Assessing certificate validation user interfaces of WPA supplicants
Kailong Wang, Yuwei Zheng, Qing Zhang, Guangdong Bai, Mingchuang Qin, Donghui Zhang, Jin Song Dong
Abstract
WPA (Wi-Fi Protected Access) Enterprise is the de facto standard for safeguarding enterprise-level wireless networks. It relies on Transport Layer Security (TLS) to establish a secure tunnel during its authentication process, and thus the notoriously error-prone certificate validation may haunt it. Incorrect validation may lead to the SSL/TLS man-in-the-middle attack, or the evil twin attack in the context of wireless networking, where the supplicant connects and unwittingly sends authentication credentials to a fake access point.
We conduct an empirical study on the effectiveness of certificate validation user interfaces (UIs) in WPA supplicants. We focus on a broad variety of mobile devices and mainstream operating systems (OSes), and find that a vast majority of them are susceptible to the evil twin attack. Insecure configuration options and lack of visual security indicators have been found common. Besides, five severe vulnerabilities (four are listed by CVE and one is found in parallel with Google) are identified from their validation processes. By examining the source code of Android's Wi-Fi manager, we link the root causes of these vulnerabilities to the immature designs and implementations of WPA software modules. Our investigation, including a review of Wi-Fi configuration guidelines of the top 200 universities and a realistic experiment deployed in a company with over 50k employees, reveals the user susceptibility in practice. Our findings have been reported to Google, leading to a security enhancement in the WPA supplicant of Android's latest version 11.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7db2fce2-2c7b-49de-9593-53e2d5521318Cited by top-tier papers5
- Are they Toeing the Line? Diagnosing Privacy Compliance Violations among Browser ExtensionsYuxi Ling, Kailong Wang, Guangdong Bai, Haoyu Wang et al.ASE 2022 · 17 citations
- Repairing Failure-inducing Inputs with Input ReflectionYan Xiao, Yun Lin, Ivan Beschastnikh, Changsheng Sun et al.ASE 2022 · 8 citations
- Wemint:Tainting Sensitive Data Leaks in WeChat Mini-ProgramsShi Meng, Liu Wang, Shenao Wang, Kailong Wang et al.ASE 2023 · 8 citations
- SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-FiS. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury et al.CHI 2025 · 2 citations
- A Multifaceted Study on the Use of TLS and Auto-detect in Email EcosystemsKa Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu ChauNDSS 2025
Builds on13
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger et al.USENIX Security 2016 · 192 citations
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 180 citations
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
Related papers
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsXuewei Feng, Qi Li, Kun Sun, Yuxiang Yang et al.S&P 2023
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar et al.USENIX Security 2021 · 45 citations
- All your Credentials are Belong to Us: On Insecure WPA2-Enterprise ConfigurationsMan Hong Hue, Joyanta Debnath, Kin Man Leung, Li Li et al.CCS 2021 · 14 citations
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan et al.USENIX Security 2024 · 7 citations
- Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate ValidationWoonghee Lee, Junbeom Hur, Hyunsoo KwonCCS 2025
