Archives

Date

Support public/private in 802.11 access points

Almost everybody has a WiFi (802.11) access point these days. Some leave them open by accident, some deliberately, some turn on encryption or other security. Being open can be nice to neighbours and wanderers, though it can also be abused, and if you have insecure machines on the local NAT, it's risky.

I propose pushing home NAT/WiFi boxes to, by default, work in both open and closed modes. They would support two NAT networks, independent of one another. One network would be for inside. Connecting machines on the inside network would need the WEP encryption key, or in lesser-security mode, be on the approved MAC list. Machines without the authentication would go on the external, open network.

The two networks might have two different SSIDs if the box can broadcast both of them, or it might be easier to have one broadcast SSID and one non-broadcast one.

Traffic for the external network would be given low priority, so that internal network use is never slowed by external use.

In other words, other than ISP complaints, there would be no reason not to do this. It would be good for giving access to visitors to the home or office, and also mean free wireless almost everywhere in the world.