Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] How we deal with [unsecure] devices on eduroam

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] How we deal with [unsecure] devices on eduroam


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Per Mejdal Rasmussen <address@concealed>, address@concealed
  • Subject: Re: [[cat-users]] How we deal with [unsecure] devices on eduroam
  • Date: Wed, 2 Oct 2019 09:17:01 +0200

Hello,

> The bottom line is we don´t care if device credentials are stolen,
> because they only grans access to eduroam - a network shared by
> millions, and same MAC address must be used. There are much easier ways
> to get anonymous network access.

The device MAC address is sent along with the username in RADIUS. An
attacker can trivially steal the entire combination of device-username,
device-password and device-MAC.

Since MAC addresses can be changed on many OSes, the attacker now has a
valid and working credential on his own device of choice.

eduroam is used by millions, yes, but millions of *education and
research* users. If a working credential leaks to unauthorized third
parties, then that is a real concern. Maybe not for you, but for the
roaming consortium as a whole because other hotspots will be able to be
abused by an attacker using that credential.

Also, since the device-username and MAC address are the ones you
recognise as valid, any abuse being done by such an attacker will be
attributed by you to the genuine user. This is a significant concern.
Again, maybe not for you, but for the user in question.

IOW, the only one with the luxury of not having to care about it is the
IdP admin. Everyone else has to live with uneasy consequences of this
mode of operation.

That is why the eduroam policy is very explicit about server-side
validation: you need to instruct your users to configure server-side
validation, and need to supply them with the means to do so (i.e. tell
them about CA and expected server name). This is in section 6.3.2 of the
(European) eduroam Service Definition:

"The server-side EAP credentials MUST be communicated to the user base,
and end-user documentation needs to be precise enough to allow users the
unique identification of their EAP server."

I'm not saying that the configuration you have set up is /per se/ not
compliant with the policy; but it becomes so if you actively tell your
users that they can stop caring about server certificate validation and
the related configuration details. Your statement above that it's
"entirely optional" makes me suspect strongly that you are indeed going
in that direction. Please don't.

Greetings,

Stefan Winter


--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page