Slashdot Mirror


Risk Management of Wireless Networks

An anonymous reader writes "As wireless becomes a bigger part of our networks, those of us charged with maintaining them find ourselves also responsible for keeping drive-by script kiddies with a Pringles can out. BankInfoSecurity.com is running an excellent article on identifying and mitigating risks on wireless networks. The article was written by members of the Office of the Comptroller of the Currency (OCC) for banks, but it's applicable to any network environment and clearly lays out all the key steps to protecting wireless systems." There's nothing new here, really, but it's a good overview of issues to keep in mind when building a wireless net, as well as a good security plan starting point.

109 comments

  1. Banks? by Anonymous Coward · · Score: 5, Insightful

    I'm sorry, but banks should not be using wirless networks. Yes, yes, I realize wires are inconvenient, but they are much more secure. This is the customer's money and lives they're dealing with, not just some company secrets.

    1. Re:Banks? by kalislashdot · · Score: 3, Informative

      I work at a bank and Wireless networks are a no no. We have none in our offices. People us them at home, including me, but we use VPN to remote in so it is all good.

    2. Re:Banks? by Aliencow · · Score: 2, Interesting

      So why not having to VPN in from the Wifi network ? What would be the difference from being at home on a crappy Linksys access point ?

    3. Re:Banks? by flok · · Score: 1

      I really hope those banks use SHIELDED cables then(!)

      --

      www.vanheusden.com - home of Multitail, HTTPing, CoffeeSaint, EntropyBroker, rsstail, bsod, listener, nagcon, nagi
    4. Re:Banks? by Glonoinha · · Score: 2, Interesting

      My first thought was the status screen part of the maintenance / configuration web interface to my router. Have it up, refresh it from time to time and just look at all the MAC addresses. Any clown that can't become familiar enough with 20-30 MAC addresses that are legit to memorize them, thus indentifying unwelcome intruders by looking at this screen ... doesn't belong in IT.

      And yes, that is one of the things I check from time to time when I want to reassure myself that my system hasn't been compromised.

      But you are right, banks probably shouldn't be using wireless, nor should they allow their home users VPN'ing in to use wireless. WEP is strong enough to protect my pr0n and warez, but it isn't strong enough (IMHO) to protect $14.6B worth of assets ... because anybody that can memorize 23 MAC addresses probably isn't going to have too much trouble burning through a 56bit key to get his hands on some of it.

      --
      Glonoinha the MebiByte Slayer
    5. Re:Banks? by x.Draino.x · · Score: 1

      It's not that hard to spoof a mac address, your mac address logs are worthless.

    6. Re:Banks? by chihowa · · Score: 2, Insightful
      Exactly.

      I'd say that one of the most difficult (and dangerous (getting caught-wise)) aspects of getting info off of a network is actually getting yourself into the network. Having a wireless link in removes a great deal of the danger (of getting caught), and leaves the intruder plenty of time to do the job more efficiently (making security's job harder).

      A big fat lock on the door keeps most intruders out. (and WEP and MAC filtering don't count as locks)

      --
      If you want a vision of the future, imagine a youtube comments section scrolling - forever.
    7. Re:Banks? by tesmako · · Score: 1

      Spoof might even be too strong a word considering how easy it is, most devices these days come with a pointy-clicky friendly gui to change the mac address even.

    8. Re:Banks? by Metzli · · Score: 1

      Why shouldn't a bank allow home users connecting via VPN to use wireless at home? If the VPN is secure enough to protect a connection on the Internet, then the VPN connection I have (which disables my local network) should be just as good.

      --
      "It's too bad stupidity isn't painful." - A. S. LaVey
    9. Re:Banks? by The+real+PoD · · Score: 1

      If you require high levels of security, e.g. financial transactions, you should not assume that a cable is any more secure than a wireless link.

    10. Re:Banks? by Glonoinha · · Score: 1

      I agree - that is why I said that an insider could pretty easily circumvent this simply by adding his MAC address, or cloning one that is on the list. If you do not already know any white-listed MAC addresses, however, how are you to find out?

      I guess it is possible to sniff that out of the air, but if it is 128bit WEP'ed ... how reasonable is that?

      --
      Glonoinha the MebiByte Slayer
    11. Re:Banks? by NateTech · · Score: 1

      One word: Virii

      Seriously... the home machine gets infected and then you connect it conveniently into the VPN router and over-the-firewall-and-through-the-woods-to-grandmo thers-house-we-go goes the virus...

      VPN's are only as secure as the home user is vigilant. Never will be any better than that.

      --
      +++OK ATH
    12. Re:Banks? by Glonoinha · · Score: 1

      Or close along those lines, Trojans or Logic Bombs. Close in concept, but wicked different in payload - a Trojan that comes in on port 80 to the leet home user's web site (gotta run server if you gonna be leet) runs a program on that server which probes out to gather data from mapped drives - later on that user VPN's in and has some fairly important data available on some mapped drives, which can be rifled through and summarized, sent back out via any number of ways.

      Might as well post it on the web.

      --
      Glonoinha the MebiByte Slayer
    13. Re:Banks? by Wolfrider · · Score: 1

      > Any clown that can't become familiar enough with 20-30 MAC addresses that are legit to memorize them, thus indentifying unwelcome intruders by looking at this screen ... doesn't belong in IT.

      --Oh, COME OFF IT man. Some of us have better things to do / suck at memorization. I get admin emails in Knoppix saying which MAC addresses have flipflopped or changed anyway, and I don't even have plans to run wireless.

      --
      .
      == WolfriderV6 == I'm willing to admit that *I just might* be wrong... Are you??
    14. Re:Banks? by Glonoinha · · Score: 1

      It was a joke, very few people are RainMan enough to memorize 30 MAC addresses. I am doing good to remember 6 or 7 and I have a photographic memory.

      Granted, this is one place where standardizing on hardware helps because the first few digits of the MAC address are vendor specific. If you use 100% SMC cards in your organization, you will see a pattern (thus making it easier to spot an outsider.)

      --
      Glonoinha the MebiByte Slayer
  2. Pringles Can? by Anonymous Coward · · Score: 0

    What's with the Pringles Can?

    1. Re:Pringles Can? by frankmanowar · · Score: 5, Informative

      It seems you can make a wirelss antenna out of a pringles can.

      --

      "Other bands play, but Manowar KILLS"
  3. Risk #1 by Anonymous Coward · · Score: 1, Funny

    THOSE PESKY WARDRIVERS!!

  4. Wireless should not be used for sensitive info by stuph · · Score: 3, Insightful

    I have great doubts that say, the government will ever allow sensitive or classified information to go on a wireless link, even if it is "secured".. there's just too much freedom in the air between origin and destination.
    Fiber should continue to be used for any info that could be considered sensitive at all.. but then again, who am i kidding.. businesses just want things to be easy, not safe

    --
    --Less Thinkin', More Drinkin'...
    1. Re:Wireless should not be used for sensitive info by Anonymous Coward · · Score: 3, Interesting

      the government will ever allow sensitive or classified information to go on a wireless link, even if it is "secured".. there's just too much freedom in the air between origin and destination.
      Drat, what are we going to do with the $8.5 billion we already spent on the satelites?

