cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Andre Forigato <andre.forigato AT rnp.br>
- To: cat-users AT lists.geant.org
- Subject: [[cat-users]] Eduroam vs Security
- Date: Tue, 2 Apr 2019 10:33:41 -0300 (BRT)
Eduroam vs Security
Hello All,
I need to share information about the safety of Eduroam.
If a hacker installs an access point with the name of Eduroam, and this
access point points to a Freeradius server, it is possible that the malicious
person sees all the logins and passwords in the Freeradius logs.
How to avoid this situation? Should user institutions force their students to
use personal certificates? (certificate issued by the institution itself to
its students)
Reaffirming that the idea here is how to make users of university
institutions not fall into the trap of malicious people. Anyone can set up an
access point pointing to a fake freeradius server. And these malicious people
can get the username and password from all the devices that connect to the
Eduroam access point.
How can we solve this problem?
Att,
André Luis Forigato
- Re: [[cat-users]] Unique device credentials, Workman, John R, 04/01/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- <Possible follow-up(s)>
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- Re: [[cat-users]] Unique device credentials, Per Mejdal Rasmussen, 04/02/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- [[cat-users]] Eduroam vs Security, Andre Forigato, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Stefan Winter, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Martin Pauly, 04/03/2019
- Re: [[cat-users]] Unique device credentials, Daniele Albrizio, 04/03/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/09/2019
- Re: [[cat-users]] Unique device credentials, Per Mejdal Rasmussen, 04/12/2019
- [[cat-users]] Eduroam vs Security, Andre Forigato, 04/02/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- Re: [[cat-users]] Unique device credentials, Per Mejdal Rasmussen, 04/02/2019
Archive powered by MHonArc 2.6.19.