No protection against "evil twin" (same-named) wi-fi networks

Bug #1258496 reported by Antti Kaijanmäki
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
indicator-network (Ubuntu)
Triaged
Wishlist
Matthew Paul Thomas

Bug Description

Currently the indicator only shows whether or not a wireless network is secured, by showing a padlock.

In a situation where we have two accesspoints which both have the same ESSID (name) but different encryption (e.g. WEP vs. WPA) they provide two separate networks. Now the indicator shows two identical items and the user has no way of figuring out which is which.

Above scenario is a very rare one, but still completely valid.
Neither nm-applet or macosx networking menu bother to deal with this situation, they just show two identical networks, but Android is always showing the encryption scheme beneath the network name.

We can either
A) do nothing
B) always have the encryption type visible somehow
C) be smart about it and only show the encryption type when we detect that the name and padlock is not enough

Changed in indicator-network:
assignee: nobody → Matthew Paul Thomas (mpt)
importance: Undecided → Low
Revision history for this message
Matthew Paul Thomas (mpt) wrote :

My first instinct is just to use "{network name} ({encryption type})" whenever there's more than one network with the same name.

I wonder if we can do anything here to protect against social engineering attacks. I could camp outside a company office and set up a network with the same name but different encryption method. A device connecting automatically to the previous network would be safe. But a new employee, told to connect to "Yoyodyne" and confronted with a choice between "Yoyodyne (WPA2)" and "Yoyodyne (LEAP)", could easily try the wrong one -- and now I've captured the password to the company's real network. Has this problem been dealt with before?

Revision history for this message
Tony Espy (awe) wrote :

I took the liberties to change the Importance to Wishlist as it's really a new feature request.

Changed in indicator-network:
importance: Low → Wishlist
status: New → Confirmed
Ted Gould (ted)
Changed in indicator-network (Ubuntu):
assignee: nobody → Matthew Paul Thomas (mpt)
importance: Undecided → Wishlist
status: New → Confirmed
Pete Woods (pete-woods)
no longer affects: indicator-network
Revision history for this message
Matthew Paul Thomas (mpt) wrote :

It turns out that the attack I described is called the "evil twin". <http://en.wikipedia.org/wiki/Evil_twin_%28wireless_networks%29>

Antti, if you don't mind, I'll retarget this bug report towards thwarting that attack. Showing the encryption type would not be a complete solution to disambiguating identically-named networks, whether they were coincidental or malicious.

summary: - show wireless encryption type
+ No protection against "evil twin" (same-named) wi-fi networks
Changed in indicator-network (Ubuntu):
status: Confirmed → Triaged
Changed in ubuntu-ux:
assignee: nobody → Matthew Paul Thomas (mpt)
status: New → Triaged
Revision history for this message
Matthew Paul Thomas (mpt) wrote :

See also bug 1258496, asking for the opposite: showing multiple networks with the same name as a single item even if they offer different authentication methods.

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

From JkB in <https://code.launchpad.net/~joergberroth/ubuntu-system-settings/wifi-802-1x-configurations/+merge/261920>: "To my understanding, the advantage of WPA Enterprise networks is that you can be sure to connect to the right access point, if it carries a valid certificate (or let's say it's way harder to build an "evil twin"
as you don't own the cert). For example, the University of Bergen works with certificates, <https://eduroam.no/connect/?institution=535;profile=1751;os=linux> but not as a must have. <https://it.uib.no/en/Eduroam_for_Linux> There seems to be an older auth scheme as well."

John Lea (johnlea)
summary: - No protection against "evil twin" (same-named) wi-fi networks
+ [System Settings] No protection against "evil twin" (same-named) wi-fi
+ networks
Changed in ubuntu-ux:
importance: Undecided → Wishlist
summary: - [System Settings] No protection against "evil twin" (same-named) wi-fi
- networks
+ No protection against "evil twin" (same-named) wi-fi networks
no longer affects: ubuntu-ux
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.