Hacker News new | ask | show | jobs
by dimdimdim 3825 days ago
45% Insecure WiFi traffic? at a Hacker Conference? :)
2 comments

Why? I long made a point of only running "insecure" network layers at home. I sincerely believe in the stupid network, and that any security belongs above the transport.

Using the term for wireless networks at home really drives the point home that you're supposed to get your personal connection and buy your own access point, so that IP addresses finally can represent identity. That is not a coincidence.

I was with you until "so that IP addresses finally can represent identity".

You don't mean actual (personal/account) identity, do you? IP addresses represent a location for delivery and they definitely identify a network interface, but that's the extent of goals for IP addressing. Courts have supported this view and I think that's a good thing. Sorry if I read too much into what you said. EDIT: spelling.

Keep in mind though, that once your Layer 2 is hijacked, a lot of attacks are possible before upper layer security kicks in - things like browser redirection and exploitation are very common these days
Please take note of this folks. Simply trusting "transport security" isn't enough. Please do not seriously run an open access point because you think it's just as safe as the OP.
I agree. Highly assured systems of the past and recent academia built security on untrusted networks, storage, etc. Standards like Wifi are too broken to trust anyway. Best to depend on something at a higher level.

Note: WiFi security is useful for filtering out the riff raff for availability & performance reasons. :)

I'll wager there are more than a few honey pots