Uh, Wi-Fi security still sucks. Can we fix that?
Uh, Wi-Fi security still sucks. Can we fix that?
* https://standards.ieee.org/beyond-standards/data-privacy-and...
* https://datatracker.ietf.org/meeting/112/materials/slides-11...
Wi-Fi 7 Sensing (802.11bf) of humans can measure breathing rate, keystroke typing, position and motion, from outside the walls of homes and business. What's the relationship between human biometric recognition and security?
Biometrics are great for identification, not so much for authentication.
My only gripe is that for whatever goddamn reason Android isn't able to detect what specific subset of WPA2 Enterprise config the AP actually wants/supports and the UI seems to constantly change around over the years, a common annoyance in large campus networks where the admins don't stay on top.
PSK authentication works both ways. If the network does not know your entered passphrase, your device won't connect to it.
The same is true for some (but not all) WPA enterprise EAP authentication methods (EAP-PWD uses it, for example); others do use public key certificates (like anything based on EAP-TTLS/EAP-PEAP). In case of EAP-PEAP-MPSCHAPv2 you even get both.
Yes, but the PSK is shared so...
> others do use public key certificates
What's needed is a mechanism for learning those. That's where the QR code thing comes in.
If you're using WPA-Enterprise, yes you can - you need to roll out your own SSL PKI though, and almost no consumer-grade APs support it.
> When I go to someone's home it'd be nice if they could post a QR code for their guest Wi-Fi network and all I'd have to do is scan it to join it. Plus a QR code could elide the need for a password.
That has been a thing for years [1], if you need a generator you can use [2].
[1] https://github.com/zxing/zxing/wiki/Barcode-Contents#wi-fi-n...