Slashdot Mirror


A Look at the State of Wireless Security

An anonymous reader brings us a whitepaper from Codenomicon which discusses the state and future of wireless security. They examine Bluetooth and Wi-Fi, and also take a preliminary look at WiMAX. The results are almost universally dismal; vulnerabilities were found in 90% of the tested devices[PDF]. The paper also looks at methods for vendors to preemptively block some types of threats. Quoting: "Despite boasts of hardened security measures, security researchers and black-hat hackers keep humiliating vendors. Security assessment of software by source code auditing is expensive and laborious. There are only a few methods for security analysis without access to the source code, and they are usually limited in scope. This may be one reason why many major software vendors have been stuck randomly fixing vulnerabilities that have been found and providing countless patches to their clients to keep the systems protected."

4 of 107 comments (clear)

  1. Re:Security is relative by ushering05401 · · Score: 4, Interesting

    On a related note... Humans are still the weakest link in any network.

    While it is interesting to read about insecurities in wireless it always bears to mention that even many well configured wired networks are easily compromised through the human component.

    I always think of this when reading about new network vulnerabilities: http://www.schneier.com/blog/archives/2006/02/proof_that_empl.html

  2. Problem with wireless by TheLink · · Score: 3, Interesting

    Current wireless solutions in practice don't have something like https usage.

    Where "anonymous" users can securely communicate with servers (that can be validated - if the users actually care).

    If you have a WiFi network secured using a naive shared key method, anyone with the shared key can decipher the access of the other users. This might be fine in your house, but not good in some public cafe.

    Seems the way around this with current WiFi technology is to let every user use an account - username and password.
    Apparently in this case even if users share the same username and password, using WPA2 or whatever (I can't be bothered to keep accurate tabs on below par crap ;) ) they can't decrypt each others sessions. Not sure if this is 100% true given the track record ;).

    Assuming it's true, it would be much easier if Windows (and other O/Ses) would default to a standard username and password AND also check the cert of the AP (and issue warnings if it looks dodgy). You should be allowed to log in using a particular user account, or be prompted if the AP rejects the default.

    Then people like Starbucks/BK/etc could use certs for their WiFi networks, and customer can have reasonably secured comms at least between themselves and the AP.

    The WiFi Alliance should have copied the SSL _concepts_ and got the help of decent security people, rather than coming up with crap year after year (for how many years?).

    --
  3. Re:Security is relative by n0-0p · · Score: 4, Interesting

    You're completely ignoring the reality of implementation flaws. Unfortunately, you fit in with the majority of the industry. I suggest you pick up a copy of Mark Dowd's "The Art of Software Security Assessment". It's 1100 pages exploring implementation flaws in real code (from a guy who's cracked everything from OpenSSH to Sendmail and MS Exchange). That's the stuff that programmers need to learn if they want to stop writing swiss cheese code, but instead they just claim that their encryption protocols solve everything. Yeah, secure protocols and design are necessary, but a bad implementation will beat you every time.

  4. The problem with security,,, by FlyingGuy · · Score: 4, Interesting

    Always has been, and always will be, the users, sorry thats just the way it is.

    I was in the military and crypto security is taken, very very very seriously. You fuck up and at minimum you will lose money, lose rank, lose your clearance or if you fucked up really bad you could go to prison.

    The problem is in business if the VP of Sales and Marketing can't make his new toy connect to your wireless infrastructure because his new toy doesn't support the same protocols he will start whining and crying that its "too hard" and you can bet your Linux live DVD you are going to be carving out an exception for the fucktard. Then he will start showing off his new toy, and then low and behold more people start buying the same thing and you have a fight on your hands. At this point the fucking CEO has to get involved and make the call and chances are security is going to lose because the VP of Sales & Marketing brings in the $profit$ and you don't regardless of how well thought out your argument is or how logical it is. Then what is going to happen is that your shit will get hacked, and that very same VP or sales and Marketing will hang it around your neck and you will be screwed.

    The only way around these kids of problems I think is two fold.

    • Device Control. You must have control over the devices that attach to your network. It has to be in hardware. Joe VP wants to bring his laptop in, then the only way he can connect is through a a USB wireless device that the IT department issues, that is burned to his ID AND his hardware and your network that way it will only work if its in HIS laptop, connected to YOUR network using HIS login credentials ( via biometrics ).
    • Policy. The adverse consequences for compromising the companies network security must be real, immediate and not left open to compromise. This has to come from the company owner if it is a private company or from the board if it is a public company.
    --
    Hey KID! Yeah you, get the fuck off my lawn!