Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID


Chronological Thread 
  • From: Tomasz Wolniewicz <twoln AT umk.pl>
  • To: cat-users AT lists.geant.org
  • Subject: Re: [[cat-users]] Windows: disable connect to nonBroadcast SSID
  • Date: Thu, 12 Sep 2019 13:38:42 +0200
  • Autocrypt: addr=twoln AT umk.pl; keydata= mQENBEvhYBEBCADIlSk8hnUtSfZ1hLbuqiUxTiBtm65lM6OlxjYnWEsH/boOsVS/WdFZebwK 53eg280UcX9VDjFjy5rimsknCvxabnxk13AF//t9mN9tq5MmIkIcRIpLrtqc8Q0s0E84cNzB bDMtRzAd7JUTmKyAnkKE9i2R9FJKzeR9TTeKtBdgXHtUKPHPGOdxUUv8UWKxsj9AYi2CgN98 jiWLx6lTIpaWegWxIyih7WUKSf43Bpi6wFxhfOxteLyQUpIlGg4CasTVGpFsha8KzlupXOLG Tl3hXtQFWvE0tl1GidvTyuQlOzsZ1vjTNEzI25VTkOIgP4IYcWSkP74p/a239ZcTOHhZABEB AAG0IFRvbWFzeiBXb2xuaWV3aWN6IDx0d29sbkB1bWsucGw+iQE4BBMBAgAiBQJL4WARAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRA8PEwxkb+lPgkeB/9NAGlmopLel6EEDFz2 ra3KLBx8kXT3G1K/YYyrjDwNjCkAmm0evzQx8g9vPX2OzvE6Ai2Xi9hPd2K/ShPFPcgJzzjr h9H1XYfBb2N/tRwN9tb4XO5i9Tsa4jP+SG8h2yQY57QOeFy16joDmIZiZrAEIGpqqSV24PrX FSo2d1E4dMswqDXlEYk9hwbdW9H4zOQrnDZeRlRx/RW/cmWTd8r5C12dKhlT/D/fBkL3eYT7 rnjHtS+ArnMUsxu2Z/q6bmxqRyv4Vn4pR0n699iLa0ol2hWeQJFaZyTA7JksW8zWu/Zasd9K Dw3jM59vs/SXVdG8pMexAzH5jmEEAgwYwUbVuQENBEvhYBEBCACgAz/z7VTnCsPSBUrjCLyS j+eRtr2tQzSU48Qa5hOcIxAKQJQNgOOqs0Mq9fT9lV+OttaYyKtijt1+G2dVMETVFkdZmM0c g8pVJp398993v89U/iwjfvNoqCM/9z312Poha/oL/EOk+gWYxZbyQ18SY69va2WHr6Pl3bzR 6BQpb86W85MreQ2lxd76b6BgjOXA/b39YyU/fMeFQd+wDpT3K1fUr89dYRnyzQIxTBSPOMLQ ShHKc/S8dStbNlLNcnaiyBOsH4A7b6IizQGqyVHBeL7u05X0/ZVdEIgsO3NmQouqY0/WjBdV qg4EsI1VvvgwXKWafP1MryLy4ZcnNjQZABEBAAGJAR8EGAECAAkFAkvhYBECGwwACgkQPDxM MZG/pT6lUQf8DC3i15okq3VycbpTYuH6f1lQkqanMS0z4z8F6xtCeXq0DBFk0ZzAU/mCwc3V PdUVGtRKGjouSAB1HDeTvAth1vY0oOJG3kXBwkcui3QxM3sxksNCRLLwcZVnsK9rt6UVp5aG qBwKf44BSApGyHNuKDhCfMCQHueqlfhJYfXocw6KDObvTkwygHLmw93ohV66v26yNvGo6+q2 qTDykGyuicACPDTyJTWFh2IwwZFAdzcc7St8aKkXFk0zWvoriWHeTLUnuFw7HN640IJkG74a 4NGco2yPc7Cz6q59rgE9xydOOXRdmnfiuJu0kQvQocD1rVLjW3qXdnxPd2/FhO4vWg==
  • Openpgp: preference=signencrypt

Hi
W dniu 12.09.2019 o 13:08, Toni Pérez pisze:

Hi,

With nonBroadcast=true the number of probe request with eduroam is increased in areas whrere there are no eduroam service. It affects security by making easier the fingerprinting of users devices (the profiles that are configured in one device). With fingerprinting the next step is a rouge/karma attack.

Is see you point. Changing this globally probably would not do any harm as eduroam is normally broadcasted anyway. We will definitely consider this.

It's true that the user is protected if the supplicant verifies root CA and CN in radius server certificate. But supplicants don't usually give the correct information to users with messages like "there are a problem" or "authentication error" instead "Warning! Malicious eduroam detected, don't try to reconfigure your configuration".

Just a comment on that. With our settings, such messages will only appear when the user tries to connect "manually". Automatic connections do not pop up any failure messages, which is probably the best approach.

Yours

Tomasz

With nonBroadcast=false may be fingerprinting is still possible but with nonBroadcast=true it's true thats is more easier the device fingerprinting.

Greetings,
Toni Pérez

El 11/09/2019 a las 20:38, Tomasz Wolniewicz escribió:

Hi,

   How would disabling this option make security better? A hidden eduroam SSID is stil covered by the security settings for the home RADIUS server, so th client will not connect to a rouge network. With eduroam connections mostly happen without thee user intervention anyway.

Cheers

Tomasz Wolniewicz


W dniu 11.09.2019 o 19:13, Toni Pérez pisze:

Hello!

We can see in Windows 10 profile that nonBroadcast optioin is enabled/true (the option to connect to networks which do not broadcast their network name or SSID).
I have not verified other operating systems.

For security reasons, would it be possible to disable (false) this option in eduroam CAT?

You can verify this option with cmd -->
    netsh wlan show profiles name="eduroam"
    or
    netsh wlan export name="eduroam"


Best regards,

Toni Pérez
Universitat de les Illes Balears

------------------------------------------------------------------------------------

<?xml version="1.0"?>
<WLANProfile xmlns=MailScanner ha detectat un possible intent de frau des de "www.microsoft.com" "http://www.microsoft.com/networking/WLAN/profile/v1">
    <name>eduroam</name>
    <SSIDConfig>
        <SSID>
            <hex>656475726F616D</hex>
            <name>eduroam</name>
        </SSID>
        <nonBroadcast>true</nonBroadcast>
    </SSIDConfig>
    <connectionType>ESS</connectionType>
    <connectionMode>auto</connectionMode>
    <autoSwitch>false</autoSwitch>

.....

------------------------------------------------------------------------------------


-- 
Tomasz Wolniewicz    
          twoln AT umk.pl        http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne   Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika     Nicolaus Copernicus University,
pl. Rapackiego 1, Torun               pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750     fax: +48-56-622-1850       tel kom.: +48-693-032-576
To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
-- 
Tomasz Wolniewicz    
          twoln AT umk.pl        http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne   Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika     Nicolaus Copernicus University,
pl. Rapackiego 1, Torun               pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750                            tel kom.: +48-693-032-576

Attachment: smime.p7s
Description: Kryptograficzna sygnatura S/MIME




Archive powered by MHonArc 2.6.19.

Top of Page