AES encrypted passwords

Alan DeKok aland at deployingradius.com
Fri Sep 30 14:57:44 CEST 2016


On Sep 30, 2016, at 6:53 AM, freeradius-users at latter.org wrote:
> However I have just looked at the instructions we give to users
> wishing to connect their Windows 8 machine to the wifi network
> and have seen this:
> 
> - Untick “Verify the server’s identity by validating the certificate”

  Which means that you have no security.

  This is MUCH worse than storing clear-text passwords in the database.

  I really wish that amateurs would stop trying to design security systems.  They get most things wrong.

  Alan DeKok.




More information about the Freeradius-Users mailing list