not really, every OS (even Network Manager does a good job) has support for the WPA enterprise login flow. You basically get 1 prompt to trust a cert, then enter your username + pass (usually tied to AD) which you can save to your OS keychain. I've never had to fiddle with the one at my corporate network since first signing in months ago.
I don't know about the actual security benefits, but I do know it stops the typical "capture the handshake & game over"
> And how about when you’re having a meeting with outside people who need to get onto a network?
You set up a crappy rinky-dink "FooBarGuest" network with a PSK that has no real access to the rest of the network and pretty much can just be used for web browsing.
Looks like this was only added in WPA3!
They can see what domains I connect to and when, but that's it, correct? No MITM, no further snooping, right?
Otherwise, it depends on what else you use the network for. Maybe you set "SSL optional" in your mail client so your email password gets fired off in plaintext. Maybe your special radio streaming app is vulnerable to RCE. Maybe the latest Windows update accidently started sending your keylogs (ahem, "telemetry") over an unencrypted channel.
Once an attacker is in your network, it's more or less trivial to make that software connect to a malicious update server.
Of course, a lot of code signing systems are mismanaged, so...
Also IP addresses and domain names you visit are visible.
DNS queries are probably still visible though, and responses potentially poisoned.
I think it's perfectly fine to expect some risk connecting to someone else's network. At least they didn't make it an open network. If you're a person that wouldn't connect to the internet in a cafe without a VPN, you shouldn't either at a WeWork.
Personally, I think any attempt at them to provide serious security on the shared network would be a really bad idea. It'd make people feel comfortable but somebody would find a hole and suddenly have access to a ton of devices.
If security is an issue, just use a VPN/Wireguard.
And yes, we did setup a VPN for all of our employees to use while we were in the WeWork office. I don't think that changes my point that the WeWork network is not setup well at all.
It is an open network, they just are limiting bandwidth use of passer byers.
I can get 20-40MB/s, not the fastest I've seen, when I was plugged into gigabit at MSFT I could basically saturate my network card, but far faster than my home connection and good enough for any possible need my development laptop has.
TBF to your complaints, I am mostly stationary, and the WeWork labs floor I'm on doesn't have very many walls, but I've roamed video calls before and not had an issue.
(The space I'm in is super new though, it was constructed last November, so that may be part of the difference as well?)