Earlier quoted context omitted.
Why? Here's my current POV: 1. Internet is not really a public resource, it's rather a gigantic alliance of p2p connections, mostly organized by private entities who can make whatever contracts they want. 2. On this alliance, if one actor wreaks havoc (spam, DOS, scam, piracy), the victim can only turn back to the node which transmitted the connection; 3. It's up to this node to keep logs and forward the pursuit upst…
> you think we should let criminals access the internet anonymously? Of course we should, because that is unavoidable. Making anonymity harder will make it so that only criminals have anonymity, because they are the ones who can justify extraordinary measures and are willing to break laws in order to get it. All laws against anonymity do is harm honest people who need it for anonymous speech and privacy. And somehow…
Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
61–70 of 85 posts
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#62Earlier quoted context omitted.
I think he might be referring to "public" but not public wifi, like coffee shops etc. I've long thought that if your business is using public unlicensed spectrum then you should be required to let the public in. A very large national phone carrier in my country is blanketing the cities with wifi reserved for their customers - using a public resource and clogging up the unlicensed spectrum for private gain. They've al…
Large scale public wifi generally doesn't have passwords, that clearly doesn't scale, they have fancy enterprise auth things or captive portals. Shared password only works for small places like coffee shops. Anecdotes: 1: on London Underground, my phone authenticates using the SIM somehow (it still shows a captive portal screen, just with an ad, yay). 2: in the Turkish lounge in Istanbul airport, the shared password…
One does not need a license to operate a radio in the WiFi bands, so that spectrum is unlicensed. However, it is not unregulated. :)
> Anecdotes: 1: on London Underground, my phone authenticates using the SIM somehow...
That might be EAP-SIM [0].
EAP (and WPA2-EAP) is really cool. I really wish that MSFT would configure their WiFi supplicants to not care if the key of the PEAP or TTLS server they're talking to is signed by an unknown CA. This would let coffee shop owners deploy encrypted but password-less WiFi and shut down a whole class of attacks. [1]
[0] https://en.wikipedia.org/wiki/Extensible_Authentication_Prot...
[1] Seriously, MSFT obviously designed their WPA2-EAP GUIs only for use in an enterprise environment. There's no way for a Windows user to connect to a WPA2-EAP network that uses PEAP or TTLS with a cert from an unknown CA by just clicking on the network in the network browser and punching in some credentials. You must manually configure the network, then uncheck a checkbox buried beneath a couple of menus. What's more, the error you get if you don't do this is entirely unhelpful. :/ In contrast, Apple's GUI for this is actually useful: "This cert is unknown. You want to trust it for this WiFi network?". Say yes and off you go!
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#63Earlier quoted context omitted.
This isn't really true. If you know the PSK and can capture the packets of the client associating with the AP, you are able to decrypt any further communication. http://security.stackexchange.com/questions/8591/are-wpa2-co...
Well, that's almost as terrible. Combined with the "everyone can deassociate everyone" that's been in WLAN forever and the "enterprise" solutions using MSCHAPv2 where passwords can be almost trivially recovered it's pretty much impossible now to do WLAN securely. Companies should really treat any wireless network as basically insecure. The terrible certificate support in e.g. Android is just icing on the top.
Those enterprise solutions are almost certainly wrapping the MSCHAPv2 exchange in TLS. e.g. PEAP-MSCHAPv2 or TTLS-MSCHAPv2. Additionally, I'm not sure, but I think that plain EAP-MSCHAPv2 can't generate the keys required for a wireless client to establish an encrypted session with an AP and -thus- would never be used by a WiFi client.
> The terrible certificate support in e.g. Android is just icing on the top.
Eh? In my experience both Android and OS X's UIs for WPA-EAP are substantially superior to the UI that Windows offers.
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#64Is this a common practice in Europe /US? It seems ridiculous that the WiFi provider would be held liable for such a thing. Why stop there, should make the ISP liable too!
Another unusual German law is having to register your location with the police, even where you're staying when you travel to other parts of Germany for a few nights.
China, Russia and the US all require that.
Citizens and everyone else with a residence permit don't have to register temporary whereabouts ("for a few nights").
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#65Earlier quoted context omitted.
Another unusual German law is having to register your location with the police, even where you're staying when you travel to other parts of Germany for a few nights.
Foreigners? Probably, but I haven't checked. But how is that unusual? China, Russia and the US all require that. Citizens and everyone else with a residence permit don't have to register temporary whereabouts ("for a few nights").
On the other end, the US is pretty unique in that you don't have to notify the government that you're leaving the country. I believe recent laws actually authorize an exit-tracking system, so that might be coming to an end unfortunately.
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#66Earlier quoted context omitted.
Foreigners? Probably, but I haven't checked. But how is that unusual? China, Russia and the US all require that. Citizens and everyone else with a residence permit don't have to register temporary whereabouts ("for a few nights").
It's not just foreigners, it's everyone in Germany. I'm not that familiar with the details though. No such thing is required in most of the West I think. In practice, an ordinary life leaves an ample paper (and digital) trail, but you can legally live "off the grid" if you'd like. On the other end, the US is pretty unique in that you don't have to notify the government that you're leaving the country. I believe recen…
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#67Earlier quoted context omitted.
> But to take your idea just one step further, once you've opened up all wifi for the general publics consumption (what a renaissance for wired networking!) I think this requires clarification - I don't mean no business should ever use wifi. I mean businesses like telephone companies shouldn't be using to augment their networks. Obviously offices and the like need secure wireless networking that normal hardware can c…
So you're speaking of a specific problem in a specific place - this is kind of hard to know when it was phrased as a general principle. Also, it's hard to discuss the issue when there are no details about the specific issue available. But two points: First, where I am, 2.4Ghz is perfectly swamped with normal residential access points. It seems unlikely that this telco in your city did much more than move up the point…
I don't particularly want to get out the spectrum analysis gear and argue with your points in a ground war. I think for discussing a general idea it's a distraction.
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#68Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#69Earlier quoted context omitted.
More precisely: for example hotels typically have a public wifi for their customers, but you must get an individual login account from the reception. This protects the hotel or its service provider. It is quite silly, of course, and is generally a little hassle with your hotel.
It's more problematic when you're transiting through a German airport, and practically fall off the face of the earth. Ohhhh, they have a wifi hotspot portal: "Enter your cell phone number to get an SMS with a 30 minute code". You want me to turn on my cell-phone and potentially incur roaming charges now? I hear things have gotten better in Frankfurt and you only have to provide an email address. How did they skirt t…
By being run by companies that claim to be ISPs. What exactly counts as an ISP is at the core of the entire issue, because ISPs are protected from this. A company which only exists to provide internet access has a better standing (and better lawyers) to argue that it is an ISP, compared to a private person or a coffee shop owner.
Most coffee shops I use Wifi in thus have access points provided by such companies. They offer AP/captive portal etc as a package and send the traffic through their systems, taking responsibility for it. (for good measure, some of them probably send the traffic out to the internet in other countries, to make it harder to harass them over it)
Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report
#70It's just common sense... Can a ISP be liable for what it's user do? An open Wi-Fi hotspot is basically an ISP....