Educause Security Discussion mailing list archives

Re: Wireless SSIDs (was Re: WEP)


From: Jeff Kell <jeff-kell () UTC EDU>
Date: Wed, 13 Jul 2005 09:45:29 -0400

Christopher E. Cramer wrote:

Regarding access control, it seemed to us that a "shared secret" between
the 30,000+ people at the institution, wasn't much of a secret and so the
access control capability wasn't too useful.

On a more fundamental level, how do you have SSIDs setup?

*  Do you have separate SSIDs for "public", "student", "fac/staff", etc?
*  Do you broadcast all of them, or just certain ones.
*  How do you disseminate information about non-broadcast SSIDs to users?
*  Do you periodically change SSIDs of non-broadcast domains?

We are currently debating this issue, haven't gotten around to encryption yet, but it is obviously on the table.  
Granted that a "shared secret" or a "private SSID" between numerous users is hardly a secret, but if you broadcast, 
isn't that somewhat akin to an open door?

Jeff

Current thread: