6 ms·
Trying to deploy WPA3 on my home network
- alexandernst 8y agoSynology Routers support WPA3 by default
- maxyme 8y agoThey also support a mode where they will use WPA3 when supported and fall back to WPA2 when there isn't device support.
- chaosite 8y agoThat's just WPA2 with extra steps.
- Spivak 8y agoI mean from a security standpoint you're right, but having opportunistic WPA3 seems to be the only sensible way to deploy until you reach acceptable device support.
- duckerude 8y agoWouldn't you keep (much of) the advantages of WPA3's forward secrecy?
- IshKebab 8y agoNot really - if all of your devices use WPA3 the attacker won't be able to brute force your password for example. You might think "if all your devices support WPA3 then why not disable WPA2?". The obvious reason is you might occasionally want to use WPA2 without fiddling around with router settings, e.g. if guests want to use your WiFi without recompiling their phone's kernel. Then another obvious but naive response is "then your security is no better than WPA2 anyway" but hopefully it's clear why that isn't the case in the real world.
- voltagex_ 8y agoWorried enough about security to deploy WPA3, but still uses a Galaxy S2? Even with LineageOS, aren't you still using ancient device drivers?
- cbhl 8y agoDevice drivers don't usually need to be updated unless the driver interface changes (i.e. when you update the Linux kernel) or the driver needs to be updated to accommodate quirks of new software (i.e. graphics drivers and new video games). They probably do want to be getting the latest security patches to the kernel and base OS.
- jtl999 8y agoI remember the creator of CopperheadOS claiming the "Nexus 5" (which is EOL) is not secure because of hardware (baseband?) vulnerabilities that wouldn't be trivial to fix. Citation: https://twitter.com/DanielMicay/status/1058103333414522880 https://twitter.com/DanielMicay/status/1058103333414522880
- lclarkmichalek 8y agoI think he's more saying that Nexus 5 is not secure going forwards because the firmware for the hardware is not getting updates. I can't see any reference to specific vulnerabilities, but when a platform is complex they're bound to exist. When you combine that with not getting updates, you have an insecure platform.
- ghusbands 8y agoThe firmware for the Nexus 5 wifi chip has well-known remotely-exploitable code-execution vulnerabilities [1] that were never patched. Nearly all modern devices have a full software stack inside the wifi (and other radio) chips and they all have plenty of security flaws and they're all proprietary and unaffected by the OS. So it's not just about it not being secure going forwards. It and most other similar age handsets are insecure because a fix has never been released for the older chips. [1] https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html https://googleprojectzero.blogspot.com/2017/04/over-air-expl...
- AlyssaRowan 8y agoUse WPA3-Enterprise (you can use Let's Encrypt to get a valid certificate so it works fine in a home environment). Don't use SAE (which is, indeed, an instantiation of Dragonfly). I have a strong suspicion that the way it is used, there will be a practical attack.
- zokier 8y agoOr just use WPA2-Enterprise, afaik there are no pressing security needs to upgrade to WPA3 if you are using EAP, and it is widely supported out of the box
- xenithorb 8y agoThe problem with this I found for home use is that IoT devices don't typically support enterprise modes. And without PSK you just flat-out can't use those devices with WiFi
- zokier 8y agoStill, I imagine lot more devices support WPA2-EAP over WPA3-EAP that OP recommended.
- deleted 8y ago[deleted]
- mey 8y agoCan you provide any more info on your concerns about SAE?
- zokier 8y agoHere is some background reading: https://news.ycombinator.com/item?id=6942145 https://news.ycombinator.com/item?id=6942145 https://news.ycombinator.com/item?id=7017160 https://news.ycombinator.com/item?id=7017160
- tgsovlerkhgsel 8y ago
- deleted 8y ago[deleted]