Jump to content

Recommended Posts

Posted

I've been asked whether when guests want to use our guest wifi then they could just scan a QR code.

Upon googling I see many QR Code makers including this one: https://www.qr-code-generator.com/solutions/wifi-qr-code/

 

So this would let a user scan the QR code and get onto our Wifi.

 

Can anyone see anything wrong with this or any security issues?

 

From what I see it simply generates a QR code with SSID, and password.

 

 

What do you think??

 

Thanks.

Posted
I used this site or similar to create one for when friends come around, the only thing that I have spotted it that they can see the details on some phones before joining but its a quick easy way. If it was me in a corporate/school environment I would be using a captivate portal for authentication.
  • Thanks 1
Posted

This is possible, depends on your WiFi system

 

 

Can anyone see anything wrong with this or any security issues?

 

Any tom dick or harry could scan the code and join your wifi, no audit log of who's on it.

 

We take the name of whoever joins the network for logs of who's on our system

  • Thanks 1
Posted

Thanks all.

 

I was thinking of giving it to the office and then they can give it out once they've met the visitors. It won't be on display to everyone.

Posted
Thanks all.

 

I was thinking of giving it to the office and then they can give it out once they've met the visitors. It won't be on display to everyone.

 

Can you not give them a login to the WiFi system that only has access to the guest pass creation? That's what our reception has and explained to them the guidelines on adding someone to the wifi

  • Thanks 1
Posted
Another take on it might be to have a QR code (or a friendly URL) on the wall that links them to a publicly available page containing your onboarding instructions, with directions to get a passcode from reception, or whatever.
Posted

In a school, I would want 100% accountability. Goes for business environments too, but school has a fair bit of safeguarding around it.

 

Lets say for absolute arguments sake, you have someone with a less than desirable link on their end that triggers an IWF/Home office alert, it happens.

 

The ISP and yourselves are likely going to be asked a few questions... one of those would be 'who went to this'. I'd not want to be the one to say I don't know!

 

In short, whats wrong with a first and last name visitor pass. Depending on the wifi/sign in system at the school, you could integrate that with a 1 time use QR/user+pass which links to that user and boom, user tied to IP, date and time in your logs which you obviously back up and maintain within GDPR regulations. When someone comes knocking, I'd want the answer to be available because they do knock!

 

Thats a worst case scenario in my eyes, especially when it comes to any child protection/RIPA requests!

 

 

As above though, a QR to a captive portal with first/last/number or something... they could lie, but you've "done your bit"

Posted
You're assuming the original person has some kind of per person guest wifi already set up, if that were the case they wouldn't be asking this question

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...