Open Wireless Movement
openwireless.org
Open Wireless Movement
1–10 of 53 posts
Re: Open Wireless Movement
#2Re: Open Wireless Movement
#3Re: Open Wireless Movement
#4Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.
The only use that I see for a standard-password approach is that it would circumvent some ISPs' terms of service that say you can't run an open network. But even then, a court may find that a closed network with a password like `openwireless` (i.e. as part of OpenWireless.org) is an "open network" anyway.
Re: Open Wireless Movement
#5Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.
Re: Open Wireless Movement
#6[1] https://github.com/seattlemeshnet/meshbox
[2] https://github.com/cjdelisle/cjdns/tree/master/tunnel
[3] Desktop/Server Linuxes, Android, OpenWRT, OSX, FreeBSD. Even Windows support is being worked on.
Re: Open Wireless Movement
#7Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.
No, because you can set up a honeypot knowing this password, and then mirror your input to the sites you visit after I collect your information.
Re: Open Wireless Movement
#8I love the idea, though the paranoid security conscious developer in me is really worried about the security for average users. I'm not worried about the individuals opening up their routers, there is always a risk, but that can be mitigated. I'm more worried about average people thinking that whenever they see an openwireless.org hotspot, they'll think it's safe. And it's obviously not, or I wouldn't know about my n…
Under the status quo, if I'm desperate for Internet I make a gut decision on how trustworthy I think the nearest random open network is based on the context of my present situation. If openwireless becomes the default, I might decide that in this random small town coffee shop, openwireless is probably trustworthy and associate with it. I do my business and leave. Then, I could be walking through an airport and pass someone who's set up a malicious base station using the openwireless SSID. My device could associate with it and put me at risk without me even knowing.
Re: Open Wireless Movement
#9I love the idea, though the paranoid security conscious developer in me is really worried about the security for average users. I'm not worried about the individuals opening up their routers, there is always a risk, but that can be mitigated. I'm more worried about average people thinking that whenever they see an openwireless.org hotspot, they'll think it's safe. And it's obviously not, or I wouldn't know about my n…
Especially since most devices auto-associate with known networks. Under the status quo, if I'm desperate for Internet I make a gut decision on how trustworthy I think the nearest random open network is based on the context of my present situation. If openwireless becomes the default, I might decide that in this random small town coffee shop, openwireless is probably trustworthy and associate with it. I do my business…
Don't rely on SSID for security. Rely on SSL/TLS and certificate pinning.
Re: Open Wireless Movement
#10Is there a reason for recommending an insecure network? Would suggesting a global default password for an encrypted network be better. It can be as simple as 'openwireless'.