Slashdot Mirror


New Security Ideas From Intel

Scott writes "Intel is developing a new technology that could prevent unauthorized access to wireless networks using the time it takes for packets to arrive from the access point to the Wi-Fi user. This is one of several ideas were presented at Intel Developer Forum. Intel has also released a hardware-based solution to fight against worm spreading. From the report: 'The system monitors the number of external connections being made and if a higher network activity is detected, the computer is disconnected to prevent the infection of further machines on the network.'"

6 of 151 comments (clear)

  1. The security of your wireless network... by Vyyper · · Score: 5, Insightful

    is only as strong as the weakest link.. which in most cases is the user.

  2. If anyone actually bothers to turn it on.. by jcr · · Score: 5, Insightful

    Hey, kudos to Intel for coming up with this stuff, but I suspect that the majority of people who buy a wi-fi router in the next five years will still not bother to even change the default admin password.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
    1. Re:If anyone actually bothers to turn it on.. by riptide_dot · · Score: 5, Insightful

      I suspect that the majority of people who buy a wi-fi router in the next five years will still not bother to even change the default admin password.

      Or take any other measures to secure the device for that matter, like preventing access to unknown MACs, limiting usage to certain times of the day, not broadcasting the SSID, etc, etc...

      This is one of those cases where some of the people that want devices like these have absolutely no idea how to use them correctly. To me, it's like handing the keys to a Ferrari to a 12 year old. ALL of my neighbors have open access points, so whenever people come over to my house with wireless equipment, I don't even bother to modify my network to let them in - I just tell them to sit by a window and inevitably they get all the bandwidth they need.

      Intel is developing a new technology that could prevent unauthorized access to wireless networks using the time it takes for packets to arrive from the access point to the Wi-Fi user.

      I think this is supposed to read "using the time it takes for packets to arrive from the Wi-Fi user to the access point. I have no idea how an access point would be able to monitor how long it took for its packets to make it to the clients...

      --
      I was in the park the other day wondering why frisbees get bigger and bigger the closer they get - and then it hit me.
  3. Disconnects on too many connections... by LittLe3Lue · · Score: 5, Funny

    From the report: 'The system monitors the number of external connections being made and if a higher network activity is detected, the computer is disconnected to prevent the infection of further machines on the network.'


    Please. Slashdot has had the same effect on websites for years.
  4. Time to drag out this old chestnut: by This+Old+Chestnut · · Score: 5, Insightful

    Security through proximity is not security at all.

  5. Wrong vector, wrong layer, respectively. by Tackhead · · Score: 5, Insightful
    > Intel is developing a new technology that could prevent unauthorized access to wireless networks using the time it takes for packets to arrive from the access point to the Wi-Fi user.

    Crackers are developing new technologies to enable unauthorized access to wireless networks using the time it takes them to intercept and retransmit packets between the access point and the Wi-Fi user.

    As for the "solution" of detecting worms by autokilling connections when bandwidth usage changes in a way that the software didn't predict, (in a way that's more likely to cripple your favorite P2P client software more than it's likely to disable a worm that decides to start slowly and ramp up), how about Intel gets off its sorry ass (if you felt a rant coming on, you were right) and comes up with a real solution to connection hijacking -- namely by implementing cryptographically strong authentication between client and access point at Layer 2 of the OSI model, not Layer 7.

    Oh, right. Securing Layer 2 instead of Layer 7 would harm the interest of those in charge of writing Layers 8 (financial) and Layer 9 (political) of the 7-layer model.