Educause Security Discussion mailing list archives

Re: Wireless SSIDs (was Re: WEP)


From: "Christopher E. Cramer" <chris.cramer () DUKE EDU>
Date: Wed, 13 Jul 2005 12:00:56 -0400

my understanding is that there is one single SSID for the campus which is
broadcasted.  there may be some other SSIDs that I am unaware of, but for
the most part, we don't rely on the SSID for anything other than
identifying/specifying which wireless network you have attached to.
since we aren't relying on ssids for access control, this isn't a problem.

on a related note, i was in a space that had wireless, but the ssid wasn't
being broadcast.  someone came in with a mac and it "helpfully" detected
the non-broadcast ssid and attached itself to the wireless network.  just
something to consider :)

-c

On Wed, 13 Jul 2005, Jeff Kell wrote:

Christopher E. Cramer wrote:

Regarding access control, it seemed to us that a "shared secret" between
the 30,000+ people at the institution, wasn't much of a secret and so the
access control capability wasn't too useful.

On a more fundamental level, how do you have SSIDs setup?

*  Do you have separate SSIDs for "public", "student", "fac/staff", etc?
*  Do you broadcast all of them, or just certain ones.
*  How do you disseminate information about non-broadcast SSIDs to users?
*  Do you periodically change SSIDs of non-broadcast domains?

We are currently debating this issue, haven't gotten around to
encryption yet, but it is obviously on the table.  Granted that a
"shared secret" or a "private SSID" between numerous users is hardly a
secret, but if you broadcast, isn't that somewhat akin to an open door?

Jeff


Current thread: