Live data from Hacker News

WPA3 Enterprise 192-bit mode at home

smallstep.com

171–180 of 201 posts

Re: WPA3 Enterprise 192-bit mode at home

#171

Earlier quoted context omitted.

You're not going to increase connection reliability/extend your wifi range by enabling radius. If you have any understanding of what's happening here, you wouldn't even ask this question.

What I’m wondering has nothing to do with signal strength. I’m wondering if the protocol differences have any effect on reliability in situations where the wireless connection is less reliable. Because, for example, there’s less negotiation on reconnecting to the network or something. After all, reliability is a cross-cutting concern :)

Unfortunately it's hard to beat a PSK based exchange in terms of quick connection, particularly with something like this where the authentication server is moved external. The difference in reconnection time is, in general, extremely marginal though. If the Wi-Fi is bad enough your client thinks it actually needs to reconnect instead of retransmit the only meaningful respite is to solve that problem directly.

Re: WPA3 Enterprise 192-bit mode at home

#172
post #76
post #52

I know the article is just "here's how", but I don't trust my wifi because of the hardware and software on it, so for me the protocol is irrelevant.

I work at smallstep. For home wifi this is totally overkill. Better security is always nice but, in this case, there's a significant usability & interop tradeoff for home use (though that may change over time... we'll see). For business / enterprise settings, this has real value. Distributing a password to everyone doesn't scale and alternative EAP methods have huge security problems. For managed devices, certs can b…

PEAP can still require a trusted server certificate -- getting set up with MDM is a pain, and scaling by hand is also a pain, but you can (and I do) set up my devices to require a specific valid SAN on the RADIUS connection. No extra certificate trust required, if the RADIUS server has a certificate that chains up to the default trust store.

I remain disappointed that there's no standard mechanism for mapping between an SSID and a domain name to know which SAN to trust.

Re: WPA3 Enterprise 192-bit mode at home

#173

Well, that means I couldn't use my iPhone from work at home as it blocks installing certificates. But, while not NSA approved, WPA3 itself has support for per-device passwords with WPA-SAE [0] (which isn't called WPA-METRIC outside of the USA...). [0] https://en.wikipedia.org/wiki/Simultaneous_Authentication_of...

[deleted]

Re: WPA3 Enterprise 192-bit mode at home

#174
post #48

Earlier quoted context omitted.

I wish more consumer devices supported multiple PSKs on the same SSID. It's a handy feature much better for airtime than creating multiple separate SSIDs and much better for sanity than 802.1x user or cert auth.

> I wish more consumer devices supported multiple PSKs on the same SSID Could you name any enterprise APs that do this, short of running your own custom AP software? As far as I know (would love to be corrected on this), Unifi APs can't do this, and they're at the very least "prosumer".

Aruba, Cisco, Extreme, Mist, Ruckus. The first I saw use it was Aerohive (now part of Extreme) and it took the enterprise market by storm about 5 years ago. For most enterprise deployments 802.1x (either username+password or certificate) makes more sense but once you get into BYOD land (say, senior living) not all devices support that (say an Xbox) but you still want to give a user a way to connect anywhere they go not just their main living area. Similar with the BYOD network on schools, give out the PSK to anyone staff and a year later the kids all have it and you have to change every PSK only device to a new PSK manually to fix it. Use multiple PSKs to give different groups of devices different PSKs, and even different staff different keys, and you not only contain the problem but can actually narrow down on the worst leak offenders as well.

Re: WPA3 Enterprise 192-bit mode at home

#175

Because the requirements of "192-bit mode" for WPA3 Enterprise fall on not only the actual WiFI but also the backend identity providers, you are explicitly not allowed to do this for Eduroam unless you also provide a parallel WPA2-style (thus WPA3 compliant but not "192 bit mode") WiFi for everybody whose home institution isn't the US government. Lots of institutions have Eduroam set so that students (and academics,…

???

This is a dude playing with his home wifi. 192-bit WPA3 Enterprise is not for every use case, nor does the author or anyone else make this claim.

Your comment seems misplaced.

Re: WPA3 Enterprise 192-bit mode at home

#176
post #121

I think this is generally barking up the wrong tree and addressing the wrong attack vectors for home wifi. An actual over-engineered home wifi looks like this: 1. Use, at the very least, prosumer grade router access points. I use *sense and Aruba access points, but you don't need to get this serious. 2. Use heavy DNS filters. This will block a lot of malware by itself. Quad9 DNS is a good starting point. 3. Use a sec…

Items 4-9 accomplish nothing. Your LAN is not a security perimeter. This ain’t token ring.

You work with reality as it is, not as you'd prefer it to be.

A home router is generally protected on the WAN side.

Your threat model is to secure connections originating from the LAN side, which is the only way a threat actor can establish a connection into a default deny network.

