Re: [Captive-portals] Thoughts/comments on draft-nottingham-capport-problem-01

"Roscoe, Alexander" <Alexander_Roscoe@cable.comcast.com> Tue, 05 April 2016 14:49 UTC

Return-Path: <Alexander_Roscoe@cable.comcast.com>
X-Original-To: captive-portals@ietfa.amsl.com
Delivered-To: captive-portals@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8248112D590 for <captive-portals@ietfa.amsl.com>; Tue, 5 Apr 2016 07:49:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Vfkqi-9ajaTa for <captive-portals@ietfa.amsl.com>; Tue, 5 Apr 2016 07:49:32 -0700 (PDT)
Received: from pacdcmhout02.cable.comcast.com (pacdcmhout02.cable.comcast.com [68.87.96.15]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 61CC812D154 for <captive-portals@ietf.org>; Tue, 5 Apr 2016 07:49:32 -0700 (PDT)
X-AuditID: 4457600f-f79406d0000020fe-f7-5703d07bf259
Received: from PACDCEX38.cable.comcast.com (cas-umc02.ndceast.pa.bo.comcast.net [68.87.34.28]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by pacdcmhout02.cable.comcast.com (SMTP Gateway) with SMTP id CA.80.08446.B70D3075; Tue, 5 Apr 2016 10:49:31 -0400 (EDT)
Received: from PACDCEX33.cable.comcast.com (24.40.2.132) by PACDCEX38.cable.comcast.com (24.40.2.137) with Microsoft SMTP Server (TLS) id 15.0.1130.7; Tue, 5 Apr 2016 10:49:30 -0400
Received: from PACDCEX33.cable.comcast.com ([fe80::3aea:a7ff:fe36:8984]) by PACDCEX33.cable.comcast.com ([fe80::3aea:a7ff:fe36:8984%19]) with mapi id 15.00.1130.005; Tue, 5 Apr 2016 10:49:30 -0400
From: "Roscoe, Alexander" <Alexander_Roscoe@cable.comcast.com>
To: Martin Thomson <martin.thomson@gmail.com>, Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [Captive-portals] Thoughts/comments on draft-nottingham-capport-problem-01
Thread-Index: AQHRjo674JqCqEOtjECKeQPGgWyfSZ96aaEAgAAhSICAAP11gA==
Date: Tue, 05 Apr 2016 14:49:29 +0000
Message-ID: <D32954BC.1B2E5%alexander_roscoe@cable.comcast.com>
References: <D328543E.51AC4%adam.cohen-rose@sky.uk> <17765.1459795394@obiwan.sandelman.ca> <CABkgnnUwB99O-gQfi9j2C=doBSVcf1bHdmhX=zV2C31huGVj0w@mail.gmail.com>
In-Reply-To: <CABkgnnUwB99O-gQfi9j2C=doBSVcf1bHdmhX=zV2C31huGVj0w@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [96.115.73.253]
Content-Type: text/plain; charset="euc-kr"
Content-ID: <B691E5F75FD80A4893803B74176E3F99@cable.comcast.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Forward
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrLIsWRmVeSWpSXmKPExsXiEq4ko1t9gTnc4FirpMXnbZtZLebOamC1 uHbmH6NFz6F+dgcWj52z7rJ7LFnyk8mjZc4eZo/mJVdYA1iiuGxSUnMyy1KL9O0SuDJOTFzP XLBLoOJ581O2BsYWgS5GTg4JAROJ3pdvGCFsMYkL99azdTFycQgJbGeS2Nbaxwrh7GSUOPfn DFTmBKPEk7Z2IIeDg03ATmLhPkeQbhGBaIl9j+4zg9jMAhkSq1+9B7OFBSIltp56wQxREyXx +GU3O4TtJLFp72ewOIuAisT/prmsIDavgL1Ex7UNTBC7FjNKTNv5hgUkwSkQKLHnLoTNCHTq 91NrmCCWiUvcejKfCeIFAYkle84zQ9iiEi8f/2OFsHUkzl5/AvWmgcTWpftYIGxFiX0fVkAd rSXx5cc+sL+YBRwkGpexQIQVJaZ0P2SHuE1Q4uTMJ1Ct4hKHj+xgncAoPQvJFbOQTJqFMGkW kkmzkExawMi6ilGuIDE5JTk3I7+0xMBILzkxKSdVLzk/NzmxuAREb2IEJ4IE/h2MR6d7HGIU 4GBU4uFl3M8cLsSaWFZcmXuIUYKDWUmEV/4sUIg3JbGyKrUoP76oNCe1+BCjNAeLkjjvucP/ woQE0hNLUrNTUwtSi2CyTBycUg2MAtNSd7TrLXqjG7Wl56TXc78gnwclUXet5N9cqz0SyL3g YsKfi04lP2Y82Z+hE/RgvozFHTFFTTOW+++qG838OydoGbX8O5aQIv17xZfeLVOfaFyeV+Jy OWLW9fqdv3x2604Qtzlhd9TrmIljnv0BLrNJS3I/h4ewL5h9IePnb8/fx1p8H32wV2Ipzkg0 1GIuKk4EAGpO9zwAAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/captive-portals/XQsKC9axZfE1rXvjxbCQam99_UY>
Cc: "Cohen-Rose, Adam" <Adam.Cohen-Rose@sky.uk>, "captive-portals@ietf.org" <captive-portals@ietf.org>
Subject: Re: [Captive-portals] Thoughts/comments on draft-nottingham-capport-problem-01
X-BeenThere: captive-portals@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Discussion of issues related to captive portals <captive-portals.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/captive-portals/>
List-Post: <mailto:captive-portals@ietf.org>
List-Help: <mailto:captive-portals-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Apr 2016 14:49:35 -0000

On Comcast’s open wifi deployment we make our best attempt to upgrade
security upon authentication on our captive portal page.  After a
successful login,  we have unique flows for each operating system that
deliver secure profiles to the client for installation.  This is very hard
to maintain and QA test as the operating systems’ sandbox gets more strict
on each iteration.    I do not know if its this is a problem we need to
address immediately but it s something we need to think about as we
transition into secure phy layers.


-- 
Alexander Roscoe
Comcast - Wireless Engineer
Phone ­ 215.286.7283
Cell ­ 215.609.2691





On 4/4/16, 5:42 PM, "Martin Thomson" <martin.thomson@gmail.com> wrote:

>On 4 April 2016 at 15:43, Michael Richardson <mcr+ietf@sandelman.ca>
>wrote:
>> So, a URL-scheme that could contain a pointer to the other SSID.
>
>You mean something I could put on my webpage that, if clicked, would
>cause a device to connect to the identified SSID?  That might be less
>than good.  I thought that Adam was talking about plain ol' text, but
>maybe he can confirm.
>
>>     > I¹m very happy to contribute towards an industry survey and will
>>keep
>>     > following the discussion in the mailing list.
>>
>> I'm super-happy to have you on the list.
>
>Likewise.  It's good to have this sort of perspective.
>
>_______________________________________________
>Captive-portals mailing list
>Captive-portals@ietf.org
>https://www.ietf.org/mailman/listinfo/captive-portals