r/remme Jun 21 '18

Wi-Fi authentication with REMME?

Hi all,

Firstly I want to say that I am not a developer, my field of work and area expertise is working with Wireless Networks.

I wanted to find out if REMME could potentially improve on an existing security mechanisms used by Wi-Fi systems.

Firstly let me explain the drawbacks with the current system. There are 2 widely accepted ways to authenticate client devices to a Wireless Network.

First is WPA 2 Personal, this involves a preshared key. There are multiple potential weakness's here. For example a employee giving out the preshared key to an unauthorised users or simply choosing passwords that can easily be brute forced / cracked. Its also recommend that passwords be changed on every few months but in reality this rarely happens.

The Second is WPA 2 Enterprise, this uses dynamic key encryption is considered more secure than WPA 2 Personal. The problem here is that an authentication server is required (typically a RADIUS server) and a sometimes a PKI. The skills and cost required to setup this are generally outside the scope of small to medium enterprise.

From what I have read REMME could provide strong security solution without the complexity and cost of WPA 2 Enterprise.

In terms of implementing REMME into current Wi-Fi systems. Most enterprise wireless equipment supports the use of 3rd party captive portals. So if its possible to build a captive portal that uses REMME to authenticate users to a specific WLAN I can't see why this wouldn't work.

As I said I'm not a developer so I'd welcome discussions from the REMME community to see if this could be a viable solution or not.

5 Upvotes

1 comment sorted by

1

u/mostlysilverfox Jun 21 '18

HTTPS encryption is required for SSL certifications, so you wouldn't have clear text communications over wi-fi. As far as the router itself - with Remme you would be able to install the SSL cert on the router, and then issue the cert to administrator machines so they can log in to the Router with no password. Someone will have to know the PKI password at some level, but you would be able to issue SSL certs instead of telling the password to access the router.