Technical Discussion
  >> Technical Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread
Standard User jonobaker
(newbie) Mon 16-Apr-07 21:52:54
Print Post

router security settings


[link to this post]
 
I have just bought an Asus wireless router that I'm using with my Apple MacBook laptop (ISP is TalkTalk) but I have no idea about what security settings I should be using, and the instructions are non-existant.
The router's wireless security page shows the following options:

Select SSID: Wireless
Guest

Network Authentication: Open
Shared
802.1x
WPA
WPA-PSK
WPA2
WPA2-PSK
Mixed WPA2/WPA
Mixed WPA2/WPA-PSK

WEP Incription: Disabled
Enabled

Any help or suggestions would be greatly appreciated
Thanks
Jono
Standard User deleted
(deleted) Mon 16-Apr-07 22:00:28
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Find your router model and google for the instruction manual on the web.

Typical advice is:-

1) don't broadcast SSID
2) limit access to specific MAC addresses
3) use WPA/WPA2 authentication (any variant with a good long password)

You will discover that it is easy for 1) and 2) to be defeated as can any form of authentication less than WPA.
Standard User Deadbeat
(experienced) Mon 16-Apr-07 22:04:55
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Change the router setup access passwords from the usual admin/admin to something a little more secure but memorable to you; jono/baker for example.
Ensure that any remote maintainence access is blocked or locked firmly down.
Change the SSID to something meaningful to you; JONONET for example.
If your clients support it and be aware that some won't, use WPA/PSK-TKIP with an alphanumeric password of at least 8 characters; J0n0bAk3r for example.
If you have data that is very much worth stealing, increase the character count to at least 20...... But let me know first.

Edited by Deadbeat (Mon 16-Apr-07 22:12:41)


Register (or login) on our website and you will not see this ad.

Standard User Deadbeat
(experienced) Mon 16-Apr-07 22:10:40
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
"Hiding" the SSID is absolutely pointless (It can't actually be hidden!) and only serves to make life difficult for anyone with a number of wireless clients to administer. Where overlapping neighbouring wireless systems with "hidden" SSIDs abound it can be a nightmare.
Standard User deleted
(deleted) Mon 16-Apr-07 22:33:31
Print Post

Re: router security settings


[re: Deadbeat] [link to this post]
 
I know that one can discover hidden SSIDs and I know that one can spoof MAC addresses and I know that one can defeat WEP encryption, and given time WPA encryption.

I choose to not broadcast SSID for privacy reasons.

I choose to limit MAC addresses so that when my neighbours discover net stumbler they can't
accidentally log into my router.

I choose to encrypt my data with WPA and a 63 character password to prevent hackers being able to interpret the data I transmit (in the short to medium term).
Standard User Deadbeat
(experienced) Mon 16-Apr-07 23:10:22
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
I have no qualms where MAC locking is concerned although it's the second most futile excercise to SSID "security". But, where "hiding" the network ID is concerned, it's not only completely pointless from a security point of view but it can serve to confuse those who use and administer the network.
The idea of enhanced security via SSID "hiding" has only one home where the internet is concerned, and that's Snopes.
Standard User Deadbeat
(experienced) Mon 16-Apr-07 23:13:36
Print Post

Re: router security settings


[re: jonobaker] [link to this post]
 
Jono, out of interest, is the info that you posted above a direct cut 'n' paste from the router interface?
Standard User rperkin
(committed) Mon 16-Apr-07 23:24:08
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
Whatever you personally 'choose' to do, doesn't change the facts:

wireless security is based on *authentication* and *encryption*

Provided that you implement this then the others are not required. No-one can accidentally hack into your router - that requires a deliberate attack.

Also, I am not aware of (but am willing to be enlightened about) any successful attacks on WPA-PSK in real time. Yes, I am aware of its long-known potential weaknesses - have a read here:
https://www.icsalabs.com/icsa/docs/html/communities/WLAN/wp_PSKStudy.pdf

I believe that you are misinformed about the necessity for a 63 character passphrase (not password - that's not the way WPA-PSK works). IEEE 802.11i recommends a 20 character passphrase, and the white paper above will give you the maths to work out why this is.

Techniques such as 'SSID hiding' and 'MAC address filtering' are merely 'security by obscurity', which is no security at all.

They may make you feel better, but they really won't improve your security. By all means use them - but please don't recommend them as useful techniques to those who ask for advice. At its worst, implementing such bogus measures will add a dangerous false sense of security.

You may know what you are doing and what you want to achieve and feel comfortable with it - but please don't recommend so-called 'security' measures that provide no security at all.

While I personally don't like the writing style, the info in this article is correct:
http://blogs.zdnet.com/Ou/index.php?p=43

Kind regards
Standard User deleted
(deleted) Mon 16-Apr-07 23:41:53
Print Post

Re: router security settings


[re: rperkin] [link to this post]
 
I don't disagree with the facts in those articles.

I do disagree with people who say it's stupid, or worthless, or pointless disabling SSID, or limiting MAC addresses, or using WEP encryption.

They all provide a level of protection. Quite frankly disabling SSID broadcast and limiting MAC addresses would defeat 99% of the population.

No protection would defeat somebody who was determined enough to get the information. Just as no physical security would prevent a determined burgular from breaking into your house.

If people are that paranoid about wireless security they shouldn't use wireless.
Standard User Deadbeat
(experienced) Tue 17-Apr-07 00:58:18
Print Post

Re: router security settings


[re: deleted] [link to this post]
 
The window that you gaze out of provides a level of protection - Until someone lobs a brick through it.
What was thought of as "protection" only a short sentence ago now serves to add to the bricks ability to maim.

As for MAC locking, well that's akin to fitting snow chains to your car in mid summer. You know damned well that they're never likely be of any practical use, particularly with global warming as it is. They'll take ages to fit and eventually remove but you're not going to get caught out by that freak August blizzard!


If it's not been registered before, we'll coin a new phrase here and you're welcome to half the glory John.

Inverse Protection!

Edited by Deadbeat (Tue 17-Apr-07 01:08:07)

Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread

Jump to