[Full-Disclosure] Re: Wireless Security

From: Chris Adams (chris_at_improbable.org)
Date: 11/28/03

  • Next message: Joel R. Helgeson: "Re: [Full-Disclosure] Wireless Security"
    To: full-disclosure@lists.netsys.com
    Date: Fri, 28 Nov 2003 13:44:06 -0800
    
    

    > be possible or practical all of the time. Although policy could
    > dictate that when a wireless card is given out, the MAC address in
    > added to the AP, however if you have multiple APs in different areas
    > of building, being administered by different IT depts then this could
    > soon become be a problem.
    >
    > To me IPSEC looks like be the better solution using SecurID tokens
    > (one time passwords) to authenticate users, any thoughts would be
    > appreciated.

    IPSec is by far the best solution. Commonly recommended steps like
    turning off SSID broadcasts, setting MAC address restrictions and using
    WEP are no better than snake-oil; even LEAP, WPA and more recent
    buzzwords may do a better job of protecting the wireless link but
    they're still fundamentally flawed since they only protect the wireless
    portion of your traffic - if, as appears to be the case, you really
    care about security there's no substitute for a full end-to-end system
    with strong cryptography (one alternative would be restricting access
    entirely to protocols which use SSL - although it's not generic you can
    avoid many client compatibility issues).

    There's also a big plus to this approach: it greatly simplifies
    deployment since you don't need the more expensive buzzword-compliant
    (=likely to break in unusual ways) access points as long as your
    network is IPSec-only, compartmentalized or both.

    Chris

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Joel R. Helgeson: "Re: [Full-Disclosure] Wireless Security"

    Relevant Pages

    • Re: Two Netgear WGT624 models will not communicate
      ... dramatically increase the leve of complexity of wireless. ... Security in a WDS network is marginal. ... the WAP54G wireless bridge has a similar problem. ... As I see it, the MAC address in the configuration is ...
      (alt.internet.wireless)
    • Re: Theoretical Discussion: Hotel WiFi Hack
      ... discussion to start with you wireless experts. ... They don't offer wired internet because it's an old ... passed his MAC address around via some GET variables in the URL. ... Surely the router or gateway would go ...
      (alt.internet.wireless)
    • Re: Wireless IP leads to arrest.. (UNCLASSIFIED)
      ... I'm going to preface this by stating that the OP still hasn't provided a link, and the further data provided makes no mention of a wireless AP. ... As for how they would track it back to a MAC, it's dirt simple *if* the user had to register their MAC address with their service provider to obtain an IP address. ... Network Security Consultant ... Wireless IP leads to arrest.. ...
      (Security-Basics)
    • Re: 802.11n
      ... Use SD content to get people to buy into iTV, and offer HD content later, but limit it only to people with 802.11n support on their Mac. ... What evidence do you have that Apple will break from tradition and give the older Macs support for 802.11n? ... Apple has a long history of providing newer tech to older machines, ... the only third-party wifi expansions for the Mac are wireless bridges and USB dongles. ...
      (comp.sys.mac.advocacy)
    • Re: Windows on a Mac
      ... wireless keyboards, wireless mice, or wireless remotes over wired ... As for wireless remotes, the whole point of a remote is that it is ... Who sells "a box with 4 tires"? ... Funny how Mac advocates switch back and forth depending on what they do. ...
      (rec.video.desktop)