    2. Re:Wireless should not be used for sensitive info by stuph · · Score: 1

      I seem to be having this problem a good deal today, not completely clarifying my points..

      Instead, let me restate as "Current standards of 802.11x wireless internet should not be used, as they are too new, too fraught with holes and problems, etc"

      --
      --Less Thinkin', More Drinkin'...
    3. Re:Wireless should not be used for sensitive info by Alrescha · · Score: 2, Interesting

      This subject deserves mod points. I don't have any today, so you have to suffer through one of my posts.

      If you are running a business with wireless, and you care at all about security, and you allow anything to go over that link unencrypted, you're insane.

      The only IP address that should be reachable over your wireless network is the IP address of your IPSec VPN gateway.

      Most APs will accept re-addressed packets. This means the perp doesn't have to even crack the keys. All he needs to do is readdress packets to himself over the net and send them back to your AP. Your AP will dutifully decrypt them and send them out over the internet. Port blocked? Use a different one - you're re-addressing the packets anyway.

      A.

      --
      ...bringing you cynical quips since 1998
    4. Re:Wireless should not be used for sensitive info by Alrescha · · Score: 3, Interesting

      (not only do you have to read my posts, you have to read me replying to my own post).

      I realized that I over-simplified the re-addressing problem.

      From the UCLA paper:

      "Active Attack from Both Ends

      The previous attack can be extended further to decrypt arbitrary traffic. In this case, the attacker makes a guess about not the contents, but rather the headers of a packet. This information is usually quite easy to obtain or guess; in particular, all that is necessary to guess is the destination IP address. Armed with this knowledge, the attacker can flip appropriate bits to transform the destination IP address to send the packet to a machine he controls, somewhere in the Internet, and transmit it using a rogue mobile station. Most wireless installations have Internet connectivity; the packet will be successfully decrypted by the access point and forwarded unencrypted through appropriate gateways and routers to the attacker's machine, revealing the plaintext. If a guess can be made about the TCP headers of the packet, it may even be possible to change the destination port on the packet to be port 80, which will allow it to be forwarded through most firewalls."

      A.

      --
      ...bringing you cynical quips since 1998
    5. Re:Wireless should not be used for sensitive info by Frennzy · · Score: 5, Insightful

      The government already uses wireless links for data. Ever heard of satellite communications?

      Back to the point, 802.11 networks are inherently insecure.

      WEP is fairly trivial to crack for someone determined to break in. The problem lies in the init vector of the key, not the length of the key.

      SSID 'hiding' achieves nothing...the first time your box associates or reassociates, a listener has your SSID.

      WPA is not as secure as people think either, even with a PSK. This was covered on /. a week or so ago (or was that Ars?)

      MAC filtering is beyond trivial...most NIC drivers nowdays allow you to set your MAC...which you could easily see on a target network while hunting.

      You can make your home network more effort than it's worth to hijack...but for business use, make damned sure you want that traffic exposed...because you simply have to assume it will be. I wouldn't install wireless client access in a work environment without the use of VPN. I've heard some interesting theories about getting past even *that*, but I've never seen or heard a practical way to do it.

      Unless and until I see some more thorough reviews of the newer 802.11 security standards (EAP and it's variants) I wouldn't implicitly trust them...however I do get the feeling they are going to be far more difficult to compromise.

      As mentioned in a previous post, there are a number of problems with wireless that many people don't think about, especially in a corporate environment. One of the worst is the rogue AP. I've found no less than three unauthorized WAPs on networks I've run in the last three years. Each time it was a (l)user who brought it and just plugged it into their switch port so they could 'use their laptop'. Each time, the AP was completely wide open. So much for the quarter-million-dollar security infrastructure of firewall, VPN, IDS, etc. They might as well have run a wire outside the building and hooked up a PC with a sign that said 'Free Corporate Access!'

      There is yet another problem with rogue access points. Someone who brings one into close proximity with your wireless users. Guess what information the blackhat can get in that scenario?

  5. The key to it all is education. by James+A.+C.+Joyce · · Score: 4, Informative

    I think that the problem is that there are a lot of people who are hearing of the WiFi craze, hearing that it is a good idea, and then setting up these adhoc networks. The problem is, they often don't bother to read up about the potential security risks of misconfiguration and so if (when?) they mess up, there's a wide open hole right there.

    (And no, "wide open hole" isn't a goatse link :-))

    --

    Slashdot: when news breaks, we give you the pieces.
    1. Re:The key to it all is education. by Anonymous Coward · · Score: 0
      1. I think that the problem is that there are a lot of people who are hearing of the WiFi craze, hearing that it is a good idea, and then setting up these adhoc networks. The problem is, they often don't bother to read up about the potential security risks of misconfiguration and so if (when?) they mess up, there's a wide open hole right there.

      Not at banks, though, or (my specialty) central bank clearing houses (think regional Federal Reserve Bank locations, usually 1+ per country). The clearinghouses aren't as secure as you'd think, though wireless and other dumb ideas will be squashed soundly.

      My concern is if someone plugs in a wireless card -- say, plug it in a USB port -- and access the network that way. Scanning for those singnals, though, would be a big job. Blocking the signals themselves might be a prudent step.

    2. Re:The key to it all is education. by anagama · · Score: 2, Interesting


      I gave a friend of mine a wireless card for her laptop as a graduation present, the idea being she could use it when she's at coffee shops offering wireless connections, or in grad school on campus (she doesn't subscribe to broadband). As it turns out, she has a minimum of 4 options to connect to the internet from her apartment at any given time thanks to her careless neighbors.

      --
      What changed under Obama? Nothing Good
    3. Re:The key to it all is education. by SCHecklerX · · Score: 1
      Heh.

      Over christmas, I stayed a few nights at my girlfriend's mother's house. I brought a modem along, since they don't have broadband, but just for kicks fired up kismet.

      Suffice it to say, I was on a much faster network than dialup, thanks to a friendly neighbor with a default-configured linksys, dhcp and everything :)

    4. Re:The key to it all is education. by Anonymous Coward · · Score: 0

      Over Thanksgiving I was vacationing in Ft Lauderdale, and the hotel didn't have ethernet in the room. I fired up the wireless and was able to get link once I sat the laptop on top of the trashcan and 2 phone books :) all web surfing attempts routed me to a captive portal. I eventually went to sign up for a day's access, and the page that takes your credit card is not SSL-encrypted. So of course, I said, "fuck that noise!", rebooted to Linux, and kicked off ethereal.

      The "sign in or sign up" page showed an example userid for the system so I knew what to look out for. I caught 10MB of traffic and started to review the packets. Instead of catching anyone authenticating to the system, I actually caught someone running pop3 and grabbed their userid & password. I checked their account status, and found they have unlimited wireless access with international roaming. The id & pwd still authenticates to the WISP today in 44 countries.