Re: WPA3 Enterprise 192-bit mode at home

#177
post #156

"NSA grade" irks me - to think these guys have your best interest at heart. In the 1970's they weakened DES [1]. In 2015 the NSA created a backdoor and pressured companies into installing it [2]. In 2016 you had the leaked tools stolen and used by the Shadow Brokers / Equation Group [3]. More recently the NSA made arguments against double encryption to combat weaknesses in potential quantum-safe encryption algorithms…

On your first point, I’m not aware of NSA weakening of DES. Only in-fact strengthening it against differential crypto analysis. Your link seems to echo that. Were you thinking of something else? Of course, the fact the NSA was aware of differential crypto analysis some years before the rest of us is another thing…

This I guess?

https://en.wikipedia.org/wiki/Dual_EC_DRBG

Re: WPA3 Enterprise 192-bit mode at home

#178
post #57
post #9

Earlier quoted context omitted.

It's not unusual to run multiple APs on a single SSID. Your scheme doesn't work for that without coordination between the APs. Also, it means replacing an AP would require reconfiguring all the clients.

Isn't coordination between APs something that Ubiquiti APs already do?

> Isn't coordination between APs something that …

All non-consumer grade (and some consumer grade) AP systems do. Ubiquiti isn’t first, unique, or best in this category.

Re: sibling comment, and no, WiFi Alliance isn’t what resulted in this working, you have it the wrong way around.

Re: WPA3 Enterprise 192-bit mode at home

#179
post #64

Personally I've essentially given up on depending on WiFi auth for anything important. For general access, segmenting various users, IOT etc for performance, monitoring and light privacy WPA-EAP and PPSKs with VLANs does some work as an initial first layer fine and in a simple reliable way that works with everything. It's a low pass filter. But for all sensitive access I use internal Wireguard now. WiFi auth gets a c…

What is your threat model to warrant this effort at home? Are your work-related machines not networking through an encrypted tunnel in some other way (that would be a serious oversight!)? What government are you living under that is routinely compromising WPA3 from mobile vans? Are friends/guests so untrustworthy that you can allow them into your home but can’t trust the VLAN implementation of your network equipment…

>What is your threat model to warrant this effort at home?

Same normal one as everyone else in a connected world? I find this interesting and do the same stuff for both home and work. You make a lot of mistakes and wrong assumptions, but a big one is failing at all to consider cost amortization. You're assuming this is a burden, but that's backwards. I need/want a decent network anyway. I want to use open source for core areas to avoid actual problems I've had (not theoretical) with lock-in going wrong anyway. There is absolutely real work and cost in setting that up, same as a good NAS, virtualization (or home k8s clusters some people do or whatever else), etc. But once you do, the marginal cost of doing more stuff with it is tiny, which of course is some part of the whole value in doing it in the first place. It's absolutely wise to pick where one spends their time and resources with care, and I have zero issues with leaning on COTS and other professional in plenty of areas. Self-hosting is both something I enjoy, something I think is important/valuable, and of professional interest.

>I’m asking incredulous and probing questions because I used to live life the way you are currently, and it’s frankly unhealthy for the human brain. If “home” feels like such an unsafe place to warrant your current measures, you need to either make serious changes to where home is, or your mental state. Neither is easy but at least one is necessary.

This is a lot of projection and confusion on your part I'm afraid. None of this has anything to do with "feeling unsafe" beyond the basic ways perhaps we should given the state of smart home devices, cloud service dependencies etc, and how valuable our digital lives and monitoring of them now are. As far as security you've literally got it backwards though: moving to an open less complex higher layer is simpler, more practical, more reliable, and thus it reduces vs adds mental burden. I don't need to think as much about whether some new aggressive smart home thing is trying to scan my network and what issues it might have (they are, they do, and no I do not get total veto on what comes in vs family desires/needs), about making use of still good but now old and never updated kit, about issues in the network hardware itself (like when some UniFi gear was leaking traffic between VLANs [0]), about new surprises in WPA, ever more automated attacks, and on and on. A minute to setup a tunnel once and a lot of that evaporates for years at a time. It significantly reduces the surface area of stuff that is critical to stay on top of vs "eh, check on updates once in awhile".

None of this comes from the strange state you describe yourself as in, but from curiosity, interest, and reasonable respect for the amount of risk against both my own limitations and positive features that I want to take advantage of in my life. Indeed if I didn't consider my home, office, and other work spaces fundamentally physically safe that would undermine the foundation of self-hosting! But physically safe with great neighbors and so on is separate from the connection to the entire rest of the planet, and the various black box objects we bring into said safe home made by profit seeking multinationals capable of communicating without our approval over said connection to the entire rest of the planet right? I hope you're making progress though!

----

0: https://community.ui.com/questions/BUG-NanoHDor-broadcast-an...

Re: WPA3 Enterprise 192-bit mode at home

#180

Earlier quoted context omitted.

NSA. Is that the organization of unemployed mathematicians that thinks it is 1989? The group that can't crack the super secret algorithm of "https". Yeah, that is the one, the group that is puzzled by large prime numbers.

I know I shouldn't, but... https isn't an algorithm.

lol. I know. I should have used "for"
Post reply on HN