Live data from Hacker News

Open Wireless Movement

openwireless.org

21–30 of 53 posts

Re: Open Wireless Movement

#21
post #20
post #4

Earlier quoted context omitted.

What would that protect against? The only use that I see for a standard-password approach is that it would circumvent some ISPs' terms of service that say you can't run an open network. But even then, a court may find that a closed network with a password like `openwireless` (i.e. as part of OpenWireless.org) is an "open network" anyway.

Using an open network without encryption allows a passerby to listen in to all of your traffic. Unfortunately not all websites are using SSL yet.

If attacker knows network pre-shared key, and intercepted handshake, they can decrypt your traffic.

Re: Open Wireless Movement

#22
post #8

Earlier quoted context omitted.

Especially since most devices auto-associate with known networks. Under the status quo, if I'm desperate for Internet I make a gut decision on how trustworthy I think the nearest random open network is based on the context of my present situation. If openwireless becomes the default, I might decide that in this random small town coffee shop, openwireless is probably trustworthy and associate with it. I do my business…

I've configured my Nexus 5 to auto-connect to any open "linksys" SSID. How would this be any different? Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.

It's not different. It's not even necessarily bad. It's just worth considering while evaluating this proposal.

Re: Open Wireless Movement

#24
post #2

Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.

That's not a password, that's a shared private key. Encrypting everyone's traffic with the same private key provides no real security benefit at all.

Re: Open Wireless Movement

#25

Earlier quoted context omitted.

I've configured my Nexus 5 to auto-connect to any open "linksys" SSID. How would this be any different? Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.

And what if you need to login to a site that isn't SSL-secured? There's nothing the end user (you) can do about that.

You use a VPN to tunnel to a trusted server and have it initiate the cleartext connection to the site, keeping the traffic between you and that server encrypted.

Re: Open Wireless Movement

#27

Until somebody uses your open wireless for child porn and the cops come asking you questions.

An interesting counterpoint from Bruce Schneier: https://www.schneier.com/blog/archives/2008/01/my_open_wirel...

I've had enough experience with being cut off first and asked questions second. Running a server at home, this wasn't pleasant. I don't fancy trying out how often random people manage to cause abuse reports with my ISP - let alone the police. Besides, wireless isn't magically limited to the confounds of my home and garden. It's not basic politeness like a cup of tea as the page claims.

Re: Open Wireless Movement

#28

Until somebody uses your open wireless for child porn and the cops come asking you questions.

An interesting counterpoint from Bruce Schneier: https://www.schneier.com/blog/archives/2008/01/my_open_wirel...

He has been having second thoughts though: https://www.schneier.com/blog/archives/2011/04/security_risk...

Re: Open Wireless Movement

#29

Until somebody uses your open wireless for child porn and the cops come asking you questions.

An interesting counterpoint from Bruce Schneier: https://www.schneier.com/blog/archives/2008/01/my_open_wirel...

And yes, if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence.

In Germany this defense wouldn't really help you much. You're (partially) responsible for the crimes that are committed over your unsecured network. It's called "Mitstörerhaftung".

Re: Open Wireless Movement

#30
post #29

Earlier quoted context omitted.

An interesting counterpoint from Bruce Schneier: https://www.schneier.com/blog/archives/2008/01/my_open_wirel...

And yes, if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence. In Germany this defense wouldn't really help you much. You're (partially) responsible for the crimes that are committed over your unse…

I can attest as an American in Berlin -- Germans are VERY serious about their privacy. this is especially true when related to the network/internets.
Post reply on HN