cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Toni Pérez <toni.perez AT uib.es>
- To: cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID
- Date: Thu, 12 Sep 2019 13:08:59 +0200
Hi, With nonBroadcast=true the number of probe request with eduroam
is increased in areas whrere there are no eduroam service. It
affects security by making easier the fingerprinting of users
devices (the profiles that are configured in one device). With
fingerprinting the next step is a rouge/karma attack. It's true that the user is protected if the supplicant verifies root CA and CN in radius server certificate. But supplicants don't usually give the correct information to users with messages like "there are a problem" or "authentication error" instead "Warning! Malicious eduroam detected, don't try to reconfigure your configuration". With nonBroadcast=false may be fingerprinting is still possible but with nonBroadcast=true it's true thats is more easier the device fingerprinting. Greetings, El 11/09/2019 a las 20:38, Tomasz
Wolniewicz escribió:
Hi, How would disabling this option make security better? A hidden eduroam SSID is stil covered by the security settings for the home RADIUS server, so th client will not connect to a rouge network. With eduroam connections mostly happen without thee user intervention anyway. Cheers Tomasz Wolniewicz
W dniu 11.09.2019 o 19:13, Toni Pérez
pisze:
Hello! We can see in Windows 10 profile that nonBroadcast optioin is
enabled/true (the option to connect to networks which do not
broadcast their network name or SSID). For security reasons, would it be possible to disable (false)
this option in eduroam CAT? You can verify this option with cmd -->
Best regards, Toni Pérez ------------------------------------------------------------------------------------ <?xml version="1.0"?> ..... ------------------------------------------------------------------------------------ -- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users |
Attachment:
smime.p7s
Description: Firma criptográfica S/MIME
- [[cat-users]] Windows: disable connect to nonBroadcast SSID, Toni Pérez, 09/11/2019
- Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID, Tomasz Wolniewicz, 09/11/2019
- Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID, Toni Pérez, 09/12/2019
- Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID, Tomasz Wolniewicz, 09/12/2019
- Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID, Toni Pérez, 09/12/2019
- Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID, Tomasz Wolniewicz, 09/11/2019
Archive powered by MHonArc 2.6.19.