China Releases Own WLAN Security Standard
Lownewulf writes "This NetworkWorldFusion article describes the release of the GB15629.11-2003 wireless networking standard in China, a wireless standard similar to 802.11, but with better security. The IEEE is worried that this may lead to the need to support two different standards in wireless networking hardware." ziggyboy adds a link to CNET's article, noting that
"all wireless devices sold in China are required to comply to this standard from December 1."
While WLAN equipment sold in China is required to comply with this standard from Dec. 1, a transition period has been granted that extends the compliance deadline for some WLAN products until June 1, 2004.
This sounds terribly rushed. How long have they been working on GB15629.11-2003 for (the
These questions lead me to believe that there are two possibilities here:
- B: The Chinese
government is rushing to get beat the IEEE people to make this an
early standard which will make worldwide adoption easier. Now re-read
A and drop the "on its people". Tell me if you feel better.
That all said, you don't need to wait for these committees to finish fighting to harden your wireless LAN. At work we use IPSec over our 802.11[bg] stuff which is all VLAN'd and routed to an outside interface of our Cisco PIX.Trolling is a art,
For most homes/businesses, encrypted wireless doesn't make sense. However, there are plenty of reasons to do encryption (or at least some other type of security measures) at the AP level in higher security situations (military/government stuff).
For instance, suppose you send me an encrypted email that is transmitted over a wireless network at some point in its path. Someone eavesdropping on the wireless almost certainly can't decrypt the message - but they can tell that a message was transferred, and in many cases determine the approximate size of the message. There are certainly some situations where that would be considered a security breach.
If the AP's were security-conscious, however, they could prevent such eavesdropping (for instance by continuously transmitting a signal stream, and splicing the actual transmissions into it). Having this done at the VPN level is less effective, since all the VPN clients would need to be built to ignore the junk data, rather than just the AP's.
Why should I or the Chinese or anyone else care?
Since when did the IEEE become the ultimate authority on standards? It's a USA institution remember. Other countries have their own institutions for this..
And it's not as if the IEEE is the most unbiased institution of them all. Corporate money decides what's a standard more often than not nowadays...
As far as the issue of standards themeselves. Since when do we have to always follow standards, especially others'? If something works better for more people, then bring it on. Progress occurs when breaking with tradition/standards and there is merit to the new system/whatever. Not by blindly following the old standards.
/. Where the truth