WPS was kinda close, but you needed to set up the router (most home users won't figure this out), and actually press a button on it to invite a user.
Apple's protocol is super user friendly, when someone tries to connect to my wifi at home, I get a popup offering to share my wifi password.
I'm glad this sort of protocol is being reverse engineered and FLOSS alternatives pop up, since it'll allow better interaction with Linux desktop and iOS guests.
The PIN was implemented first because it’s the most convenient and doesn’t need hardware and it turned out to be a security disaster.
So now its reputation is shot and for both PIN and the button there had to be a way to turn off WPS (with the ‘secure’ default option being WPS off)
$ qrencode "WIFI:T:WPA;S:${SSID};P:${PASSWORD};;" -o wifi.pngOn iPhone if you and a friend in iMessage are together and one can connect to a protected WiFi, the other can connect to. Automatically.
Scenario: people come to my home, I give the password to a friend of mine that never visited me before or changed phone and asks me for the password. I don't know the other people and they don't ask for the password, but they get on the network anyway? Principle of most surprise and least security.
The idea that more sophisticated authentication is possible to prevent password sharing would be a surprise to most laypeople I know.
Also home internet is increasingly coming with smart routers that will alert you to new devices on the network. Tech savvy people are the only ones who BYOD.
Then they should switch their network to a more complex authentication scheme. Multiple SSIDs, run 802.1x authentication (maybe with certs), MAC filtering maybe (bypassable sure, but will foil most casual users), run their own simple portal and shunt different classes onto different VLANs with different levels of isolation and traffic shaping, etc.
Ultimately if there is one password which then gets any device on, well that's that. Sharing has always been pretty trivial. If the owner of a network wants more fine grained and powerful security, all the tools exist to do that already, but they'll have to use them.
That's what you get when all the decisions are made by a comitee that only cares about the BOM cost in the modems.
btw, nothing on this have changed. Only that the not-so-secure stuff is still relatively new and not exploited yet.
all hail wpa3, the new crapy unsafe standard of tomorrow.
or betting their life on WPA3 that haven't had a decent sized deployment yet?
Or did they bet their lives on WPA2-PSK/WPA2-enterp during the first months of launch before any exploit was public?
:)
As for the iMessage thing, holy shit that is such a bad idea and I'm really glad I never gave any iPhone users access to my network!
I don't think this is accurate. The Wifi sharing feature works differently. It's documented here: https://support.apple.com/en-us/HT209368
But the Apple sharing is something else entirely.
Why not just have an open WiFi network? I stubbornly have kept my network open since my very first Linksys WRT54G router. Am I some kind of internet hippy for feeling like networks should be open and we'd all be better off if we shared with our neighbors? Over the years, I've probably wasted an hours of my life searching for and struggling to correctly enter complex WiFi passwords.
Although truth be told, I think it's primarily that I don't want to bothered giving WiFi passwords to my guests:)
Because I don't want the creepy neighbor kid to do something on my guest network that will get me a visit from the cops or a letter from my ISP. Sure, guests could do that, but they'd be a lot less anonymous in the process.
Think about it. Honestly, what are the odds of that? I'm sure the last time I got in my car (to get a coffee) it was 100x more risky than that (actually it was snowing, make it 1000x). And so what? They show up, I'd tell pull open their phones and connect to my network. I did nothing wrong, have at it wasting my tax dollars. After all is said and done in that 1-in-a-million incident, still less of my life wasted with than if I bothered with annoying WiFi passwords over these decades.
Your comment reminds me of my friends and family who keep their kids locked up (pre-COVID), depriving them of the opportunity to learn independence that I had growing up. Just like when I was a kid, there is no crime in my neighbor and yet people act like their kid will have a 10% chance of being kidnapped if they let him go to the local convenience store, when in reality the odds are closer to 1 in 100 million. Social media or local news has screwed up our society's ability to calculate risk/rewards.
Here in Canada, I'm comfortable knowing the cops won't show up in military surplus and shoot me before I can explain.
I used to do that for a long time. It was great for guests and also for plausible denaiblity if I every got a nastygram from my ISP.
But the liability just got to great and the plausible deniability argument got pretty weak. And also, with so many neighbors with devices that will just auto join open networks, I started seeing strange traffic a lot, most likely from neighbors connecting accidentally.
At the end of the day, making it super easy for guests inside my house without being totally open works out well.
If Apple isn't using that, then it's them who are ignoring the standards and doing their own thing.