AES encrypted passwords
Alan DeKok
aland at deployingradius.com
Fri Sep 30 14:57:44 CEST 2016
On Sep 30, 2016, at 6:53 AM, freeradius-users at latter.org wrote:
> However I have just looked at the instructions we give to users
> wishing to connect their Windows 8 machine to the wifi network
> and have seen this:
>
> - Untick “Verify the server’s identity by validating the certificate”
Which means that you have no security.
This is MUCH worse than storing clear-text passwords in the database.
I really wish that amateurs would stop trying to design security systems. They get most things wrong.
Alan DeKok.
More information about the Freeradius-Users
mailing list