Technical Discussion
  >> Technical Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | [2] | 3 | (show all)   Print Thread
Standard User rperkin
(committed) Tue 17-Apr-07 02:39:51
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
In reply to:

I don't disagree with the facts in those articles


Then we're agreed.
In reply to:

I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses


Then not only are we not agreed, but it seems to me that you have zero experience of managing a network with more than one access point and more than a couple of PCs.

Let's get it straight:
- 'hiding' the SSID is doomed to failure. It *cannot* be hidden and is always transmitted in certain frames
- it is a network identifier, *not* a security feature
- it is *designed* to be broadcast
- if it is not broadcast, certain things *will not work* or will not work well

The obvious thing that will not work is seamless roaming between multiple access points. Try it and see. For coverage of any sufficiently large area with the usual 'dead' spots, you will need to use multiple access points with the same SSID but different radio channels (usually hanging off a wide area Ethernet) or perhaps in a smaller network a repeater or two). [Note: in case you haven't read IEEE 802.11 recently, this is known as an Extended Service Set, ESS]. Now try walking about with a laptop and expecting to roam seamlessly between multiple access points in the ESS when SSID broadcast is disabled.

This won't only be a commercial network. Even a large house (ie bigger than a 'normal' 4 bed detached) is difficult to cover with a single access point, let alone when you want coverage for outbuildings + garden.

As for MAC address filtering, apart from it being useless as a security measure, try maintaining it on a wireless network much greater than say 10 devices and with changing clients.
In reply to:

or using WEP encryption


Now we're back to agreeing again. While WEP may provide weak security, it provides better protection than the bogus methods above. Implementing it will prevent your neighbours accidentally associating with your router (which seems to be what you are looking for) - no need to bother with even lesser protection.

Kind regards

Note: I haven't used strict IEEE 802.11 terminology above in terms of stations, association, disassociation etc - otherwise it becomes unreadable.

EDIT: Here's an updated article. Should have spotted it before I guess, but as I said I don't like the (over smug) style. But he's still correct:
http://blogs.zdnet.com/Ou/?p=454

Edited by rperkin (Tue 17-Apr-07 03:16:36)

Standard User deleted
(deleted) Tue 17-Apr-07 11:32:31
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
I found this info useful for wireless security http://bbs.adslguide.org.uk/showthreaded.php?Cat=&Board=general&Number=2895259&page=&view=&sb=&o=
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 11:35:27
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Aaaaarrrrggghhhhh!!!! Gibson again! Spit spit.


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Tue 17-Apr-07 11:41:51
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Yes. That's why I respond to the tin-foil brigade once and then try to stop. It's not fair on the original poster.
Standard User Kiro
(committed) Tue 17-Apr-07 12:06:05
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
That's a useful article. I knew that MAC filtering could easily be defeated but I didn't realise that SSID hiding was so useless and potentially dangerous.
Standard User rperkin
(committed) Tue 17-Apr-07 12:42:19
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Aaaagh!!!!

It is most certainly not fair on the original poster.

For heaven's sake, please stop giving incorrect info. Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish.

At best, Steve Gibson has a reputation that can only be described as 'mixed'. While tools such as the simple-to-use Shields Up tester are fine (within its limits), the site is unduly alarmist. At worst, he is regarded as a self-publicist without security credentials or credibility and who provides silly advice.

Tools to generate random keys are fine. There are many available. But all the blather that goes round it is just that - blather. Take a large shovelful of salt before believing what you read on the GRC site. I suggest you Google on "steve gibson".

However, on a related matter, I have used the SpinRite product with success, so it's not all bad. But then it's not a security product...

Kind regards
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 12:47:16
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
There's no tin foil hat brigade here. What myself and others are saying with regards to MAC filtering and SSID obscuring is just plain, factual common sense
I will agree that WPA passphrase length is a different matter and is open to healthy debate but who's wearing the tin foil hat where that's concerned?

It's you who is being unfair to posters such as the OP in this thread by continually proliferating disinformation with regard to security. Now, I'll be the first to admit that we all get things wrong from time to time but when we do, it's no big deal to stand up, admit to it, apologise if necessary and amend ourselves accordingly. Blindly ignoring the facts helps no-one and serves only to confuse the uninitiated.

There, it's done. I've said what I've said and I make no apologies for doing so.
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 12:55:55
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
"Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish."
Hear hear!

"I have used the SpinRite product with success, so it's not all bad."
Haven't you experienced HDDRegen? The website may be a little tatty, the English poor and the application itself very basic looking but it's a product that does exactly what it says on the tin. What's more, it leaves Spinrite 6 with all its bells and whistles miles behind and eating dust.

Standard User rperkin
(committed) Tue 17-Apr-07 13:08:49
Print Post

Re: router security settings


[re: Deadbeat] [link to this post]
 
Thanks for the link.

I haven't needed to use a disk recovery utility for some years and it was an earlier version of SpinRite that I used. I always ignore the 'spin' (to coin a phrase) in marketing material, but credit where it's due, it did work.

Kind regards
Standard User Xris
(fountain of knowledge) Tue 17-Apr-07 18:22:00
Print Post

Re: router security settings


[re: Kiro] [link to this post]
 
The way I look at it is that when your stupid neighbour sets up his wifi, if he can't see your network then he has no reason not to choose the same channel as you. If he does choose the same channel, then you both suffer . . . . I see the SSID as a way of staking my claim for my little share of the ether.

______________________________________________________________________
http://www.vfast.co.uk/ - 2 Mbps symmetrical via fixed-link wireless
Pages in this thread: 1 | [2] | 3 | (show all)   Print Thread

Jump to