3 ms·
I think you could even take this one step further: Have a captive portal on an unencrypted channel (using TLS obviously) to do the vending, so that the credenti
by labcomputer 3y ago
I think you could even take this one step further: Have a captive portal on an unencrypted channel (using TLS obviously) to do the vending, so that the credentials don’t need to be purchased before the flight.
- lxgr 3y agoOh, these are neat ideas, I hadn’t thought of that! One concern might be expiring access credentials (not sure if most OSes will re-prompt for a new password or just give up), but you could just make the EAP credentials per-user instead and redirect users to the captive portal again once needed. This leaves clients not supporting WPA-EAP, but these could just continue using the regular unencrypted/MAC-authenticated service.
- yub 3y agoThat’s what Passpoint (aka Hotspot2)’s Online Sign Up is supposed to do. Main network is protected by WPA2/3-Enterprise (aka EAP), and there’s the OSU open network where you can get signed up and get a profile installed for the full main network. And every modern device supports EAP these days.
- MBCook 3y agoYou might be able to just do the sign up on the in-flight entertainment system and have the user scan the resulting WR code. Only works with IFE equipped planes, of course.
- eru 3y agoWell, the customer also needs to futz around with scanning a WR code, and get it from the device she scanned it on to the device she wants to use the wifi on (if they ain't the same.) Though you could route around these problems, but giving them both a scannable code, and underneath some credentials as plain text they could type.