  6. Warning : Troll in parent. by MooKore+2004 · · Score: 0, Troll

    The text has been modified. Search for "pig" in the text.

  7. Re:Site is Slashdotted! by Anonymous Coward · · Score: 0

    uh, no it's not. AC Karma wh#@$...

  8. VPN by Munkey_123 · · Score: 5, Interesting

    Just have your wireless devices set to a DMZ that opens to one page, a VPN portal. Then you have a wireless connection, with VPN providing your security. Voila...a little bit more cumbersome, but isn't your network integrity worth it?

  9. SSIDs and WEP by USAPatriot · · Score: 5, Informative
    Ars Technica has a good summary of what you can do with SSID's and WEP to improve your wireless network's security:

    Security Practicum: Essential Home Wireless Security Practices

    --

    Slashdot Moderation: From positive to terrible in 2 "insightful" posts.

    1. Re:SSIDs and WEP by (startx) · · Score: 1

      ars's 2nd tip is to turn off SSID broadcasting to "hide" your network. Anyone with a packet sniffer though can tell you that this really doesn't help hide you at all. In fact, as this paper suggests, it may actually harm the performance of your wireless network.

    2. Re:SSIDs and WEP by squiggleslash · · Score: 1

      Neither tip will prevent a determined hacker (WEP is not as secure as people think), but someone just looking for an insecure network will be thwarted by SSID hiding and WEP. Look at them as putting locks on your doors - not the world's greatest security, but would you use that as an excuse not to put locks on your doors?

      --
      You are not alone. This is not normal. None of this is normal.
    3. Re:SSIDs and WEP by Zocalo · · Score: 2, Insightful
      Yes, it's security through obscurity, and not very opaque obscurity at that, but that's not really the point. It's more of a deterrant to stop the casual cracker, rather than the determined one. It's kind of like not responding to ICMP pings; by default a lot of port scanners don't scan an IP that fails to respond to a ping. Blocking pings prevents full port scans from those that don't know any better. It also prevents scans from those that do know about this, but work to the assumption that if you are blocking pings, then you probably have a firewall and who knows what else and move onto the softer target a few IPs along.

      Besides, for me at least, wireless isn't about performance, it's about the convenience factor. I like being able to take my laptop out into the garden when the sun shines without a 20m CAT5 umbilical cable shoved through a window!

      --
      UNIX? They're not even circumcised! Savages!
    4. Re:SSIDs and WEP by rikkards · · Score: 1

      What about if you do the following:
      1. turn off SSID broadcasting
      2. Use WEP 128bit encryption
      3. Limit connections to specific MAC addresses
      Is that good enough outside setting up VPN between hosts?

      I am curious to know

    5. Re:SSIDs and WEP by Glonoinha · · Score: 3, Informative

      Locking the connections to specific MAC addresses is about your strongest link if protection from unknown outsiders is your concern. WEP128 is nice, the SSID thing is spiffy but if the WAP is rejecting connections from anybody not on the MAC white-list, unless someone is on the inside of your organization and can get his hands on that list I would say that you are going to be pretty tight.

      Remember - you don't have to be uncrackable, you just have to be harder to crack that the other guy. My WAP has 64bit WEP and that's it - but in my hood there are 4 WAPs, two of which are totally open - it is easier for someone that wants to play to get into those systems than to get into mine.

      If security is a serious concern, consider installing (on a different channel) a nearby wireless access point with no encryption, with a SSID that seems to indicate that it is worth hacking into, on a lame box connected to the internet but not on your internal network. Keep your eyes on this box watching for intruders. I think the term is 'honeypot' but I am not overly fond of that term.

      --
      Glonoinha the MebiByte Slayer
    6. Re:SSIDs and WEP by Anonymous Coward · · Score: 2, Insightful

      As people've said before, your MAC list is only effective is no one ever uses it. As soon as a whitelisted computer logs on their MAC's all over the air. Clearly this can't work for a financial institution. WEP, WAP, etc... all seem poorly implemented (however newer routers seem to nix airsnort pretty effectively by not using weak IVs). No SSID makes the AP silent to NetStumbler but any nix hacker with Kismet will see the anonymous beacon packets.

      As for a honeypot to distract attackers, that may be interesting, but if you really care it'd be more interesting to get around to setting up an encrypted VPN.

      This paranoia about sending information over the air is unwarranted; there're plenty of working encryption systems out there, if only they're implemented correctly. If you want a quick solution, setup a squid proxy and then tunnel your connection to it over ssh. But banks should have specific VPNs on top of the more obvious measures.

    7. Re:SSIDs and WEP by LinuxHam · · Score: 1

      on a lame box connected to the internet but not on your internal network

      perhaps not even connected to the Internet. I occasionally have to work in midtown Manhattan, which is wireless heaven. I do occasionally have to configure stuff by hand, such as guessing the default gateway and using known external DNS servers, but given enough time, I can pretty reliably get service from my office or hotel room.

      One particularly annoying connection gave me a 192.168.1 address and let me ping 192.168.1.1 but do absolutely nothing else. I ran nmap and nessus against the ip and absolutely nothing came back. It was freakiest thing I've ever seen. Its like someone bought a Linksys and powered it up without attaching it to anything else on the internal or external side. I guess it would be a good way to p2p with some friends if your apartments or offices are all within reach of the AP, but otherwise, it was a strange finding.

      --
      Intelligent Life on Earth
    8. Re:SSIDs and WEP by Glonoinha · · Score: 1

      -Its like someone bought a Linksys and powered it up without attaching it to anything else on the internal or external side.

      Never attribute to malice, that which is easily explained by ignorance. I would give about 50/50 odds that it was a wireless link between friends (Quake3A/UT/whatever deathmatch), and 50/50 that your first assessment was correct (somebody simply powered it up without plugging it into the Internet) - maybe swiped it from work to use as a network hub. Funny story though, tempts me to do the same.

      --
      Glonoinha the MebiByte Slayer
  10. POP passwords are the biggest risk I see out there by Twid · · Score: 4, Informative

    I've had some fun sniffing the network around the office, around town, and at O'Reilly OSXCon, and I think the biggest security risk I see on wireless networks are plaintext POP passwords going out in-the-clear.

    It's amazing how many people who should know better are still using plain POP for grabbing their mail. Since most mail client recheck for mail every few minutes, it's quite simple to grab passwords. Using those password, a hacker can then try the same password to enter the network, read the person's e-mail to do subsequent social engineering, or just fish around the person's e-mail for interesting information.

    The second thing I think most people don't realize is that on a standard wireless network all the HTTP url's they are surfing to with a web browser are public. This may not be a security risk, but companies also may not want a hacker in the parking lot to know that a server named secretinternaldata.mycompany.com exists.

    I set up an SSH tunnel from my laptop to my squid proxy at home just for fun to see if I could fix the issue. It worked well, but of course it's not something the average end-user with a laptop on wireless could manage.

    Anyway, that's my .02.

