Lab Notes
Musings on Wi-Fi security issues, our product plans, and the general state of the world. Follow up with your comments and complaints to Lab Notes's .
PARC: Wi-Fi PKI Usability Stinks
The title actually paraphrases Drs. Balfanz, Durfee, Smetters, and Grinter, but the gist is correct: managing your Wi-Fi PKI is nigh impossible. We've been seeing this here at the Labs from the beginning — from day one, the vast majority of our technical support questions have been certificate-related.
PARC conducted the study on Wi-Fi PKI usability, "In Search of Usable Security: Five Lessons from the Field." [PDF] two years ago. They asked expert computer users to try to configure their Windows XP machines to connect to the PARC Wi-Fi network:
Once the wireless network and the PKI were in place, our HCI researcher studied eight subjects’ enrollment experiences. All the subjects had advanced degrees, typically PhDs in computer science and related disciplines, but the average time it took for them to request and retrieve their certificates and then configure their systems was 140 minutes. More significantly, despite using a fairly automated Web-based enrollment system (similar to those used by commercial certificate vendors such as Verisign) and the GUI-based 802.1x wireless configuration software provided by Microsoft Windows XP, the process involved a total of 38 steps to complete enrollment.
Executive summary: "We took a bunch of computer science Phd's, gave them explicit step-by-step instructions, and it still took them over two hours to complete the configuration task, and in the end they didn't know what they had just done to their computers."
Microsoft is clearly aware of the problem, as they modified the Wi-Fi network enrollment process in Vista to suck slightly less. They've still got a long way to go, though. Personally, I'm a fan of the Mac OS X process: just connect to the network, the Mac asks "hey, I've never seen this certificate before, should I trust it?" and you're off. Clearly, Apple is on to something. Of those technical support questions I mentioned above, a lot of them start with "Help: my Macs connect to my Elektron-secured network just fine, but my Windows XP machines refuse to connect!" We've never once received the opposite.
Search
Recent Entries
Elektron 2.0.2118
Creating a Rogue CA Certificate
Major Privilege Escalation Bug in Mac OS X 10.4 and 10.5
Overheard at the WWDC Keynote
iPhone 2.0 to Include 802.1X
Time Capsule
New Xserves
Mac OS X 10.5.1
Elektron and Leopard
Elektron 2.0.1755
Monthly Archives
February 2009 (1)
December 2008 (1)
June 2008 (2)
March 2008 (1)
January 2008 (2)
November 2007 (1)
October 2007 (1)
September 2007 (1)
August 2007 (1)
July 2007 (8)
June 2007 (16)
November 2005 (8)
October 2005 (13)
September 2005 (22)
August 2005 (23)
July 2005 (21)
June 2005 (26)
May 2005 (23)
April 2005 (23)
March 2005 (25)
February 2005 (23)
January 2005 (29)
December 2004 (32)
November 2004 (32)
Subscribe to Lab Notes
Elektron® is a registered trademark of Periodik Labs LLC
Leave a comment