Earlier quoted context omitted.
Especially since most devices auto-associate with known networks. Under the status quo, if I'm desperate for Internet I make a gut decision on how trustworthy I think the nearest random open network is based on the context of my present situation. If openwireless becomes the default, I might decide that in this random small town coffee shop, openwireless is probably trustworthy and associate with it. I do my business…
I've configured my Nexus 5 to auto-connect to any open "linksys" SSID. How would this be any different? Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.
Open Wireless Movement
11–20 of 53 posts
Re: Open Wireless Movement
#12Earlier quoted context omitted.
I've configured my Nexus 5 to auto-connect to any open "linksys" SSID. How would this be any different? Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.
And what if you need to login to a site that isn't SSL-secured? There's nothing the end user (you) can do about that.
Now, while I understand this is out of an end user's control, that shouldn't cause us to throw the idea of a shared wireless network out the door. That should cause us to look at non-secure sites accepting credentials, and how to prevent that behavior in the first place.
Re: Open Wireless Movement
#13Re: Open Wireless Movement
#14Earlier quoted context omitted.
I've configured my Nexus 5 to auto-connect to any open "linksys" SSID. How would this be any different? Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.
And what if you need to login to a site that isn't SSL-secured? There's nothing the end user (you) can do about that.
this site helps with this issue forcing sslany.
Re: Open Wireless Movement
#15Earlier quoted context omitted.
And what if you need to login to a site that isn't SSL-secured? There's nothing the end user (you) can do about that.
https://www.eff.org/https-everywhere this site helps with this issue forcing sslany.
Re: Open Wireless Movement
#16Re: Open Wireless Movement
#17Re: Open Wireless Movement
#18Until somebody uses your open wireless for child porn and the cops come asking you questions.
Re: Open Wireless Movement
#19One solution to the privacy problem is running OpenWRT with cjdns [1] on the routers and clients, and using its IPTunnel feature [2]. The list of supported platforms is steadily growing [3], and it'd be something that runs alongside the existing IPv4/DHCP setups just fine. [1] https://github.com/seattlemeshnet/meshbox [2] https://github.com/cjdelisle/cjdns/tree/master/tunnel [3] Desktop/Server Linuxes, Android, OpenW…
cjdns will never be a workable solution for the general public, and I wish people would stop recommending it.
Re: Open Wireless Movement
#20Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.
What would that protect against? The only use that I see for a standard-password approach is that it would circumvent some ISPs' terms of service that say you can't run an open network. But even then, a court may find that a closed network with a password like `openwireless` (i.e. as part of OpenWireless.org) is an "open network" anyway.