    --
    - "When you want something with all your heart, the entire universe conspires to give it to you" -Paulo Coelho
  11. Disable wireless ability of wireless router? by Anonymous Coward · · Score: 0, Flamebait

    Can you take a Linksys (or any other brand) 4 port wireless router and simply disable the wireless ability of it and just use it as a standard wired 4 port router?
    Why? I don't need wireless ability now (I just use normal wired ethernet), but may need wireless in the future.

    1. Re:Disable wireless ability of wireless router? by agwis · · Score: 3, Informative

      Yes, at least with the linksys wireless routers you can.

      Call me paranoid but I normally disable wireless mode unless I know I or someone else in my family needs it.

      -Pat

    2. Re:Disable wireless ability of wireless router? by stuph · · Score: 2, Informative

      I'm generally a fan of MAC address restrictions.. when I lived in an apartment in Berkeley, if I was in the living room, I would be connected to my own wireless router, but in my bedroom I got someone else's.. Oh well, I just used their bandwidth instead, they had the better link to me, so their loss.. But when I would check the router's logs to see connected users, there were FAR too many people who weren't my roommates trying to connect.. poor them, no free access from me (at that time, I'm reconsidering my position on that as I get trafic shaping improved on my linux box)

      --
      --Less Thinkin', More Drinkin'...
    3. Re:Disable wireless ability of wireless router? by interstellar_donkey · · Score: 1

      You could probably just unscrew the antenna and put something that would block the radio signal, like some oddly shapped tin foil over the outside lead. That would probably be a quick way of "disabling" the wireless features.

      --
      The Internet is generally stupid
    4. Re:Disable wireless ability of wireless router? by Anonymous Coward · · Score: 0

      I'm sure most routers have this ability. My 4 port NetGear WG614 allows you to do this. All web-based and very easy to set up.

  12. Reducing Risks of Wireless Networks by gellenburg · · Score: 5, Informative

    Disclaimer: I work in Information Security.

    • APs should be configured so as not to broadcast their SSID.
    • 128bit WEP keys should be chosen.
      • WEP keys should be changed as frequently as practical.
      • APs should be firewalled, and on their own DMZ.
      • If the AP supports it, consider MAC Address filtering by only allowing authorized MAC Addresses.
      • If the AP supports it, consider additional authentication such as RADIUS.

    But, by all means:

    • Please change the damned default SSID that was configured on your AP:
      • Linksys
      • Default
      • Netgear

    We now return you to your regularly scheduled programming.

    1. Re:Reducing Risks of Wireless Networks by Twid · · Score: 4, Funny

      Please change the damned default SSID that was configured on your AP

      A funny aside:

      I was in Park City visiting friends over the holidays. The ISP for the friend that I was staying at went out of business, so I walked around the house looking for another wireless AP.

      At one corner of the house, I find one, and the name is the first initial and last name of the person running it. It's not running with any security so I'm able to hop onto the net. So, I feed in his first initial and last name and "park city" into google (on his own wireless, even) and google gives me his home address and phone number.

      I felt like calling him to thank him for the free wireless access. :)

      --
      - "When you want something with all your heart, the entire universe conspires to give it to you" -Paulo Coelho
    2. Re:Reducing Risks of Wireless Networks by azuretek · · Score: 3, Insightful

      "I felt like calling him to thank him for the free wireless access. :)"

      You should have, if he's left his network open for everyone to use and he's bright enough to change the network ID then I'm sure he did this on purpose. I do the same and I expect others to do the same so that we can all get free net anywhere we go.

    3. Re:Reducing Risks of Wireless Networks by sumbry · · Score: 1

      I do the same as well and have for years. Every now and then I see people hop onto my network and as I travel alot I do the same. Never abusing anyone elses connection most of the time all I am really doing is checking email and browsing web pages.

      One thing to add: I use Secure IMAP, SSH, SCP, and SSL for accessing most things work related. No cleartext passwords being transmitted by me for this exact reason that I'm always on other peoples networks.

    4. Re:Reducing Risks of Wireless Networks by loraksus · · Score: 1

      I'm going to take the complete opposite point, if you have a business AP, OPEN your wireless network, assume that it is compromised from the start. This will force you to encrypt your network traffic with something that actually resembles security.

      WEP, MAC filering and stopping SSID broadcasting aren't really worth anything in terms of security - they might prevent the casual user from drifting in, but it is pretty clear that the security they provide is trivial at best and they are more of a hinderance to users than anything else.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
    5. Re:Reducing Risks of Wireless Networks by GodBlessTexas · · Score: 1

      Disclaimer: I work in Information Security.

      Funny, me too. I'll only address the things that I disagree with and leave the other points that stand alone.

      APs should be configured so as not to broadcast their SSID.

      Doesn't matter. It's trivial to determine the SSID. I can either catch a client associating to the AP or force any/all connections to disassociate and then catch the SSID when the card reassociates. I don't even need low-level 802.11b code to do this. A simple connection cutter written in C cutting connections at the transport layer can cause enough havoc that someone will reset their card and I can snatch it that way.

      If the AP supports it, consider MAC Address filtering by only allowing authorized MAC Addresses.

      MAC address filtering is pointless. It may keep a wintel user out of your network, but an actual attacker can bypass this with BSD or Linux card drivers.

      If the AP supports it, consider additional authentication such as RADIUS.

      Using RADIUS is a good idea, but entirely too many people use their SSID as their RADIUS key, their WEP key, or both. The problem with all those keys is key management, and people tend to be lazy in that aspect.

      And of course, if you really want to be a nuisance, it's not that hard to simply DOS any and all 802.11b networks your antenna can reach from a distance.

      It would be really, really nice if IEEE put some honest through into the security of network technologies, especially the wireless technologies. Retrofitting security after the fact isn't the ideal solution.

      Now 802.11g is a little more secure, but only because the information behind the chipsets have been so closely guarded by the chipset manufacturers. Now that 802.11g drivers are starting to appear for Linux, it won't be long before we see canned code to exploit it as well.

      --
      Remember the Alamo, and God Bless Texas...
    6. Re:Reducing Risks of Wireless Networks by gellenburg · · Score: 1

      I agree with you whole-heartedly on all points; but as you know, security is all about balancing risk & deterrence with the business-needs and usability.

      While the 802.11x protocols provide little to no effective security within them, my comments were targeted towards the typical /. audience - the gamer & geek who happens to have a WAP set up in his apartment. I was not writing a best-practices & standards document. ;-)

      Ultimately though, the most secure WAP is one which isn't turned on, but so many people are jumping on the WAP bandwagon that they're forgetting even the most common-sense types of things to make their networks a little more secure.

      Me, I use an Apple Airport Extreme. Not the most secure WAP, but it's better than a lot.

      * I don't use WEP, but use WPA. (All of my Macs run Panther).
      * Key lifetime is 15 mins.
      * SSID is not broadcasted.
      * Transmitter power is reduced.
      * The WAP is located centrally in my house.
      * The Base Station Name is changed weekly, and is generated randomly using 'mkpasswd'. (1)
      * The Base Station Password is changed weekly, and is generated randomly using 'mkpasswd'.
      * The SSID is changed weekly, and is generated randomly using 'mkpasswd'.

