Technical Discussion
  >> Technical Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread
Standard User jonobaker
(newbie) Mon 16-Apr-07 21:52:54
Print Post

router security settings


[link to this post]
 
I have just bought an Asus wireless router that I'm using with my Apple MacBook laptop (ISP is TalkTalk) but I have no idea about what security settings I should be using, and the instructions are non-existant.
The router's wireless security page shows the following options:

Select SSID: Wireless
Guest

Network Authentication: Open
Shared
802.1x
WPA
WPA-PSK
WPA2
WPA2-PSK
Mixed WPA2/WPA
Mixed WPA2/WPA-PSK

WEP Incription: Disabled
Enabled

Any help or suggestions would be greatly appreciated
Thanks
Jono
Standard User deleted
(deleted) Mon 16-Apr-07 22:00:28
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Find your router model and google for the instruction manual on the web.

Typical advice is:-

1) don't broadcast SSID
2) limit access to specific MAC addresses
3) use WPA/WPA2 authentication (any variant with a good long password)

You will discover that it is easy for 1) and 2) to be defeated as can any form of authentication less than WPA.
Standard User Deadbeat
(experienced) Mon 16-Apr-07 22:04:55
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Change the router setup access passwords from the usual admin/admin to something a little more secure but memorable to you; jono/baker for example.
Ensure that any remote maintainence access is blocked or locked firmly down.
Change the SSID to something meaningful to you; JONONET for example.
If your clients support it and be aware that some won't, use WPA/PSK-TKIP with an alphanumeric password of at least 8 characters; J0n0bAk3r for example.
If you have data that is very much worth stealing, increase the character count to at least 20...... But let me know first.

Edited by Deadbeat (Mon 16-Apr-07 22:12:41)


Register (or login) on our website and you will not see this ad.

Standard User Deadbeat
(experienced) Mon 16-Apr-07 22:10:40
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
"Hiding" the SSID is absolutely pointless (It can't actually be hidden!) and only serves to make life difficult for anyone with a number of wireless clients to administer. Where overlapping neighbouring wireless systems with "hidden" SSIDs abound it can be a nightmare.
Standard User deleted
(deleted) Mon 16-Apr-07 22:33:31
Print Post

Re: router security settings


[re: Deadbeat] [link to this post]
 
I know that one can discover hidden SSIDs and I know that one can spoof MAC addresses and I know that one can defeat WEP encryption, and given time WPA encryption.

I choose to not broadcast SSID for privacy reasons.

I choose to limit MAC addresses so that when my neighbours discover net stumbler they can't
accidentally log into my router.

I choose to encrypt my data with WPA and a 63 character password to prevent hackers being able to interpret the data I transmit (in the short to medium term).
Standard User Deadbeat
(experienced) Mon 16-Apr-07 23:10:22
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
I have no qualms where MAC locking is concerned although it's the second most futile excercise to SSID "security". But, where "hiding" the network ID is concerned, it's not only completely pointless from a security point of view but it can serve to confuse those who use and administer the network.
The idea of enhanced security via SSID "hiding" has only one home where the internet is concerned, and that's Snopes.
Standard User Deadbeat
(experienced) Mon 16-Apr-07 23:13:36
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Jono, out of interest, is the info that you posted above a direct cut 'n' paste from the router interface?
Standard User rperkin
(committed) Mon 16-Apr-07 23:24:08
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Whatever you personally 'choose' to do, doesn't change the facts:

wireless security is based on *authentication* and *encryption*

Provided that you implement this then the others are not required. No-one can accidentally hack into your router - that requires a deliberate attack.

Also, I am not aware of (but am willing to be enlightened about) any successful attacks on WPA-PSK in real time. Yes, I am aware of its long-known potential weaknesses - have a read here:
https://www.icsalabs.com/icsa/docs/html/communities/WLAN/wp_PSKStudy.pdf

I believe that you are misinformed about the necessity for a 63 character passphrase (not password - that's not the way WPA-PSK works). IEEE 802.11i recommends a 20 character passphrase, and the white paper above will give you the maths to work out why this is.

Techniques such as 'SSID hiding' and 'MAC address filtering' are merely 'security by obscurity', which is no security at all.

They may make you feel better, but they really won't improve your security. By all means use them - but please don't recommend them as useful techniques to those who ask for advice. At its worst, implementing such bogus measures will add a dangerous false sense of security.

