3 ms·
One issue with WPA2 Enterprise is the client user interface. It's hard for users to configure the correct settings because there is no feedback about configurat
by keeperofdakeys 6y ago
One issue with WPA2 Enterprise is the client user interface. It's hard for users to configure the correct settings because there is no feedback about configuration issues - wrong EAP mode - vs credential errors - wrong user password. All you get is a "Can't connect".
There is also the problem of so many eap modes. There are some interesting EAP modes that have come along - like EAP-PWD - that remain unimplemented on major platforms, and are basically unusable. So you're left with EAP-TTLS with PEAP and MSCHAPv2 (stores passwords weakly), or EAP-TLS with client certificates. And no one wants to manage client certificates if they can help it.
Both of the above make WPA2 Enterprise on BYO devices quite a challenge.
- amaccuish 6y agoI agree totally. My phone company gives me access to their hotspots using EAP-SIM/AKA, which is really useful, but there's no way for an AP to advertise the EAP methods they support which sucks. And EAP-PWD is awesome but like you said, rarely implemented. There's also EAP-GTC which I think allows you to do secure password auth as well. We currently use PEAP with MSCHAPv2 since the user credentials are protected in transport and our domain controllers are pretty secure, but it'd be nice to be more flexible.
- tialaramex 6y agoEAP-PWD seems like a weird thing to want. It's probably incrementally better than WPA2-PSK if you actually have a small number of users who can keep the secret (or in a home network with no guests) and if you use a decent secret, but that's a pretty narrow scenario. It's not obvious that you're better off security-wise with EAP-PWD than you'd be on WPA3-PSK for example, the UX for PSK is better, and the compatibility story for WPA3 is probably acceptable today, so there's no reason to want EAP-PWD now even if it might have been better than the status quo five years ago. MSCHAPv2 is garbage but that's Microsoft's fault, and the uncomfortable reality for almost any medium or large organisation will be that there is a bunch of Microsoft stuff and so whatever crap they shovelled into Windows is what you have to put up with. The more I think about "evil twin" and read/ re-read this thread, the more I think maybe the most attractive new-build answer is throw away WPA2 Enterprise in favour of WPA3 with no password†, then do BeyondCorp / ZeroTrust and defend your systems at their edge not by hoping a poorly defended WiFi network or VPN saves you from doom. †In WPA3 networks with no password are still secured against passive adversaries, so the UX is nicer but it's just as safe as having a WiFi PSK that inevitably is easy to find out. And unlike MSCHAPv2 it doesn't let bad guys harvest all your users' credentials for the price of a DES cracker.