After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 541257 - NM should not connect automaticly to unsecured network which was formerly a secure one
NM should not connect automaticly to unsecured network which was formerly a s...
Status: RESOLVED FIXED
Product: NetworkManager
Classification: Platform
Component: general
unspecified
Other Linux
: Normal major
: ---
Assigned To: Dan Williams
Dan Williams
Depends on:
Blocks:
 
 
Reported: 2008-07-02 14:17 UTC by newsScott
Modified: 2009-02-04 15:07 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description newsScott 2008-07-02 14:17:35 UTC
I have an access point using PSK encryption. NetworkManger works as expected. The key has been saved and after every system startup NM automatically established a connection to the encrypted network.

Now it happens that i completley switched of encryption by mistake. After the next reboot, NM established the connection to the unsecured network without any warning. In my opinion this is a security problem. I can think of two scenarios:

* You are allowed to connet to a secured network and trust all other participants on that network. Now, by mistake, the encryption is disabled by the network administrator. You still send confidential data over the network without knowing that everybody can evesdropping.
* Maybe this problem is also usable for an active attack: Is it possible to provide an access point with the same ssid / (MAC?) in a way, that it 'shadows' the proper access point?

Once a connection was established to a encrypted network, there should at least a warning if that encryption no longer exists (changed?).
Comment 1 Dan Williams 2009-02-04 15:07:51 UTC
NM 0.7 will not connect to an incompatible network; thus if you connected first with security enabled, that will not be automatically reconnected to if the AP's security is dropped.  The user would have to manually choose the AP again from the menu.