You may know what you are doing and what you want to achieve and feel comfortable with it - but please don't recommend so-called 'security' measures that provide no security at all.

While I personally don't like the writing style, the info in this article is correct:
http://blogs.zdnet.com/Ou/index.php?p=43

Kind regards
Standard User deleted
(deleted) Mon 16-Apr-07 23:41:53
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
I don't disagree with the facts in those articles.

I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses, or using WEP encryption.

They all provide a level of protection. Quite frankly disabling SSID broadcast and limiting MAC addresses would defeat 99% of the population.

No protection would defeat somebody who was determined enough to get the information. Just as no physical security would prevent a determined burgular from breaking into your house.

If people are that paranoid about wireless security they shouldn't use wireless.
Standard User Deadbeat
(experienced) Tue 17-Apr-07 00:58:18
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
The window that you gaze out of provides a level of protection - Until someone lobs a brick through it.
What was thought of as "protection" only a short sentence ago now serves to add to the bricks ability to maim.

As for MAC locking, well that's akin to fitting snow chains to your car in mid summer. You know damned well that they're never likely be of any practical use, particularly with global warming as it is. They'll take ages to fit and eventually remove but you're not going to get caught out by that freak August blizzard!


If it's not been registered before, we'll coin a new phrase here and you're welcome to half the glory John.

Inverse Protection!

Edited by Deadbeat (Tue 17-Apr-07 01:08:07)

Standard User rperkin
(committed) Tue 17-Apr-07 02:39:51
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
In reply to:

I don't disagree with the facts in those articles


Then we're agreed.
In reply to:

I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses


Then not only are we not agreed, but it seems to me that you have zero experience of managing a network with more than one access point and more than a couple of PCs.

Let's get it straight:
- 'hiding' the SSID is doomed to failure. It *cannot* be hidden and is always transmitted in certain frames
- it is a network identifier, *not* a security feature
- it is *designed* to be broadcast
- if it is not broadcast, certain things *will not work* or will not work well

The obvious thing that will not work is seamless roaming between multiple access points. Try it and see. For coverage of any sufficiently large area with the usual 'dead' spots, you will need to use multiple access points with the same SSID but different radio channels (usually hanging off a wide area Ethernet) or perhaps in a smaller network a repeater or two). [Note: in case you haven't read IEEE 802.11 recently, this is known as an Extended Service Set, ESS]. Now try walking about with a laptop and expecting to roam seamlessly between multiple access points in the ESS when SSID broadcast is disabled.

This won't only be a commercial network. Even a large house (ie bigger than a 'normal' 4 bed detached) is difficult to cover with a single access point, let alone when you want coverage for outbuildings + garden.

As for MAC address filtering, apart from it being useless as a security measure, try maintaining it on a wireless network much greater than say 10 devices and with changing clients.
In reply to:

or using WEP encryption


Now we're back to agreeing again. While WEP may provide weak security, it provides better protection than the bogus methods above. Implementing it will prevent your neighbours accidentally associating with your router (which seems to be what you are looking for) - no need to bother with even lesser protection.

Kind regards

Note: I haven't used strict IEEE 802.11 terminology above in terms of stations, association, disassociation etc - otherwise it becomes unreadable.

EDIT: Here's an updated article. Should have spotted it before I guess, but as I said I don't like the (over smug) style. But he's still correct:
http://blogs.zdnet.com/Ou/?p=454

Edited by rperkin (Tue 17-Apr-07 03:16:36)

Standard User deleted
(deleted) Tue 17-Apr-07 11:32:31
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
I found this info useful for wireless security http://bbs.adslguide.org.uk/showthreaded.php?Cat=&Board=general&Number=2895259&page=&view=&sb=&o=
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 11:35:27
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Aaaaarrrrggghhhhh!!!! Gibson again! Spit spit.
Standard User deleted
(deleted) Tue 17-Apr-07 11:41:51
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Yes. That's why I respond to the tin-foil brigade once and then try to stop. It's not fair on the original poster.
Standard User Kiro
(committed) Tue 17-Apr-07 12:06:05
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
That's a useful article. I knew that MAC filtering could easily be defeated but I didn't realise that SSID hiding was so useless and potentially dangerous.
Standard User rperkin
(committed) Tue 17-Apr-07 12:42:19
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Aaaagh!!!!

It is most certainly not fair on the original poster.

For heaven's sake, please stop giving incorrect info. Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish.

At best, Steve Gibson has a reputation that can only be described as 'mixed'. While tools such as the simple-to-use Shields Up tester are fine (within its limits), the site is unduly alarmist. At worst, he is regarded as a self-publicist without security credentials or credibility and who provides silly advice.

Tools to generate random keys are fine. There are many available. But all the blather that goes round it is just that - blather. Take a large shovelful of salt before believing what you read on the GRC site. I suggest you Google on "steve gibson".

However, on a related matter, I have used the SpinRite product with success, so it's not all bad. But then it's not a security product...

Kind regards
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 12:47:16
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
There's no tin foil hat brigade here. What myself and others are saying with regards to MAC filtering and SSID obscuring is just plain, factual common sense
I will agree that WPA passphrase length is a different matter and is open to healthy debate but who's wearing the tin foil hat where that's concerned?

It's you who is being unfair to posters such as the OP in this thread by continually proliferating disinformation with regard to security. Now, I'll be the first to admit that we all get things wrong from time to time but when we do, it's no big deal to stand up, admit to it, apologise if necessary and amend ourselves accordingly. Blindly ignoring the facts helps no-one and serves only to confuse the uninitiated.

There, it's done. I've said what I've said and I make no apologies for doing so.
Standard User Deadbeat
(fountain of knowledge) Tue 17-Apr-07 12:55:55
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
"Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish."
Hear hear!

"I have used the SpinRite product with success, so it's not all bad."
Haven't you experienced HDDRegen? The website may be a little tatty, the English poor and the application itself very basic looking but it's a product that does exactly what it says on the tin. What's more, it leaves Spinrite 6 with all its bells and whistles miles behind and eating dust.

Standard User rperkin
(committed) Tue 17-Apr-07 13:08:49
Print Post

Re: router security settings


[re: Deadbeat] [link to this post]
 
Thanks for the link.

I haven't needed to use a disk recovery utility for some years and it was an earlier version of SpinRite that I used. I always ignore the 'spin' (to coin a phrase) in marketing material, but credit where it's due, it did work.

Kind regards
Standard User Xris
(fountain of knowledge) Tue 17-Apr-07 18:22:00
Print Post

Re: router security settings


[re: Kiro] [link to this post]
 
The way I look at it is that when your stupid neighbour sets up his wifi, if he can't see your network then he has no reason not to choose the same channel as you. If he does choose the same channel, then you both suffer . . . . I see the SSID as a way of staking my claim for my little share of the ether.

______________________________________________________________________
http://www.vfast.co.uk/ - 2 Mbps symmetrical via fixed-link wireless
Standard User RobertoS
(experienced) Tue 17-Apr-07 20:32:35
Print Post

Re: router security settings


[re: Deadbeat] [link to this post]
 
In reply to:

Inverse Protection!


Given a function, f : D -> C, a function g : C -> D is called a left inverse for f if for all d in D, g (f d) = d and a right inverse if, for all c in C, f (g c) = c and an inverse if both conditions hold. Only an injection has a left inverse, only a surjection has a right inverse and only a bijection has inverses. The inverse of f is often written as f with a -1 superscript.
Standard User JonRennie
(knowledge is power) Fri 20-Apr-07 18:32:34
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 

In reply to:

The obvious thing that will not work is seamless roaming between multiple access points.




Oh yes it will...

Comms is hard
Standard User rperkin
(committed) Fri 20-Apr-07 19:33:04
Print Post

Re: router security settings


[re: JonRennie] [link to this post]
 
All I can say is that it doesn't (more accurately, didn't) for me.

I've recently reconfigured and simplified my network after a relocation, but I was running 5 APs: a wireless router + two further APs (using channels 1, 6, 11) and two Repeaters (on the same channel as their 'root' AP). With SSID broadcast disabled, roaming did not work. With SSID broadcast enabled, roaming worked just fine.

Perhaps I've put it too strongly - it did not work at all well with a 'hidden' SSID. It most certainly wasn't seamless.

I have also observed the same effect on larger scale business networks. So what effect am I seeing? And am I also misinterpreting the performance issues in what Bob Moskowitz has to say here:
http://www.icsalabs.com/WLAN/wp_ssid_hiding.pdf

Kind regards
Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread

Jump to