4 ms·
Woah, do not get into the habit of putting your wifi network password into a website if you care about security. This particular site might or might not collect
by pathseeker 6y ago
Woah, do not get into the habit of putting your wifi network password into a website if you care about security. This particular site might or might not collect it now but it's a terrible habit to put your sensitive data into another site.
Imagine if this was a web-based password strength meter.
- seesawtron 6y agoTrue. How else would one implement this as a workaround for security? Perhaps a locally running version of the same thing that hopefully doesn't upload the data back to some server? Edit: some users already commented in another thread about pacakges that can do it instead.
- tialaramex 6y agoIn WPA2 and earlier it makes sense to have a WiFi password even if it isn't secret from anyone. Without a WiFi password these versions communicate in plaintext, so a passive adversary can snoop everything, choosing a password switches on encryption and thus protects against passive eavesdroppers. Only in WPA3 do networks with no password get encryption to protect you from passive eavesdroppers. Obviously an active MitM can work regardless, but that's trickier to attempt and unavoidably subject to detection. If you "care about security" in the sense of not wanting random people to connect then you should not use "Personal mode" which is garbage in all versions of WPA because it relies on a shared human memorable password and (say it after me) human memorable passwords are garbage. Use whichever of the terrible 802.1x alternatives best fits your scenario, as these authenticate specific users rather than relying on a single shared password. You can federate to allow large groups of people with something in common to all use all the networks in the federation. For students (and academic staff) most tertiary education sites in the world now offer Eduroam for example. Or, give it all up as a bad job, and (with the caveat at the top about preventing passive eavesdropping) just stop trying to fence off your network and accept that it's the Internet and you'll need a BeyondCorp / Zero Trust security model.
- unethical_ban 6y agoI think the OP was saying that it is not a good thing to encourage people inputting their personal passwords to untrusted websites. They weren't commenting on the need to put passwords on wifi networks.
- Dylan16807 6y ago> I think the OP was saying that it is not a good thing to encourage people inputting their personal passwords to untrusted websites. I dunno, the comment clearly says you shouldn't be putting wifi network passwords into websites, not passwords in general. > They weren't commenting on the need to put passwords on wifi networks. The thesis of the reply was "it makes sense to have a WiFi password even if it isn't secret". That's directly about whether it's okay to put a wifi password into a website.
- deleted 6y ago[deleted]
- h4waii 6y agoWPA doesn't rely on a "human memorable password". You can generate a random 63 character string to use. The point of QR for this is to be able to actually share that high entropy 63 character string so you don't have to use a "human memorable password".
- tialaramex 6y agoFair point. Thanks.
- tjbiddle 6y agoHaha, my first thought as well. Went ahead and just starred the Github page and I'll run it locally if I ever care to use it.
- lozf 6y agoYou can use `qrencode` on your local machine. https://github.com/fukuchi/libqrencode https://github.com/fukuchi/libqrencode