Skip to Content.
Sympa Menu

cat-users - [[cat-users]] Eduroam vs Security

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

[[cat-users]] Eduroam vs Security


Chronological Thread 
  • From: Andre Forigato <andre.forigato AT rnp.br>
  • To: cat-users AT lists.geant.org
  • Subject: [[cat-users]] Eduroam vs Security
  • Date: Tue, 2 Apr 2019 10:33:41 -0300 (BRT)

Eduroam vs Security


Hello All,


I need to share information about the safety of Eduroam.

If a hacker installs an access point with the name of Eduroam, and this
access point points to a Freeradius server, it is possible that the malicious
person sees all the logins and passwords in the Freeradius logs.

How to avoid this situation? Should user institutions force their students to
use personal certificates? (certificate issued by the institution itself to
its students)

Reaffirming that the idea here is how to make users of university
institutions not fall into the trap of malicious people. Anyone can set up an
access point pointing to a fake freeradius server. And these malicious people
can get the username and password from all the devices that connect to the
Eduroam access point.

How can we solve this problem?

Att,
André Luis Forigato



Archive powered by MHonArc 2.6.19.

Top of Page