EAP-TLS: Secure Authentication Explained
ID: 7a55ac11-d9bd-571b-b5c2-fdf4c938f30d
STIX ID: report--7a55ac11-d9bd-571b-b5c2-fdf4c938f30d
Feed Name: NCC Research
This blog assesses EAP-TLS security, highlighting two main weaknesses: username enumeration through EAP-Response/Identity and misconfigured or disabled server-certificate validation that enables evil-twin (rogue AP) attacks. The author demonstrates how attackers can harvest usernames and impersonate enterprise Wi‑Fi when clients accept untrusted certificates or fail to validate server names, documents Windows-specific behaviors and prompts that exacerbate the risk, and recommends mitigations (privacy NAI, computer authentication, enforce server validation, restrict trusted CAs) to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