      War driving into work I see all too many WAPs configureg with the homeowner or business owner's name.

      * The WPA Personal Key is changed weekly, and is generated randomly using 'mkpasswd'. It's key-length is also 16 bytes.

      And for me, these steps work well. But, I'm not protecting a Fortune 25 Company's Financials, but I am protecting my own personal financials, investments, etc.

      In addition, I'm attempting to protect my ass from script kiddies in the neighborhood hijacking my connection and downloading pr0n and MP3s.

      Can MAC addresses be spoofed? Absolutely.

      Can one easily obtain the SSID of a WAP? You're average Joe can't, and I'd even venture that your average script kiddie can't, but if you've got a modicum amount of skills then yes, you're right.

      But are all of these better than the default configs WAPs are shipped with? Yes.

      Bottom line, the end-user needs to decide what's good enough for them. At work, all I can do is document and present the risks as objectively as possible; but at the end of the day, Management is the one with a fiduciary responsibilty to the Company, not me.

      But in the Ellenburg household, I am the one with the fiduciary responsibility, and maybe that's why when I'm not using anything wireless, my WAP, my Airport Extreme, is actually turned off. (2)

      -----
      (1) For example, last week's Base Station Name (not the SSID) was "32jfgp|RO". The SSID was "rvy7@8Xv9".

      (2) When I'm at work, when I'm asleep, and when I'm not using the computers, my WAP is actually turned off (unplugged since that's the only way an Airport can be turned off). As I stated earlier, the only secure WAP is one which is unplugged.

  13. It's that time again... by Cylix · · Score: 1

    I for one, welcome our new OCC over lords.

    I couldn't resists.

    I shall now bathe in the cleansing flame.

    --
    "You should always go to other people's funerals; otherwise, they won't come to yours." -- Yogi Berra
  14. There are methods to secure access... by Wicked187 · · Score: 0

    but for reason does a bank need wireless access? In environment that could benefit (warehouses and such), there are ways to help limit how far the signal gets. Most warehouses have cinder block or steel panel walls, you could also add some grounded chicken wire or some of meshed metal wiring to the exterior walls to keep the signal from escaping the building... just fyi

    --
    Politics, Life, and More on my Aspiring for the Future
  15. What about WPA? by flinxmeister · · Score: 1

    I saw only a tiny blurb about WPA, which should be a primary consideration for banks and credit unions analyzing the risk of wireless.

    WPA has stronger encryption that WEP and authentication mechanisms built in. I work for a Credit Union processing/software company, and many financial institutions are waiting for WPA to become more mature before they jump into wireless.

    For more info, google, or check this out.

    1. Re:What about WPA? by azuretek · · Score: 1

      They shouldn't even be considering it, there are so many things that can go wrong with it and I think that's just too much risk for customers.

      If I knew my bank or anyone else handling my financial information was using wireless to transmit my information I would go somewhere else. I dont trust wireless even if it is secure.

      Any encryption that can be dycrypted is instantly insecure.

    2. Re:What about WPA? by NateTech · · Score: 1

      Umm, I thought WPA just rotated standard WAP keys? If that's true, that's not "stronger encryption" that's just "changing encryption at the same strength".

      --
      +++OK ATH
  16. I work for a wireless switch vendor... by routerwhore · · Score: 3, Interesting
    A wireless switch you ask? Isn't that an oxymoron? A wireless god box may be a better description. Using a system such as this, you too can provide, or prevent, secure wireless access.

    The switch has all inline power ports to power the APs, which may or may not be directly connected. Each AP automatically creates an IPSEC tunnel back to the switch. The switch supports every auth method under the sun (EAP-TTLS being generally most secure) when combined with 802.1x (which includes dynamic WEP/WPA 2.0). The switch itself supports a per-user firewall, integrated, signature-based IDS (that detects things like monkeyjack and netstumbler), and terminates 2 Gbps of IPSEC (which includes the IPSEC client running on each user's machine.

    All of this for a couple of grand. Secure wireless is possible, the market is demanding it, and vendors have come to meet that demand.

    1. Re:I work for a wireless switch vendor... by Xenophon+Fenderson, · · Score: 1

      I've seen a similar-sounding product from a company called Vernier Networks. Not only can you control access via a variety of VPN methods (including PPTP, L2TP over IPSEC, and vanilla IPSEC), but it can do limited transparent proxying with HTTP, amongst other things. It was very slick, and to be honest, this kind of network access control technology can be applied to a lot more than just Wi-Fi.

      --
      I'm proud of my Northern Tibetian Heritage
    2. Re:I work for a wireless switch vendor... by routerwhore · · Score: 1

      As someone with personal knowledge of Vernier's products, let's just say there are much better products out there (under the hood especially) that do a whole lot more.

    3. Re:I work for a wireless switch vendor... by Anonymous Coward · · Score: 0

      Great you've got this do-it-all wireless box that is affordable and perfect. Now how about telling us the one thing that really matters. What's the freakin name smartass.

  17. Re:POP passwords are the biggest risk I see out th by gvc · · Score: 4, Interesting

    I agree 100%.

    The hoopla about physical access security obscures the point that *all* internet traffic and most intranet traffic is viewable by others. It is a good idea to assume that all your networks are open and to use VPN, ssh, etc. to secure your data. And *never* send plain-text passwords.

    If you lock your data down under this assumption (that all network traffic may be intercepted) the impetus for clunky and insecure wireless access restrictions is much diminished.

  18. A nameless UK store... by Anonymous Coward · · Score: 3, Interesting

    used to use WiFi between it's checkouts and inventory system. No encryption, SSID broadcasts were switched on and everything, to the extent that we used to sit in the car park and surf the web via their connection for hours on end on Saturday afternoons.

    This was a good 18 months ago though. I'd assume they've changed it now. I certainly made a point of telling them why I wasn't shopping there any more, rather than doing the whole 'your network is totally unsecure and I found out why' thing and getting myself arrested...

    1. Re:A nameless UK store... by Anonymous Coward · · Score: 0

      i think i know the same store which (not that i ever ventured into it) had wireless between one of its petrol stations and the main store across the road :-) - i didnt have a laptop handy to check it out though :-(

  19. Wep isn't bad to begin with. by MooKore+2004 · · Score: 2, Troll

    If you're smart when you set up your access point, and turn on WEP, 99.9% of people that might hack your network are going to go find an easier target. The typical figure I've heard is 24 hours or more to get enough traffic to break the encryption. Unless someone knows you have something they want, they're not going to bother.

    Home users are going to generate less traffic than businesses, and so it will take even longer to get enough traffic. Unless you happen to notice a van parked outside your house for a couple days, or find yourself staring down the barrel of a pringles can, you can relax.

    Turn off SSID broadcasting

    use a unique SSID

    For God's sake, change the admin password

    Turn on WEP

    Use MAC address filtering

    Congratulations, you're now more trouble than you're worth.

