Why We Need An Open Wireless Movement
eff.org
eff.org
There is currently no WiFi protocol that allows anybody to join the network, while using link-layer encryption to prevent each network member from eavesdropping on the others. But such a protocol should exist.
It boggled my mind, repeatedly, when I discovered that non-password-protected wireless networks don't generate a unique encryption key for each connection. Boggle, I say. Sure, public key cryptography used to be too computationally expensive, but not any more. And even if it were, Diffie-Hellman has been around for quite a while, go ahead and use symmetric keys.
What the hell is wrong with our standards groups? And hardware manufacturers? There are trivial solutions to this, why haven't they pushed them?
In any case, current MITM-prevention techniques should work just fine w/o a password. Unless someone knows otherwise, I don't really see why a default-encrypted system would be any more vulnerable than something behind a password.
The article raises the point that if you're just looking for a connection, you might not know the ID of the access point you want. Most of the time, if you want to snoop on people's traffic all you'd need to do is set up an AP with a higher signal strength than your neighbour's (and just forward the traffic on to the neighbour to get the bits onto the internet.)
More to the point, even if you do know the ID of the access point they want, you may not know that it's trustworthy. Even if the link between you and it is encrypted, it still gets to see your packets in the clear.
Seriously, you're asking to be MITM'd if you're connecting to un-trusted networks. Literally. If you don't understand that, then you deserve what's coming to you. As long as you're not protecting yourself by somehow tunneling to only trusted end-points, there's no way to secure yourself.
I honestly believe this is solvable. Maybe there's no financial market, but it seems like a tremendous good.
An Open Wifi protocol might be difficult to sell, but selling better routers should be possible. The current ones are ugly and difficult to use.
It's arguable, but I agree with the author of the linked post.
This neatly solves both the problem with local eavesdroppers, and much of the problem where an ISP or law-enforcement fingers you, the billing contact, for the activity of third parties. Their traffic emerges at the other end of the VPN tunnel – somebody else's problem.
And, it doesn't require any new local crypto protocols – just mundane destination/port filtering.
A very paranoid regime could even establish rules to only allow certain accredited VPN providers (e.g. ISPs) to free people who offer open WiFi from the fear of being prosecuted.
I actually saw this back when I ran an open network, in trying to prioritize bittorrent below ssh and interactive traffic. Some remote seeders will operate on port 22 or 443 because that's the only way they can reach the outside world. If an "Open Wireless Movement" using a standard VPN setup took hold, a similar thing might happen with that port.
Of course, without DNS only the savviest users would initially be able to exploit mundane destination port filtering, but it's only a matter of time before one of these users puts together a tool for the masses. So I still wonder about the plausible deniability of such a setup.
With that, you could only use other protocols with those limited destinations if they agree... which typically they wouldn't.
Fundamentally, anyone with access to a network segment can saturate it. Like you, I ran an open network for years (this was pre DD/Open-WRT, using pebble linux), and saw some pretty crazy stuff. Eventually I got tired of fighting to maintain a fair and usable network and just went encrypted.
However -- this piece and your request for pointers has inspired me to publish my bandwidth sharing and traffic shaping scripts from those days [1], in the hopes that some of the problems can be solved. I really would like to run an open network again, I just need to get things done using my internet connection from time to time. :)
[1] https://github.com/acg/wifishape
EDIT: I need to have a fresh look at the high bandwidth encrypted / low bandwidth unencrypted setup you mention, because sharing bandwidth across separate network segments seems like it might work.
What's my recourse? Not sure I have any.
Hahaha, but more seriously this has been an idea I've thrown around for a while. Really glad people are currently working on stuff like this. Hope it gets big enough (or something like it) to have a mesh network come out of it. Then things will get REALLY interesting.
It doesn't always work quite as well as you might hope - connecting can be a bit of a pain sometimes - but it's a great idea. They've provided a real incentive for people to share their bandwidth.
It's been growing semi-quietly and the beauty of it is that it's more or less global these days..
The goal is not to prevent someone some getting on the network but rather to keep all clients separated. Is that possible using existing devices/protocols?
Does this apply to WPA2 as well?
How else would you print stuff? How does the printer having its own encrypted channel prevent it from printing stuff?
Not true. Ever heard of promiscuous mode?
> How does the printer having its own encrypted channel prevent it from printing stuff?
It doesn't. You can set up an encrypted channel between your computer and the printer by using a secure printing protocol. The point is that "the network" doesn't provide secure channels between all pairs of clients; it's up to the clients.
For wireless, you... sit up to a few hundred feet away (miles if you have a good parabolic antenna), and run Wireshark. It's entirely passive and undetectable.
However, the main security concern with open WiFi networks is that everybody can use them to do anything on the web. The person who runs the hotspot is responsible for the traffic that comes from this hotspot. If someone is using your internet connection to do anything illegal such as downloading child porn or something like that, there's no way to trace that back to the person who uses your WiFi.
The real issue is not about encryption, it is about identifying the users of a WiFi such that it holds strong in court if there are claims and one wants to prove his innocence. And I personally can't think of a secure out-of-the-box and easy-to-use solution that offers exactly that: protection from actions/attacks performed by others in your name over your WiFi without making them register and somehow prove their identity.