cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Andre Forigato <address@concealed>, address@concealed
- Subject: Re: [[cat-users]] Eduroam vs Security
- Date: Tue, 2 Apr 2019 15:41:57 +0200
Hello,
> I need to share information about the safety of Eduroam.
>
> If a hacker installs an access point with the name of Eduroam, and this
> access point points to a Freeradius server, it is possible that the
> malicious person sees all the logins and passwords in the Freeradius logs.
>
> How to avoid this situation? Should user institutions force their students
> to use personal certificates? (certificate issued by the institution itself
> to its students)
>
> Reaffirming that the idea here is how to make users of university
> institutions not fall into the trap of malicious people. Anyone can set up
> an access point pointing to a fake freeradius server. And these malicious
> people can get the username and password from all the devices that connect
> to the Eduroam access point.
>
> How can we solve this problem?
It is strange that you ask this question on this mailing list.
The solution to this problem is that users have to get onboarded with
configuration details which specify exactly what the correct
authentication server is, and to lock down the configuration so that any
usernames and passwords are only sent once the server correctly
identifies itself.
With this done, an attacker can set up a FreeRADIUS instance as much as
they like - since the server certificate does not match the configured
expected one, the user's device will NOT send any credentials to that
fake server.
So, you solve this problem by using proper onboarding tools such as
eduroam CAT.
I would have thought that, since you are a subscriber to this list which
has eduroam CAT as its dedicated topic, you would be doing that already?
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
Re: [[cat-users]] Unique device credentials,
Workman, John R, 04/01/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- <Possible follow-up(s)>
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Per Mejdal Rasmussen, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
[[cat-users]] Eduroam vs Security,
Andre Forigato, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Stefan Winter, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Martin Pauly, 04/03/2019
-
Re: [[cat-users]] Unique device credentials,
Daniele Albrizio, 04/03/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/09/2019
- Re: [[cat-users]] Unique device credentials, Per Mejdal Rasmussen, 04/12/2019
-
[[cat-users]] Eduroam vs Security,
Andre Forigato, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Per Mejdal Rasmussen, 04/02/2019
Archive powered by MHonArc 2.6.19+.