    1. Re:Wep isn't bad to begin with. by NetJunkie · · Score: 3, Interesting

      But what about your neighbors? From my office upstairs in my house I can see 9 wireless networks. 24 hours to get enough data? That's easy. That is what concerns me. You never know who you live around and they have all the time they want to break it.

      From what I've seen most of my neighbors don't use their connect enough to get enough traffic but 1 or 2 do. In a test of AirSnort I got close to 1K interesting packets in 2 days for one network. Given a week or two of a system sitting in a corner I bet I could break it.

      This is the main reason I totally dropped wireless in the new house. I had it wired with CAT5 for data everywhere I'd need it. I work a lot from home and have a site-to-site VPN and don't want to compromise that.

      Your suggestions are good... But turning off SSID broadcast is overrated. As soon as a client associates I can get that. As soon as they associate I can get a MAC address to clone.

  20. Conduct Wireless Audits by lewko · · Score: 4, Interesting

    If you are responsible for a company's security, you should regularly search for wireless nodes within your organization which you are not aware of WHETHER OR NOT you are using wireless as policy.

    I have been asked to assess companies and offered a wireless audit. They said "we don't use wireless". I checked anyway, and it turned out they DID have wireless (but didn't know about it) thanks to in one instance, a laptop acting as an AP and in another, a sysadmin who figured he'd plug in a wireless AP with built-in switch instead of a hub or switch, and wireless was turned on. This is all the more problematic as the laptop and wireless device were both inside the firewall and therefore represented a major hole.

    Intruders may also leave wireless devices behind to save coming onto the site for subsequent eavesdropping. That is, they will bring your network to them rather than bringing themselves to your network.

    In any case, fire up your stumbling application, a GOOD antenna and have a look around your own environment. You may be surprised what you see!

    --
    Do you or your partner snore? - Visit www.snoring.com.au
  21. Re:POP passwords are the biggest risk I see out th by Anonymous Coward · · Score: 0

    This all being said from somebody who logins into their favorite geek news site without the faintest bit of encryption!

  22. Re:POP passwords are the biggest risk I see out th by micsaund · · Score: 2, Insightful

    The problem with plaintext POP passwords is that many ISPs (mine included) do not offer any other option. I wish they would, but they do not.

    Thus, I just choose a mail-only password that I use for POP access. I guess a hacker could read my e-mail and maybe even send mail as me, but I've done what I can to minimize the risk of stupidly designed mailservers.

    --
    Pinball, arcade video, tech and more: www.micsaund.com
  23. script kiddies by SparafucileMan · · Score: 2, Insightful
    As wireless becomes a bigger part of our networks, those of us charged with maintaining them find ourselves also responsible for keeping drive-by script kiddies with a Pringles can out.

    Nevermind the professional hackers with a 12db antenna engaged in corporate espionage...

    I mean seriously, I think the scR1pt k1Dd13 n00bs are the least of our problems.

  24. Re:POP passwords are the biggest risk I see out th by Twid · · Score: 3, Interesting

    Yeah, I see a lot of people stuck like that with insecure POP, and a lot of people who use the same password for their home account (which is almost always POP only) as they do for their work account. Bad bad bad.

    One thing you could do, if you want to be a bit more secure, is to port forward port 110 using SSH to a server at home. Your POP password is still going out in the clear then, but it's going in the clear from your house, which is presumably more secure that going out over open wireless.

    the tunnel would be something like this:

    ssh -L 110:www.yourhomeserver.com:110 -f -N yourname@www.yourhomeserver.com

    Here's a howto that goes into a little more depth.

    --
    - "When you want something with all your heart, the entire universe conspires to give it to you" -Paulo Coelho
  25. Hmmm... by ttblum · · Score: 1

    I know this is off the subject but..
    My company has recently begun implementing wireless
    networks, using all Cisco equipment.

    Base on my reading, it looks like you should only use Spanning Tree Protocol with wireless
    bridges, not with access points. Why is this?

    What's the difference between a wireless access point and a wireless bridge?

    1. Re:Hmmm... by ttblum · · Score: 1

      Oh, now I see.

      APs don't communicate with other over their wireless
      interfaces--making for no redundant links. This is why STP is totally unnecessary on APs.
      Bridges, however, do communicate with APs or other bridges
      making redundant paths a possibilty.

      Thanks tomsnetworking.com!

      Todd

  26. Can Linux Do This? (TM) by Karma+Sucks · · Score: 1

    I just got a wireless Ad-Hoc network using iwconfig on Linux.

    How do I tell iwconfig not to broadcast the essid?

    --
    (Please browse at -1 to read this comment.)
  27. Let's not forget the next-door neighbor by Frisky070802 · · Score: 3, Interesting
    Simson Garfinkel ran a blog entry a few days ago about detecting overuse of his home network and tracing it to unauthorized WLAN access by his teenage neighbor who then got affected by a Kazaa virus. Nearly got his broadband shut off from over-use.

    He'd left it open to facilitate use by visitors, but no longer.

    --
    Mencken had it right. So glad that's old news.
  28. Re:POP passwords are the biggest risk I see out th by slowbad · · Score: 2, Interesting

    many ISPs do not offer any other option

    Use your ISP for connectivity and spend $30-35 a year for a better mail service.

    For less than 3 bucks a month, you might even get HTTPS webmail thrown in ... some extra storage ... and one of those "lifetime" domain names that gives you some flexibility regarding additional accounts and spam control.

    If email matters to you, it is doubtful you can find an ISP for twice the price that gives you mail security and your current level of non-mail speed and features (how most people pick their provders).

  29. Re:What about WPA? MOD PARENT UP!!! by neBelcnU · · Score: 1

    Finally!
    All this talk of MAC-address locking, SSID changes, WEP key rotation. (All good steps if you can't use WPA)

    And WPA fixes (almost) everything.

    So while I give flinxmeister "The Hammer" for hitting the nail on the head, I've got to add my voice to the general theme, BANKS should NEVER go wireless.

    Historic building? Asbestos? Cutting quarterly costs to make bonus targets? Fuggedaboutit. There ain't no "safe" wireless vis a vis any financial institution.

    But for the rest of us, get the upgrades in place /.ers, WPA is the way to go. (Until I can get ".x" on my Ethernet...)

  30. help by Anonymous Coward · · Score: 0

    Does anyone have instructions on how to make a foil beanie for my wireless router to tremble under????

  31. Re:What about WPA? MOD PARENT UP!!! by flinxmeister · · Score: 1

    Well, you certainly sound more sane than the prior post....and I appreciate that hammer!

    However, remember the title of the article: "Risk management". There is no safe way of banking or doing business...period. There are only various shades of grey. As long as a financial institution understands the risks and takes appropriate steps to mitigate the risks and shield their customers/members from damage, they can implement a given technology. The question this thread seems to be encountering is "what is the level of risk that is impossible to mitigate". I submit that a wireless network with WPA and some other tricks falls well within the realm of manageable risk.

