Security Basics mailing list archives

Re: wpa2-psk aes


From: thinkofit () gmail com
Date: 23 Feb 2011 09:11:14 -0000

On 02/22/2011 06:35 PM, marco gregorio wrote:
I actually would like to dig further into your issue, do you want to
make each peer secure from each other, or you want the partecipants to
be securely isolated from external intrusion?

hi,

the project's aim is to keep secure each participant from each other and, of course, from external intrusions.
 
Using a PSK eases from using a pki infrastructure in order to have a
safe key exchange.
The point is: authentication.
Diffie helmann exchanges keys but it's peer authentication-less: discarded.
The way is key exchange through RSA  (SSL does it).
The use of a psk assumes that who knows the psk is trusted, as soon as
the AES takes place, the key is recalculated over again, so just take
the PSK as a secure way of beginning the session.

so, my understanding is that using a wpa2-psk scheme with the key being known by participants would keep the meeting 
room secure from external intrusion but a peer vs peer intrusion could still be possible.

now, the only viable solution for that scenario is 802.1X standard: it should keep safe each participant from other 
participants and from external intruders.

thank you
-- 
antonio

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: