|
|
|
I have just bought an Asus wireless router that I'm using with my Apple MacBook laptop (ISP is TalkTalk) but I have no idea about what security settings I should be using, and the instructions are non-existant.
The router's wireless security page shows the following options:
Select SSID: Wireless
Guest
Network Authentication: Open
Shared
802.1x
WPA
WPA-PSK
WPA2
WPA2-PSK
Mixed WPA2/WPA
Mixed WPA2/WPA-PSK
WEP Incription: Disabled
Enabled
Any help or suggestions would be greatly appreciated
Thanks
Jono
|
|
|
|
Find your router model and google for the instruction manual on the web.
Typical advice is:-
1) don't broadcast SSID
2) limit access to specific MAC addresses
3) use WPA/WPA2 authentication (any variant with a good long password)
You will discover that it is easy for 1) and 2) to be defeated as can any form of authentication less than WPA.
|
|
|
Change the router setup access passwords from the usual admin/admin to something a little more secure but memorable to you; jono/baker for example.
Ensure that any remote maintainence access is blocked or locked firmly down.
Change the SSID to something meaningful to you; JONONET for example.
If your clients support it and be aware that some won't, use WPA/PSK-TKIP with an alphanumeric password of at least 8 characters; J0n0bAk3r for example.
If you have data that is very much worth stealing, increase the character count to at least 20...... But let me know first.
Edited by Deadbeat (Mon 16-Apr-07 22:12:41)
|
|
Register (or login) on our website and you will not see this ad.
|
|
|
|
"Hiding" the SSID is absolutely pointless (It can't actually be hidden!) and only serves to make life difficult for anyone with a number of wireless clients to administer. Where overlapping neighbouring wireless systems with "hidden" SSIDs abound it can be a nightmare.
|
|
|
|
I know that one can discover hidden SSIDs and I know that one can spoof MAC addresses and I know that one can defeat WEP encryption, and given time WPA encryption.
I choose to not broadcast SSID for privacy reasons.
I choose to limit MAC addresses so that when my neighbours discover net stumbler they can't
accidentally log into my router.
I choose to encrypt my data with WPA and a 63 character password to prevent hackers being able to interpret the data I transmit (in the short to medium term).
|
|
|
I have no qualms where MAC locking is concerned although it's the second most futile excercise to SSID "security". But, where "hiding" the network ID is concerned, it's not only completely pointless from a security point of view but it can serve to confuse those who use and administer the network.
The idea of enhanced security via SSID "hiding" has only one home where the internet is concerned, and that's Snopes.
|
|
|
|
Jono, out of interest, is the info that you posted above a direct cut 'n' paste from the router interface?
|
|
|
Whatever you personally 'choose' to do, doesn't change the facts:
wireless security is based on *authentication* and *encryption*
Provided that you implement this then the others are not required. No-one can accidentally hack into your router - that requires a deliberate attack.
Also, I am not aware of (but am willing to be enlightened about) any successful attacks on WPA-PSK in real time. Yes, I am aware of its long-known potential weaknesses - have a read here:
https://www.icsalabs.com/icsa/docs/html/communities/WLAN/wp_PSKStudy.pdf
I believe that you are misinformed about the necessity for a 63 character passphrase (not password - that's not the way WPA-PSK works). IEEE 802.11i recommends a 20 character passphrase, and the white paper above will give you the maths to work out why this is.
Techniques such as 'SSID hiding' and 'MAC address filtering' are merely 'security by obscurity', which is no security at all.
They may make you feel better, but they really won't improve your security. By all means use them - but please don't recommend them as useful techniques to those who ask for advice. At its worst, implementing such bogus measures will add a dangerous false sense of security.
You may know what you are doing and what you want to achieve and feel comfortable with it - but please don't recommend so-called 'security' measures that provide no security at all.
While I personally don't like the writing style, the info in this article is correct:
http://blogs.zdnet.com/Ou/index.php?p=43
Kind regards
|
|
|
|
I don't disagree with the facts in those articles.
I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses, or using WEP encryption.
They all provide a level of protection. Quite frankly disabling SSID broadcast and limiting MAC addresses would defeat 99% of the population.
No protection would defeat somebody who was determined enough to get the information. Just as no physical security would prevent a determined burgular from breaking into your house.
If people are that paranoid about wireless security they shouldn't use wireless.
|
|
|
The window that you gaze out of provides a level of protection - Until someone lobs a brick through it.
What was thought of as "protection" only a short sentence ago now serves to add to the bricks ability to maim.
As for MAC locking, well that's akin to fitting snow chains to your car in mid summer. You know damned well that they're never likely be of any practical use, particularly with global warming as it is. They'll take ages to fit and eventually remove but you're not going to get caught out by that freak August blizzard!
If it's not been registered before, we'll coin a new phrase here and you're welcome to half the glory John.
Inverse Protection!
Edited by Deadbeat (Tue 17-Apr-07 01:08:07)
|
|
|
In reply to:
I don't disagree with the facts in those articles
Then we're agreed.
In reply to:
I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses
Then not only are we not agreed, but it seems to me that you have zero experience of managing a network with more than one access point and more than a couple of PCs.
Let's get it straight:
- 'hiding' the SSID is doomed to failure. It *cannot* be hidden and is always transmitted in certain frames
- it is a network identifier, *not* a security feature
- it is *designed* to be broadcast
- if it is not broadcast, certain things *will not work* or will not work well
The obvious thing that will not work is seamless roaming between multiple access points. Try it and see. For coverage of any sufficiently large area with the usual 'dead' spots, you will need to use multiple access points with the same SSID but different radio channels (usually hanging off a wide area Ethernet) or perhaps in a smaller network a repeater or two). [Note: in case you haven't read IEEE 802.11 recently, this is known as an Extended Service Set, ESS]. Now try walking about with a laptop and expecting to roam seamlessly between multiple access points in the ESS when SSID broadcast is disabled.
This won't only be a commercial network. Even a large house (ie bigger than a 'normal' 4 bed detached) is difficult to cover with a single access point, let alone when you want coverage for outbuildings + garden.
As for MAC address filtering, apart from it being useless as a security measure, try maintaining it on a wireless network much greater than say 10 devices and with changing clients.
In reply to:
or using WEP encryption
Now we're back to agreeing again. While WEP may provide weak security, it provides better protection than the bogus methods above. Implementing it will prevent your neighbours accidentally associating with your router (which seems to be what you are looking for) - no need to bother with even lesser protection.
Kind regards
Note: I haven't used strict IEEE 802.11 terminology above in terms of stations, association, disassociation etc - otherwise it becomes unreadable.
EDIT: Here's an updated article. Should have spotted it before I guess, but as I said I don't like the (over smug) style. But he's still correct:
http://blogs.zdnet.com/Ou/?p=454
Edited by rperkin (Tue 17-Apr-07 03:16:36)
|
|
|
|
|
|
|
|
Aaaaarrrrggghhhhh!!!! Gibson again! Spit spit.
|
|
|
|
Yes. That's why I respond to the tin-foil brigade once and then try to stop. It's not fair on the original poster.
|
|
|
|
That's a useful article. I knew that MAC filtering could easily be defeated but I didn't realise that SSID hiding was so useless and potentially dangerous.
|
|
|
|
Aaaagh!!!!
It is most certainly not fair on the original poster.
For heaven's sake, please stop giving incorrect info. Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish.
At best, Steve Gibson has a reputation that can only be described as 'mixed'. While tools such as the simple-to-use Shields Up tester are fine (within its limits), the site is unduly alarmist. At worst, he is regarded as a self-publicist without security credentials or credibility and who provides silly advice.
Tools to generate random keys are fine. There are many available. But all the blather that goes round it is just that - blather. Take a large shovelful of salt before believing what you read on the GRC site. I suggest you Google on "steve gibson".
However, on a related matter, I have used the SpinRite product with success, so it's not all bad. But then it's not a security product...
Kind regards
|
|
|
|
There's no tin foil hat brigade here. What myself and others are saying with regards to MAC filtering and SSID obscuring is just plain, factual common sense
I will agree that WPA passphrase length is a different matter and is open to healthy debate but who's wearing the tin foil hat where that's concerned?
It's you who is being unfair to posters such as the OP in this thread by continually proliferating disinformation with regard to security. Now, I'll be the first to admit that we all get things wrong from time to time but when we do, it's no big deal to stand up, admit to it, apologise if necessary and amend ourselves accordingly. Blindly ignoring the facts helps no-one and serves only to confuse the uninitiated.
There, it's done. I've said what I've said and I make no apologies for doing so.
|
|
|
"Pointing users to the GRC site as a 'good' place for info about security matters is, quite frankly, foolish."
Hear hear!
"I have used the SpinRite product with success, so it's not all bad."
Haven't you experienced HDDRegen? The website may be a little tatty, the English poor and the application itself very basic looking but it's a product that does exactly what it says on the tin. What's more, it leaves Spinrite 6 with all its bells and whistles miles behind and eating dust.
|
|
|
|
Thanks for the link.
I haven't needed to use a disk recovery utility for some years and it was an earlier version of SpinRite that I used. I always ignore the 'spin' (to coin a phrase) in marketing material, but credit where it's due, it did work.
Kind regards
|
|
|
The way I look at it is that when your stupid neighbour sets up his wifi, if he can't see your network then he has no reason not to choose the same channel as you. If he does choose the same channel, then you both suffer . . . . I see the SSID as a way of staking my claim for my little share of the ether.
______________________________________________________________________
http://www.vfast.co.uk/ - 2 Mbps symmetrical via fixed-link wireless
|
|
|
In reply to:
Inverse Protection!
Given a function, f : D -> C, a function g : C -> D is called a left inverse for f if for all d in D, g (f d) = d and a right inverse if, for all c in C, f (g c) = c and an inverse if both conditions hold. Only an injection has a left inverse, only a surjection has a right inverse and only a bijection has inverses. The inverse of f is often written as f with a -1 superscript.
|
|
|
In reply to:
The obvious thing that will not work is seamless roaming between multiple access points.
Oh yes it will...
Comms is hard
|
|
|
All I can say is that it doesn't (more accurately, didn't) for me.
I've recently reconfigured and simplified my network after a relocation, but I was running 5 APs: a wireless router + two further APs (using channels 1, 6, 11) and two Repeaters (on the same channel as their 'root' AP). With SSID broadcast disabled, roaming did not work. With SSID broadcast enabled, roaming worked just fine.
Perhaps I've put it too strongly - it did not work at all well with a 'hidden' SSID. It most certainly wasn't seamless.
I have also observed the same effect on larger scale business networks. So what effect am I seeing? And am I also misinterpreting the performance issues in what Bob Moskowitz has to say here:
http://www.icsalabs.com/WLAN/wp_ssid_hiding.pdf
Kind regards
|