    When you use an ATM, or buy something on the 'net, or give your personal check to someone, or use internet banking, or give someone your social security number, you are engaging in far, far more risk than if your FI uses a properly secured wireless network.

    Did you know that your entire financial history is routinely fedexed on a tape? Did you know that there's a 99% chance that your financial data is routinely transmitted through multiple telecom companies unencrypted? Did you know that there is a good chance your paycheck is transmitted via a very secure, but very DDOSable single Federal Reserve website?

    Trust me or don't, a loan officer on a car lot using a properly secured WPA implementation to loan you money is perfectly safe compared to the risk you are exposed to every day by simply existing as a financial being.

    But before you put all your money into your matress, manage the risk of a house fire. ;)

  32. My wish by Anonymous Coward · · Score: 0

    I wish there was a way for me, as a Christian, as a human being, to sit down with some of you and have a pleasant, civil discussion without bitterness or sarcasm. I don't force people to believe what I believe. I don't mock others with different beliefs. I hope I can find the words to explain myself, as my life goes on. I hope I can help people to see.

    1. Re:My wish by Anonymous Coward · · Score: 0

      Jesus, not this troll again. Go away!

  33. Re:POP passwords ... by antdude · · Score: 1

    I would like to use encrypted passwords but most providers do not have encryption password feature for POP3 on their side. :(

    --
    Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
  34. Re:POP passwords are the biggest risk I see out th by gvc · · Score: 1

    Guilty as charged. This is a public forum and I have transmitted no data to it that I consider sensitive. I assume that my Slashdot password may be compromised - that may let you impersonate me here but it won't get you into my bank or my paypal account, or my personal computer for that matter.

  35. Doctors by SCHecklerX · · Score: 3, Interesting
    You are worried about banks? I noticed that my orthopedic surgeon's office uses a wireless network for pretty much everything (the doctor can dictate from anywhere, and nurses put your blood pressure and such in using a laptop from any exam room).

    So, for kicks, I took my libretto to the office on my next visit and fired up kismet.

    They are wide open. No WEP, Windoze boxes (including the domain controllers) all easily accessible. A quick port scan showed all types of vulnerable services and such. I did not take the time to go further, but figure that getting patient records would not be too difficult.

    From the port scans, it seems that this small office is also on the same subnet as other businesses in the area. WTF???

    So what is one to do? I dare not tell them what I found, what with the risk of being labeled a terrorist and all. I thought that an anonymous letter to them might be best. But how can I be sure that they ever fix the problem?

    1. Re:Doctors by LinuxHam · · Score: 1

      I agree with the other replier to tell him gently, but I would do it in a backhanded way. Make sure you're surfing the web or checking your email when he walks in. Be sure to say something like, "wow, I am *so* glad you guys put this wireless in for us, it *such* a timesaver while I'm waiting to see you! THANK YOU so much." And if you're brave.. "and thanks for keeping it easy to get on the network. So many places have all these convoluted security settings. If you're just letting your patients check their email, then there's no sense in encrypting anything or keeping outsiders off your network." There's a great value in the skill that lets you tell decisionmakers what to do and make them think they came up with it all along.

      I don't have a PDA with 802.11 so I haven't checked my hometown doctor's WLAN. I guess I could pringles-can it from the parking lot. My orthopaedic surgeon is at a major university and they run fiber to every desktop, and even replaced an xray review station with about a 25" wall-mounted flat screen.. just beautiful.

      --
      Intelligent Life on Earth
    2. Re:Doctors by Fluid+Truth · · Score: 1

      I know this is a bit late, but I thought I'd chime in. I wouldn't admit that you already know that they're vulnerable. I'd first mention that you see that they use a wireless network and ask them who set up their network and if they know how secure it is. You don't even have to lie; you can say that you are concerned about their security and your privacy (which, IIRC, they are mandated to protect).

      If they blow you off, then I'd actually contact an agency that might care about the privacy laws and just ask them to check on this office's security, since you're concerned and their answers didn't make you very comfortable.

      If they don't blow you off and either refer you to the people who set it up or are knowledgable themselves, you can offer to do a cursory security audit, "the kind that any malicious hacker might do while driving by." If you get permission, get it in writing. :-) Then, go for it and let them know the results.

      Seems to me that it's always best to ask and appear ignorant until they tell you the answer or they ask you to find the answer for them.

      --
      Apparently, of the rich, by the rich, for the rich.
  36. Give me a break... by SmokeGhost · · Score: 1

    I am aware of the dangers of wirelsss, it's becoming the top networking solutions for homes and small business. A simple drive around town yields 80+% open networks, there is a solution though. it will eventually cost money(a) and it will be a long process but it will work.. Simply create and air a PSA on local television, by law they have to run them and they are free to run, you only have production cost(a(depending on scale and quality will determine the cost)) and that is a non-issue really. A good PSA that runs like tobacco adds will start working when you show what can happen to an open wireless network.. All in 30 seconds:)

  37. A doctor replies by The+Tyro · · Score: 4, Insightful

    Tell him... gently.

    Explain to him that you're a hardcore networking geek with an interest in security, and that you often run security checks against your own systems. You were there, running one just for kicks, and viola! You are a patient of his presumably, so you already have a relationship and rapport... it would be different if you were some joe-blo off the street who came waltzing into his office running kismet on your Zaurus.

    He probably has NO CLUE that whoever set up his network has left it open to be plundered (tech-saavy doctors are rare. Thinking about all my colleagues, I can count the tech-saavy on one hand).

    Take him aside privately, and explain to him that you were hesitant to come forward (for obvious reasons... like being labeled a cracker), but that you really felt he should know what was up, not only for the security of your own medical records, but also for the security of everyone else's. Heh... he might even hire you to help fix it.

    You will likely find him VERY receptive if you approach him the right way. I'm quite certain he contracts his IT stuff out to somebody, so he probably has ZERO emotional investment in the security of his network... he just wants it to work, and pass HIPAA muster (which it probably doesn't right now).

    I bet he'd be receptive.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
    1. Re:A doctor replies by nostriluu · · Score: 1

      While I still think there is an assumption on your part that approaching someone rationally is always going to work, it might also be worth mentioning that the doctor's office could be criminally charged for not adequately protecting patient data.

  38. are you sure all is good? by djupedal · · Score: 1

    We have none in our offices.

    But those cordless phones in use are a yes yes...?

  39. Wi-Fi Security Analysis by ObsceneProphet · · Score: 1

    The simplicity of the problem is compounded by the complexity of the solution.

  40. What Risk? Aside from kiddie pr0n? by grolaw · · Score: 1

    This lawyer runs a WIFI hotspot for his office. All boxes have decent firewalls and the CPUs are all off-line after hours (e.g. whenever we are not working late).

    I don't care about free riders. I want a few. Let the RIAA claim I have downloaded anything. . . I haven't and neither have my staff. BUT I would love the accusation.

    The client data and the electronic filings are all all encrypted (PGP on office systems or SSL in submission to the federal courts where most become a public record) and so is all email.

    Other than that Canadian idiot who was found with his pants off and kiddie crap on his laptop, I have no worries.

    I also have an office in a small town near a big city in the midwest. I know my town's mayor, elected officers and police. I also have my fly rods, shotguns and a single handgun in the 114 year old building.

    The first idiot that runs into the building nekked with kiddie pr0n on his laptop can elect the 9mm or the Parker exit. There will be no alternative. The time frame will be a few milliseconds (police are a two clicks away, fire station 50 M).

    Either way, he is history (strange that there are no women who act this dumb). I doubt that the inquest would go beyond the coroner. He needed killing.

    If we were lucky enough to wack a "sting", so much the better! There is no defense to downloading kiddie pr0n and killing that sick f**k too quickly may be the only liability.

    The endodontist in town has the same view, though he favors frangible .40 cal in is Sig Sauer over 9mm.

    Meanwhile, let the RIAA accuse me of downloading anything. I'd love it! I'd sue them up, down and each attorney individually and I'd prefer ethics charges as well. I can only hope that we draw one or the other to our little trap. Meanwhile, any student or local who needs a quick link to the Internet can enjoy our on-ramp.

    I see nothing (aside from the pr0n free riders) negative about an open wifi access point.

    1. Re:What Risk? Aside from kiddie pr0n? by NateTech · · Score: 1

      Unless you're blocking port 25 outbound, you (and everyone else running open "oh the world is beautiful, share your bandwidth flower-child brothers and sisters!" access points have created just another way for spammers to inject crap into our inboxes.

      --
      +++OK ATH
    2. Re:What Risk? Aside from kiddie pr0n? by grolaw · · Score: 1

      I made it clear that the access to mail servers is zip. Port 80 is all they have.

      I also mentioned the bandwidth issue. I monitor system usage and will choke - or kill - all access when the free riders approach 50% saturation.

      I have a wifi access point that is available to a few folks in a small town near a big city. The access is limited (by range) and aside from somebody putting a clandestine antenna and cable on my building - I should be able to actually SEE the person who accesses my wifi site.

      You are missing the point: I am not just another "share" person... I want the advantage that open access provides me against the RIAA and their ilk. They cannot point to my net's IP and say that I am responsible for all traffic from that address. I clearly am not.

      Obtaining a search warrant for a law firm's computers is not a trivial process and attempting to use a civil subpoena to "audit" a law firm is just not going to fly with any judge around due to the fact that an audit would involve breach of attorney-client confidences stored on those systems.

      I've been litigating Title 18 for a decade now (ECPA & the tampering with computers fraud and abuse act) and I believe that the positives of having an open wifi point outweigh the negatives.

  41. Re:but do absolutely nothing else. by Technician · · Score: 1

    One particularly annoying connection gave me a 192.168.1 address and let me ping 192.168.1.1 but do absolutely nothing else. I ran nmap and nessus against the ip and absolutely nothing came back. It was freakiest thing I've ever seen. Its like someone bought a Linksys and powered it up without attaching it to anything else on the internal or external side.

    Most likely, neither solution is correct. The WIN box sharing the internet connection is in BSOD and nobody noticed it yet. ;-)

    --
    The truth shall set you free!
  42. Re:oddly shapped tin foil by Technician · · Score: 1

    The router would like you much better if you replaced the antenna with a proper (microwave not CB band) 50 ohm dummy load. It is possible to feed a stub of tin foil and it could radiate the signal. A dummy load in a coaxial fitting provides a load on the transmitter preventing high standing waves which can produce high current or high voltage nodes in the router which radiate the signal.

    --
    The truth shall set you free!
  43. SSID broadcasting. by jotaeleemeese · · Score: 1

    The problem is that some WiFi devices can't connect to AP if it does not broadcast the SSID.

    I got two USB WiFi devcies and they would not work until I re-enabled SSID broadcasting.

    When you buy devices it is not obvious if they will work without the SSID being broadcasted.

    Perhaps a compilation of devices that are more secure should be gathered somewhere.

    --
    IANAL but write like a drunk one.
  44. insightful? by RMH101 · · Score: 1
    people have been successfully convicted for exactly this...

    The zero-risk to yourself approach is to do nothing. Next up is the anonymous letter, and the continuum extends right up to admitting you've used their network...your choice where you draw the line.

  45. Wireless should be illegal by Anonymous Coward · · Score: 0

    I'm not trolling here - I'm completely serious. Wireless networks offering access to the Internet using existing 802.11 security mechanisms should be illegal.

    This crowd seems to be thinking only of security against direct attack - but by FAR the greater problem is "third-party liability". If someone uses your wireless network to attack a third party, YOU are liable for the damages.

    In a time when we're all fighting spammers and other attackers, the morons out there installing wireless networks are giving attackers the greatest tool they've ever had - free, untraceable, high-bandwidth network access.

    Do your part - turn OFF every existing wireless lan. Demand 802.1x security mechanisms. (The 802.1x standard, although still in draft form, has already been implemented as part of Cisco Wireless Security Suite.)

    The only valid security mechanisms for 802.11x WLANs to be developed so far ALL require client behavior that is outside the scope of the 802.11x standards. There is no such thing as a standards-only, secure 802.11 network.

    Security in 802.11x will come from the incorporation of 802.1x - that's not a typo - 802.1x is a security standard that fixes all of the problems with existing wireless security techniques and is meant to be the foundation for future enterprise network security.

    Don't think "WPA" is a solution either - it's already been cracked as well. The only solution in the foreseeable future is 802.1x. Push for it. Push back AGAINST the stupid wireless networks that are presently jeapordizing the entire Net.

  46. Indeed. by The+Tyro · · Score: 1

    Hence my admonition... it's all in the presentation.

    Physicians are insanely busy people... busy taking care of patients, busy dealing with insurance companies, busy trying to comply with govt. regulations. No doctor has a legal department sitting on its hands with nothing to do, just waiting to prosecute/sue a patient who happens to fire up his laptop in the waiting room and inadvertantly pick up the open AP. The original poster is a patient of that physician, and did not hack into the open network.. he simply found it.

    Prosecuting your own patient (who was trying to do the right thing by informing the doctor of a big confidentiality problem) would play VERY POORLY in the local newspapers... physicians have a professional reputation to uphold, one that's more valuable than gold. Prosecuting your own patient for trying to help you looks pretty shitty, even to a non-techie layman... and the doctor can't afford to hire a public relations firm to repair his damaged reputation, unlike {insert your favorite MegaCorp here}.

    In a way, the original poster is not only helping the doctor, he's helping assure the safety of his own medical records (which he arguably has the right to do). Also consider that if he discusses this matter during the course of a patient visit, that communication could be considered privileged, and NOT admissable as evidence without the patient's consent. Also, there's the small matter of getting a prosecutor to pursue the case, and a jury to convict...

    I stand by my comments.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
  47. Nice job pumping your own trolls by Anonymous Coward · · Score: 0

    Interesting history you have of trolling on your own trolls. Fucker.